In a recent Spotlight on Women in GRC podcast, Lucy Montague sat down with Global Director of Trust & Safety, Sophie Walsh, a risk, integrity and compliance leader whose career spans charities, global technology platforms, and some of the most complex risk environments in modern business. From social care and NGOs to digital regulation and e-commerce, Sophie’s work has been guided by a simple but powerful question: how can organizations earn and maintain trust?
In this conversation, Sophie shares:
- Why trust should be treated as a strategic business asset
- How trust and enterprise risk management are beginning to converge
- Why outcome-based metrics may be more valuable than traditional risk registers
- What boards should understand about trust in the digital age
- How organizations can build cultures that encourage transparency and accountability
- Trust is becoming the defining governance question of the next decade
Trust is becoming the defining governance question of the next decade
When Sophie talks about trust, she’s not referring solely to reputation or public perception:
“The organizations that will win the next decade will be the ones that really treat trust as infrastructure, a genuine driver of value and growth, and not just a PR exercise.”
Sophie Walsh, Global Director of Trust & Safety,
According to Sophie’s definition, trust exists across multiple stakeholder groups as “layers”:
- Customers who share their data
- Regulators who expect accountability
- Communities affected by business decisions
- Employees responsible for delivering organizational objectives
Each group experiences trust differently, but all contribute to long-term business performance and layer together.
This understanding of stakeholder engagement and alignment fits in with broader business trends. Deloitte research highlights that intangible assets such as reputation, relationships, organizational culture, knowledge, and data now represent a significant proportion of enterprise value for modern organizations, making their stewardship increasingly important.
Sophie’s view is that trust sits at the center of these intangible assets.
“You can be fully compliant with every user and every regulator, but still be operating on borrowed trust.”
Sophie Walsh, Global Director of Trust & Safety,
That distinction is becoming increasingly important as organizations navigate complex questions around technology including AI, ethics, privacy, and accountability.
Why enterprise risk management
is evolving beyond traditional risk registers
In a previous Spotlight on Women in GRC episode, former Deloitte partner, Emma Price argued that risk management is shifting from identifying risks to navigating uncertainty. Sophie takes that idea one step further, arguing that the next generation of GRC leaders must focus not only on managing risk, but on earning, measuring, and protecting trust.
As enterprise risk management evolves beyond static risk registers and businesses face growing scrutiny around technology, AI, ethics, and digital regulation, Sophie believes trust is moving from a reputational concern to a strategic business capability.
According to Sophie, the difference between risk and trust is that, traditional risk management was built to answer one question: What could happen to us?
Trust and safety functions, however, often focuses on: What could happen to them?
While enterprise risk teams often focus on organizational exposure, trust and safety professionals are typically focused on the people affected by products, services, technologies, and decisions.
As digital regulation evolves, however, those worlds are becoming increasingly difficult to separate.
“Regulation converts harm to them into risk to us.”
Sophie Walsh, Global Director of Trust & Safety,
Legislation such as the Online Safety Act and the Digital Services Act requires organizations to proactively identify, assess, document, and mitigate risks that could harm users, children, and wider communities. In the EU, failures can result in penalties of up to 6% of annual worldwide turnover, transforming stakeholder harm from an operational issue into a board-level concern. Risk is no longer defined solely by what could happen to the organization. Increasingly, regulators are asking what could happen because of the organization.
The rise of value-based risk management
Sophie’s perspective closely aligns with themes explored by GRC Strategy Director, Paul Cadwallader, who coined the term value-based GRC:
“Value-based GRC aligns governance, risk and compliance with what matters most – the organization’s strategic goals and objectives.”
Paul Cadwallader, GRC Strategy Director, CoreStream GRC
For Sophie, one of the biggest opportunities for GRC leaders lies in moving beyond process-driven measurements and toward outcomes. In trust and safety environments, teams often measure exposure to harm and user impact rather than simply tracking whether controls exist on paper.
“Prevalence is often a better key risk indicator than most risk registers have ever seen because it’s real-time and outcome-based and it’s measuring actual harm rather than processes.”
Sophie Walsh, Global Director of Trust & Safety,
This represents a significant shift in thinking.
Historically, governance functions have focused heavily on policies, documentation, reporting, and assurance. While those remain essential, organizations are increasingly being asked a different question: What outcomes are we delivering?
Rather than measuring activity alone, future-focused organizations are beginning to evaluate whether controls are delivering meaningful results for customers, employees, regulators, and wider stakeholder groups.
