• There are no new risks, only new combinations: how pre-mortems and digital twins help GRC teams anticipate cascading risks 

    There are no new risks, only new combinations: how pre-mortems and digital twins help GRC teams anticipate cascading risks 

    Key takeaways  Introduction: when risks combine resilience can suffer  When national governments began locking down in spring 2020, few risk registers anywhere carried a line for “global shortage of automotive microchips.” Carmakers, forecasting a pandemic-driven collapse in demand, canceled their orders just as consumer electronics manufacturers absorbed the freed-up capacity to build laptops and games consoles for people stuck at…

  • Risk

    Risk

    What is risk? Risk is the effect of uncertainty on an organization’s objectives. In simple terms, risk is what could happen that may affect whether an organization achieves what it set out to do. In governance, risk, and compliance (GRC), risk matters because decisions are rarely made with perfect certainty. Organizations need a clear way…

  • Third party risk management

    Third party risk management

    Third party risk management is the process of identifying, assessing, monitoring, and managing the risks that come from working with external organizations. These third parties can include suppliers, vendors, contractors, service providers, consultants, technology providers, outsourced partners, and other external relationships. In governance, risk, and compliance (GRC), third party risk management matters because organizations are…

  • The CareCloud data breach: a third-party risk warning for healthcare compliance teams

    The CareCloud data breach: a third-party risk warning for healthcare compliance teams

    Key takeaways Introduction: the changing face of a healthcare data hack In early August 2026, patients of various US healthcare providers began opening data breach notifications from a company many had never heard of: CareCloud, the cloud-based electronic health record and billing platform their doctor’s office quietly ran in the background. The letter said their…

  • CoreStream GRC to attend Gartner’s Enterprise Risk, Audit & Compliance Conference 2026 

    CoreStream GRC to attend Gartner’s Enterprise Risk, Audit & Compliance Conference 2026 

    CoreStream GRC, the GRC platform that truly works for you, is pleased to be attending the Gartner Enterprise Risk, Audit & Compliance Conference 2026 in Grapevine, Texas, bringing together risk, audit, compliance, and governance leaders to explore the future of enterprise risk management, AI, regulatory intelligence, and business resilience.   Traditional risk programs are often too rigid and retrospective to…

  • Spotlight on Women in GRC on value-based internal audit and why business value matters more than findings 

    Spotlight on Women in GRC on value-based internal audit and why business value matters more than findings 

    In a recent Spotlight on Women in GRC podcast, Lucy Montague sat down with Rachel Paddon, Director of Internal Audit and Risk at Coats Group plc, to discuss the evolution of internal audit, risk-based assurance, and the growing expectation for GRC functions to deliver measurable business value. Having recently expanded her remit from internal audit into enterprise…