GRC blogs
Explore our blogs for expert insights, industry updates, and practical guidance
Designed to challenge ways of thinking and help your enterprise excel in GRC.

-

8 risk and compliance leaders to follow and learn from on LinkedIn
Read more: 8 risk and compliance leaders to follow and learn from on LinkedInWe’re shining a spotlight on the people shaping the future of governance, risk and compliance. LinkedIn is one of the best places to find real conversations about risk leadership, compliance culture, internal audit, AI governance, operational resilience and the future of GRC. In this blog, we’ve curated 8 GRC leaders worth following on LinkedIn. Their work spans: From established analysts and community…
-

The Modern CISO’s Compliance Stack: Frameworks, Automation and AI webinar
Read more: The Modern CISO’s Compliance Stack: Frameworks, Automation and AI webinarIntroduction: What should a modern CISO compliance stack actually look like? CISOs are being asked to protect the business across more frameworks, more regulatory expectations and more third-party assessments than many compliance programs were built to handle. The pressure is not theoretical. PwC’s Global Compliance Survey 2025 found that 85% of respondents said compliance requirements have become more complex in the last 3…
-

Spotlight on Women in GRC: Chief Compliance Officer on accountability, crisis management & leadership
Read more: Spotlight on Women in GRC: Chief Compliance Officer on accountability, crisis management & leadershipIn the latest episode of CoreStream GRC’s Spotlight on Women in GRC podcast, Lucy Montague speaks with Grace Suleyman, Chief Compliance Officer at an asset management company servicing insurance clients. Grace’s role spans legal, company secretarial, enterprise risk and compliance, giving her a broad view of what modern compliance leadership now requires. The discussion explores why senior GRC roles…
-

Why easy login can create risk in GRC and Conflict of Interest systems
Read more: Why easy login can create risk in GRC and Conflict of Interest systemsBy Mike VidoniSenior GRC Client Executive & Customer Success, CoreStream GRC Key takeaways Introduction: When does convenience become a control weakness? GRC teams need people to use their systems. A Conflict of Interest process cannot work properly if employees, or board members struggle to complete disclosures because the process is unnecessarily complicated. But login design is not simply a usability decision. It…
-

What is ISO 27001? A practical guide to information security management
Read more: What is ISO 27001? A practical guide to information security managementAbstract ISO 27001 gives organizations a structured way to manage information security risk. But for many teams, the real challenge is not understanding the standard. It is maintaining the evidence, ownership and control visibility needed to prove the system works. This guide should explain what ISO 27001 is, why it matters, how certification works, what Annex A controls cover, and why…
-

Is the vendor risk assessment dead?
Read more: Is the vendor risk assessment dead?Is the traditional vendor questionnaire still fit for purpose? Imagine beginning a vendor assessment without sending another 200-question form. Before contacting the third party, you already understand who the organization is, who sits behind it, and whether there are public risk signals that warrant closer attention. You can ask the vendor for the evidence it already holds, identify the gaps that…
-

Spotlight on Women in GRC: Former Head of Internal Financial Controls on AI, leadership & work-life balance
Read more: Spotlight on Women in GRC: Former Head of Internal Financial Controls on AI, leadership & work-life balanceTo countdown to the Women in GRC Awards on 2 July 2026, we are running a podcast series, “Spotlight on Women in GRC”. In this episode, CoreSream GRC’s Head of Marketing, Lucy Montague sits down with Nikki Absolom, Tax Technology and Transformation Lead at IVC Evidensia, former Head of Controls at Pets at Home, and an Independent Board…
-

Third-Party Risk Management software RFP template: questions and scoring
Read more: Third-Party Risk Management software RFP template: questions and scoringEnter your details and we’ll email you the Third Party Risk RFP template: For a lot of organizations, the search for Third-Party Risk Management software starts when the current process stops giving the team a reliable view of risk. Maybe supplier onboarding still runs through email chains, spreadsheets, shared folders, and disconnected questionnaires. Maybe due diligence happens before…
-

Spotlight on Women in GRC: Senior Risk Officer from the banking sector on AI, risk reporting & TPRM
Read more: Spotlight on Women in GRC: Senior Risk Officer from the banking sector on AI, risk reporting & TPRMIn advance of the Women in GRC Awards on 2 July 2026, we are running a podcast series, “Spotlight on Women in GRC”. In this episode, CoreStream GRC Head of Marketing Lucy Montague sits down with Rita Parmar, a Senior Risk Officer with vast experience across the finance sector. As well as Sarbanes-Oxley compliance, governance, regulatory reporting, and non-financial risk. The discussion explores; Rita also shares her…
-

Policy Management software RFP template: questions and scoring
Read more: Policy Management software RFP template: questions and scoringEnter your details and we’ll email you the Policy RFP template: Why do organizations invest in Policy Management software? For many organizations, policy management starts with shared drives, document repositories, spreadsheets, and email-based approvals. While these approaches may work initially, they often become harder to manage as the business grows and compliance requirements increase. The challenge is…
Ready to speak to our experts?
Discover our case studies
The success stories of flexible intuitive GRC technology
-

CASE STUDY: South Western Railway
Reinventing rail compliance: how South Western Railway kept obligations under control through re-nationalization Contracts change. Ownership changes. Reporting lines change. However, what does not change is the impact risk can have on a business. Obligations must be tracked, updated, evidenced, and reported. And if your Governance, Risk & Compliance (GRC) platform cannot flex with the business change, teams fall back to outdated methods; spreadsheets, inbox chasing and hoping nothing gets missed. South Western Railway…
-

GUIDE: buying a GRC platform
How to choose the right GRC software for your business: A buyer’s guide Buying GRC software is rarely just a software decision. By the time most organizations start reviewing platforms, they are usually already dealing with something more structural: fragmented reporting, unclear ownership, too much manual chasing, weak leadership visibility, and governance activity spread across…
-

CASE STUDY: Pool Re
From constraint to control: how CoreStream GRC transformed risk management at Pool Re About Pool Re Pool Re is the UK’s largest terrorism reinsurer, trusted by over 150 insurers and globally recognized as the leading experts in terrorism risk financing. Their mission is to provide financial protection against the risk of terrorism and, in so…
Ready to upgrade your GRC tech?
Contact the team and request your demo today.
This form may not be visible due to adblockers, or JavaScript not being enabled.