GRC pundit, Michael Rasmussen backs up this argument, stating:
“Value-based risk management asks: What are we trying to achieve? What value are we trying to create or protect? What uncertainty could affect that value? What decisions must be made? What confidence do leaders need to act?
This aligns with the essential insight of ISO 31000: risk is the effect of uncertainty on objectives. Yet too many organizations focus almost entirely on the uncertainty and not nearly enough on the objective.”
Michael Rasmussen, Pundit and Founder of GRC 20/20
Trust is a board-level asset. So why isn’t anyone measuring it?
The commercial importance of trust is becoming difficult to ignore.
PwC’s Trust Survey found that 93% of business executives believe building and maintaining trust improves the bottom line. However, the same research found a significant gap between how much trust executives believe they have earned and how much trust customers actually report.
For Sophie, part of the problem is that trust is rarely managed with the same discipline applied to financial or operational assets.
“If 80% of an organization’s assets that were highly valuable were in a physical warehouse, it would be insured, it would be audited, we’d have names against everything and everybody would know who’s accountable. But when trust is essentially that 80% of the warehouse contents, nobody necessarily owns it.”
Sophie Walsh, Global Director of Trust & Safety,
The consequences of failing to protect trust can be significant, trust is often easiest to measure once it has been lost.
Boeing’s 737 MAX crisis evolved from a product safety issue into a much broader governance and trust crisis. Tragically, two crashes claimed 346 lives, prompting a 20-month global grounding of the aircraft and triggering intense scrutiny from regulators, airlines, investors, and the public. What began as a technical failure quickly became a board-level conversation about accountability, decision-making, oversight, and organizational culture.
Volkswagen’s emissions scandal followed a similar trajectory. What initially appeared to be a compliance issue ultimately became a trust crisis affecting approximately 11 million vehicles worldwide. The fallout included regulatory investigations, more than $30 billion in fines and settlements, significant reputational damage, and a sharp decline in market value as stakeholder confidence deteriorated.
In both cases, public attention eventually moved beyond the original incident and focused on a more fundamental question: How did the organization allow this to happen?
As Sophie points out:
“Every major trust failure of the last decade became a governance failure in hindsight.”
Sophie Walsh, Global Director of Trust & Safety,
These examples demonstrate that trust is not simply a reputational issue. When trust breaks down, the impact extends far beyond brand perception, affecting people, governance, regulatory relationships, financial performance, and long-term organizational resilience.
When trust creates valuefor business and the wider community: Patagonia and Lush
While trust failures can destroy value, trust can also become a powerful source of competitive advantage.
Patagonia remains one of the most compelling examples.
In 2011, the company launched its now-famous Don’t Buy This Jacket campaign, encouraging consumers to think more carefully about consumption and openly highlighting the environmental impact associated with its products. At a time when most retailers were competing for Black Friday sales, Patagonia was effectively telling customers to buy less.
On the surface, the campaign appeared commercially risky. In reality, it strengthened trust by demonstrating that the company’s actions aligned with its values.
The results were significant. Patagonia reported revenue growth of around 30% in the year following the campaign. The company has since grown from approximately $540 million in annual revenue in 2011 to around $1.5 billion by 2023.
What made the campaign so powerful was that it reinforced the relationship Patagonia had built with its customers. Rather than focusing solely on products, the company demonstrated a commitment to the environmental values many of its customers shared. Later initiatives, including product repair programs and its Common Threads Initiative, continued to strengthen that trust by prioritising long-term relationships over short-term transactions.
The same principle can be seen in Patagonia founder Yvon Chouinard’s decision to transfer ownership of the company to a trust and nonprofit structure dedicated to fighting climate change. For customers, every major decision reinforced a belief that Patagonia was willing to act on its principles, even when doing so appeared unconventional.
Lush provides a more recent example.
In 2021, the cosmetics retailer deleted its Instagram, Facebook, TikTok, and Snapchat accounts, walking away from more than 10 million followers because of concerns about the impact of social media platforms on mental wellbeing for their customers.
The industry questioned whether the move would damage growth.
Instead, Lush went on to record its strongest UK Christmas trading performance in 2 years, increased physical store sales, and improved profitability from a £45 million loss to a £29 million profit.
Whether customers agreed with the decision or not, the move reinforced an important trust signal: the company was prepared to back its values with action. This aligns with Sophie’s point of what she’s motivated to do, throughout her career:
“Helping organizations to do the right thing in the right way so that they can earn the trust of the people they exist to serve.”
Sophie Walsh, Global Director of Trust & Safety,
Together, Patagonia and Lush demonstrate a lesson many GRC leaders are beginning to recognize: Trust is not simply a reputational asset. It is a value-creating asset.
