GRC blogs
Explore our blogs for expert insights, industry updates, and practical guidance
Designed to challenge ways of thinking and help your enterprise excel in GRC.

-

Michael Rasmussen podcast with Richard Eddolls: why CoreStream GRC focuses on value-based GRC technology
Read more: Michael Rasmussen podcast with Richard Eddolls: why CoreStream GRC focuses on value-based GRC technologySpeakers: Michael Rasmussen, GRC 20/20, and Richard Eddolls, Co-Founder and Chief Product Officer, CoreStream GRC In this episode of The Hitchhiker’s Guide in the GRC Technology Galaxy, Michael Rasmussen returned to CoreStream GRC’s London office to speak with Richard Eddolls, Co-Founder and Chief Product Officer at CoreStream GRC. The conversation explored the origins of CoreStream GRC, why flexibility and usability still matter in enterprise…
-

5 overlooked retail GRC risks senior leaders should be watching
Read more: 5 overlooked retail GRC risks senior leaders should be watchingKey takeaways Retail leaders are focused on growth, margin, resilience, customer trust and operational performance. For GRC teams to add real value, they need to connect risk and controls to those outcomes, not manage them in isolation. Recent retail examples show why this matters. Lindsay Haselhurst, Chief Operating Officer at Currys, said retail crime statistics “make for difficult reading”, but the…
-

Spotlight on Women in GRC: Risk Director on AI, trust & career paths
Read more: Spotlight on Women in GRC: Risk Director on AI, trust & career pathsIn anticipation for the Women in GRC Awards on 2nd July 2026, we’re running a podcast series “Spotlight on Women in GRC”. In this first episode, Head of Marketing, Lucy Montague of CoreStream GRC sits down with Lauren de Thibault, a Risk Director at a leading global telecommunications company and previous Women in GRC Award winner, and shares how a career spanning law, compliance, governance and risk shaped her leadership style. The…
-

What is the Secure Controls Framework and why does it matter for compliance?
Read more: What is the Secure Controls Framework and why does it matter for compliance?Key takeaways Compliance teams are not short of frameworks. They are short of time, clarity and defensible evidence. The Secure Controls Framework, or SCF, is designed to reduce duplication by consolidating 200+ laws, regulations and frameworks into a single control architecture. SCF covers 1,400+ controls across 33 domains, giving organizations a clearer way to understand…
-

Why GRC platforms need to keep pace with business change
Read more: Why GRC platforms need to keep pace with business changeA GRC platform should not only reflect how your business worked on day 1. It should reflect how your business works now and into the future. Contracts change. Ownership models shift. Reporting lines move. New teams come into scope. New obligations appear. Historic records still matter, but they should not make live work harder to…
-

EHS, ESG and GRC: why sustainability compliance now belongs at the heart of risk
Read more: EHS, ESG and GRC: why sustainability compliance now belongs at the heart of riskHow Enhesa and CoreStream GRC GRC help you turn EHS and sustainability pressure into a joined up, defensible GRC program If you want to see how leading organizations are folding EHS and ESG into their core GRC framework, this is the place to start. 1. Integrating Environment, Health & Safety (EHS), Environmental, Social, and Governance…
-

Effective AI-enabled GRC: how to implement trusted, verified AI into risk and compliance
Read more: Effective AI-enabled GRC: how to implement trusted, verified AI into risk and complianceAbstract AI has moved quickly from boardroom curiosity to operational pressure. GRC teams are being asked to reduce manual work, strengthen assurance, and do more with the same headcount. The problem is that generic AI can sound right while producing outputs that are hard to evidence, hard to explain, and impossible to defend in front…
-

A value-based GRC guide for unique SMEs
Read more: A value-based GRC guide for unique SMEsValue-based Governance, Risk and Compliance (GRC) is not about buying an overly complex platform, copying what a global enterprise does and it is more than penalties avoided or hours saved. For smaller and mid-sized businesses, it is much more straightforward than that. It is about aligning GRC to what matters most, the organization’s strategic goals…
-

Short snippet of GRC 2020’s Conflict of Interest solution perspective
Read more: Short snippet of GRC 2020’s Conflict of Interest solution perspectiveAt CoreStream GRC, we believe Conflict of Interest (COI) Management should go beyond checkbox compliance: “A mature program treats conflict management as continuous, not episodic.” It’s one of our most in‑demand solutions precisely because many organizations are rethinking whether their existing approaches truly stand up to today’s regulatory scrutiny. To put that belief to the test, we invited trusted GRC industry analyst Michael Rasmussen to…
-

Gifts and Entertainment software RFP template: questions and scoring
Read more: Gifts and Entertainment software RFP template: questions and scoringEnter your details and we’ll email you the G&E RFP template: From talking with our expert community, we know that for a lot of teams, the search for gifts and entertainment software starts when the current process stops feeling defensible. Maybe declarations still sit across email chains, spreadsheets, shared folders, or basic forms that were never built for sensitive compliance…
Ready to speak to our experts?
Discover our case studies
The success stories of flexible intuitive GRC technology
-

CASE STUDY: South Western Railway
Reinventing rail compliance: how South Western Railway kept obligations under control through re-nationalization Contracts change. Ownership changes. Reporting lines change. However, what does not change is the impact risk can have on a business. Obligations must be tracked, updated, evidenced, and reported. And if your Governance, Risk & Compliance (GRC) platform cannot flex with the business change, teams fall back to outdated methods; spreadsheets, inbox chasing and hoping nothing gets missed. South Western Railway…
-

CASE STUDY: COI GRC 2020 solution perspective
The client stories behind Michael Rasmussen’s Conflict of Interest Management solution perspective for CoreStream GRC Introduction Michael Rasmussen, globally recognized GRC thought leader and former Forrester analyst who originally defined the Governance, Risk, and Compliance market, recently drafted his perspective on CoreStream GRC’s conflict of interest solution. For this analysis, Michael engaged with 3 organizations actively using the CoreStream GRC platform to manage conflicts of interest. While operating in…
-

CASE STUDY: Implementation success story
Raising the bar on Conflict of Interest management: CoreStream GRC’s high quality implementation services success story Everyone’s heard the horror stories of GRC implementations that drag on for months, sometimes years, with personnel moving in and out as people leave before the project is done. It’s no wonder risk and compliance teams cling to the devil they know. The fear of scope creep, decision paralysis, slipping timelines, and sheer…
Ready to upgrade your GRC tech?
Contact the team and request your demo today.
This form may not be visible due to adblockers, or JavaScript not being enabled.