Insights

Practical guidance you can apply this week.

Framework explainers, checklists, common mistakes and implementation roadmaps — written for people doing the work.

Risk ManagementHow-to guide

Writing a risk appetite statement the board will actually use

Most appetite statements fail because they are unmeasurable. Here is a structure that ties appetite to tolerances, KRIs and escalation.

8 min read

ComplianceFramework explainer

ISO 37301 in practice: building the compliance obligations register

From compliance universe to obligation owner, evidence and monitoring frequency — how to build a register that survives audit.

11 min read

AssuranceCommon mistakes

Combined assurance maps: the five mistakes that waste the effort

Coverage without conclusions, mapping to processes instead of risks, and other traps that turn a good tool into a wall chart.

7 min read

GovernanceTemplate walkthrough

Audit committee reporting: what oversight really needs to see

A one-page pack structure covering top risks, assurance coverage, findings ageing and unresolved management actions.

6 min read

Risk ManagementChecklist article

ERM maturity: an honest self-assessment before you buy a system

Maturity is behaviour, not software. Use these dimensions to score where you actually are before investing.

9 min read

Specialist GRCImplementation roadmap

AI governance: applying existing risk frameworks to new exposure

You do not need a new framework. You need model inventory, use-case risk rating, human oversight and clear accountability.

10 min read

Specialist GRCHow-to guide

ISO 27005 without the theory: a working risk assessment method

Assets, threats, vulnerabilities and treatment — turned into a workbook your security and risk teams can both use.

12 min read

ComplianceCareer development

Moving from compliance officer to GRC leadership

The skills that get you promoted are rarely technical. Influence, commercial framing and assurance literacy matter more.

6 min read

ComplianceImplementation roadmap

Regulatory change management that does not rely on heroics

Horizon scanning, impact assessment, implementation tracking and sign-off — designed as a repeatable monthly cycle.

8 min read