How do you build a trust-based culture? Start with psychological safety
While trust may increasingly be discussed in boardrooms, Sophie believes it ultimately begins with culture. For leaders looking to create more trusted organizations, the first step is building environments where employees feel safe speaking up.
“Leadership should want to hear it, because you can’t do anything about something unless you know about it.”
Sophie Walsh, Global Director of Trust & Safety,
When employees believe concerns will be ignored, dismissed, or punished, risks stay hidden. The Journal of Pediatric Nursing found that
“Psychological safety is one of the strongest predictors of whether employees report risks, errors, and emerging issues.”
Sophie Walsh, Global Director of Trust & Safety,
Sophie’s view is that this internal layer of trust underpins everything else.
“If you lose your employees’ trust, then you’ll lose the team that delivers for everybody else.”
Sophie Walsh, Global Director of Trust & Safety,
Ultimately, trust is not built through policy alone. It is built through transparency, consistency, accountability, and a willingness to listen.
“The desired GRC culture is frequently one that is inclusive and collaborative.”
Rich Eddolls, Chief Product Officer and Co-Founder at CoreStream GRC

The Future of GRC: trust as a strategic business capability
For decades, governance, risk and compliance programs have focused on controls, reporting, and risk identification, centered around regulations like SOX. Those capabilities remain essential.
But as organizations face increasing scrutiny from regulators, customers, employees, investors, and society, the conversation is expanding. The future of enterprise risk management will not be defined solely by identifying risks. It will be defined by understanding outcomes.
And increasingly, one of the most important outcomes will be trust.
Organizations that can earn trust, measure trust, and protect trust will be better positioned to navigate uncertainty, strengthen stakeholder relationships, and create long-term value.
As Sophie Walsh argues, trust is no longer a communications challenge or a brand exercise. It is becoming one of the most important strategic capabilities in modern GRC.
About Sophie Walsh
Sophie Walsh is a trust, integrity and compliance leader with experience spanning international NGOs, social care charities, and global digital platforms. Her work sits at the intersection of digital regulation, ethics, governance, risk, and compliance, helping organizations build trust with the people they serve. Throughout her career, Sophie has focused on creating responsible, accountable systems that balance innovation, regulatory requirements, and human impact. She is passionate about trust as a driver of long-term business value and believes the organizations that succeed in the next decade will be those that treat trust as a strategic asset rather than a communications exercise.
About the Spotlight on Women in GRC Podcast
Spotlight on Women in GRC is a podcast series created to continue the conversations sparked by the Women in GRC Awards and shine a light on the professionals shaping governance, risk and compliance today. Hosted by CoreStream GRC’s Lucy Montague, the series explores career journeys, leadership lessons and the trends transforming the GRC profession.
Condensed transcript of Sophie Walsh’s women in GRC podcast episode
What does trust mean in an organization?
Lucy Montague: You’ve worked at the intersection of technology, human rights, and risk. How do you define trust in an organization, and why should boards be paying more attention to it?
Sophie Walsh: I think about trust in layers.
The first is trust from users or customers. They have handed over something valuable, whether that’s data, attention, or money, expecting something in return. Organizations lose that trust when they fail to deliver on that bargain.
The second layer is trust with regulators. Regulators don’t need to like you. They need to be able to verify you. Trust in that relationship comes from accountability, evidence, and governance.
The third layer is societal trust. This is trust from people affected by an organization’s decisions even if they never signed up for its products or services. The community affected by a supply chain decision, for example, or an individual impacted by a technology they never chose to use.
Then there’s internal trust. Employees are often the first people to see the gap between stated values and operational reality. If you lose your employees’ trust, you lose the team that delivers for everybody else.
The organizations that will win the next decade will be the ones that treat trust as infrastructure, a genuine driver of value and growth, not just a PR exercise.

Are trust and risk management beginning to converge?
Lucy Montague: Trust and safety is often seen as separate from traditional risk management. Do you think those worlds are coming together?
Sophie Walsh: I think they’re converging in necessity, but not always effectively yet.
Traditional risk management was built to answer the question: What could happen to us?
Trust and safety was built to answer a different question: What could happen to them?
The difference is important because the risk bearer is different.
Risk teams often work with appetite statements, controls, and residual risk. Trust and safety teams often focus on harm reduction, prevalence, and real-world outcomes. In many organizations, the two functions are speaking different languages despite trying to solve related problems.
What is changing is regulation.
