Insights
Practical guidance you can apply this week.
Framework explainers, checklists, common mistakes and implementation roadmaps — written for people doing the work.
Writing a risk appetite statement the board will actually use
Most appetite statements fail because they are unmeasurable. Here is a structure that ties appetite to tolerances, KRIs and escalation.
8 min read
ISO 37301 in practice: building the compliance obligations register
From compliance universe to obligation owner, evidence and monitoring frequency — how to build a register that survives audit.
11 min read
Combined assurance maps: the five mistakes that waste the effort
Coverage without conclusions, mapping to processes instead of risks, and other traps that turn a good tool into a wall chart.
7 min read
Audit committee reporting: what oversight really needs to see
A one-page pack structure covering top risks, assurance coverage, findings ageing and unresolved management actions.
6 min read
ERM maturity: an honest self-assessment before you buy a system
Maturity is behaviour, not software. Use these dimensions to score where you actually are before investing.
9 min read
AI governance: applying existing risk frameworks to new exposure
You do not need a new framework. You need model inventory, use-case risk rating, human oversight and clear accountability.
10 min read
ISO 27005 without the theory: a working risk assessment method
Assets, threats, vulnerabilities and treatment — turned into a workbook your security and risk teams can both use.
12 min read
Moving from compliance officer to GRC leadership
The skills that get you promoted are rarely technical. Influence, commercial framing and assurance literacy matter more.
6 min read
Regulatory change management that does not rely on heroics
Horizon scanning, impact assessment, implementation tracking and sign-off — designed as a repeatable monthly cycle.
8 min read