The Online Safety Act, the Digital Services Act, and similar frameworks place risk assessments at the center of organizations’ duties. They’re effectively converting harm to users into risk for the business.
Regulation converts harm to them into risk to us.
I also think there are lessons each discipline can learn from the other. Trust and safety teams often use real-time, outcome-focused measures of harm. Traditional risk management brings governance, accountability, and structure. The future opportunity is bringing those strengths together.

Why outcome-based risk management matters
Lucy Montague: Emma Price recently talked about moving beyond static risk registers and focusing more on outcomes. Does that resonate with you?
Sophie Walsh: Absolutely.
In trust and safety, we often use prevalence metrics to understand how frequently users are exposed to harm. That’s often a better key risk indicator than many traditional risk registers because it’s real-time and outcome-based.
It’s measuring actual harm rather than whether a process exists.
I think there are organizations doing genuinely brilliant protection work that struggle to evidence it, while others have immaculate documentation that has drifted away from actual harm.
The future isn’t choosing one approach over the other.
It’s combining both. Organizations need to be able to protect people and prove they’re protecting people.

How can organizations build trust internally?
Lucy Montague: If someone joins an organization that doesn’t have a strong trust culture, where should they start?
Sophie Walsh: Trust starts with how people show up every day.
Anybody can help create a culture of trust by creating an environment where people genuinely feel heard and included.
When people feel psychologically safe, they’re more willing to raise concerns and share bad news. That matters because leadership should want to hear the difficult information.
You can’t do anything about something unless you know about it.
By creating transparency and honest conversations, organizations can begin solving problems earlier and build a stronger culture of trust over time.

What will define the next era of GRC?
Lucy Montague: Looking ahead, what do you think will define the next era of governance, risk, and compliance?
Sophie Walsh: I think the next era of GRC will be defined by the convergence of traditional risk management and trust-focused disciplines.
Many organizations are very strong at governance and proving compliance. Others are very strong at understanding and reducing harm. The opportunity is bringing those worlds together.
Digital regulation is accelerating that change by forcing organizations to think differently about accountability, stakeholder impact, and outcomes.
The organizations that succeed will be those that understand trust isn’t separate from risk management.
Trust will increasingly become one of the defining governance questions of the next decade.
FAQs about trust and risk management
In GRC, trust refers to the confidence stakeholders have that an organization acts responsibly, transparently, and consistently. It is built through strong governance, accountable decision-making, effective risk management, and evidence that the organization is delivering the outcomes it promises.
Trust is important because many of today’s most significant risks are stakeholder-led. Customers, employees, regulators, investors, and communities judge organizations not only by whether they comply with rules, but by whether their actions protect people, uphold values, and create confidence over time.
Organizations can begin measuring trust by looking beyond policies and controls to indicators such as customer confidence, employee speak-up rates, issue escalation speed, regulatory feedback, stakeholder sentiment, complaints, control effectiveness, and evidence of real-world outcomes.
Outcome-based GRC shifts the focus from whether processes exist to whether they are producing meaningful results. Instead of measuring only activity, such as completed assessments or documented controls, it asks whether those controls are reducing harm, supporting objectives, and strengthening stakeholder confidence.
Value-based GRC aligns governance, risk, and compliance with the organization’s strategic goals and value creation priorities. It helps leaders understand which risks could affect the outcomes that matter most, what value needs to be protected, and where risk decisions can enable better business performance.
GRC brings governance, risk, and compliance activities together into a connected operating model. ERM focuses more specifically on identifying, assessing, managing, and monitoring risks that could affect strategic objectives. The strongest organizations use both: ERM to understand enterprise risk and GRC to operationalize controls, accountability, and compliance.
Traditional risk registers can be useful, but they often become static records of potential issues. Modern GRC leaders need more dynamic, outcome-based indicators that show how risks are changing, whether controls are working, and how decisions affect stakeholders in real time.
Boards can treat trust as a strategic asset by assigning clear ownership, reviewing trust-related metrics, connecting stakeholder harm to enterprise risk, asking how major decisions affect confidence, and ensuring culture, transparency, and accountability are part of governance oversight.
Psychological safety helps employees raise concerns, report issues, and challenge decisions before risks escalate. When people feel safe to speak up, organizations are more likely to identify emerging risks early and respond before those risks become governance or trust failures.
The future of GRC will be more strategic, outcome-led, and trust-centered. As organizations face growing scrutiny around AI, digital regulation, privacy, ethics, resilience, and stakeholder impact, GRC will increasingly focus on helping leaders earn, measure, and protect trust as a core business capability.


