• Why easy login can create risk in GRC and Conflict of Interest systems 

    Why easy login can create risk in GRC and Conflict of Interest systems 

    By Mike VidoniSenior GRC Client Executive & Customer Success, CoreStream GRC  Key takeaways  Introduction: When does convenience become a control weakness?  GRC teams need people to use their systems. A Conflict of Interest process cannot work properly if employees,  or board members struggle to complete disclosures because the process is unnecessarily complicated.  But login design is not simply a usability decision. It…

  • What is ISO 27001? A practical guide to information security management 

    What is ISO 27001? A practical guide to information security management 

    Abstract  ISO 27001 gives organizations a structured way to manage information security risk. But for many teams, the real challenge is not understanding the standard. It is maintaining the evidence, ownership and control visibility needed to prove the system works.  This guide should explain what ISO 27001 is, why it matters, how certification works, what Annex A controls cover, and why…

  • World Cup stadium strike was narrowly averted: how resilient are your critical suppliers? 

    World Cup stadium strike was narrowly averted: how resilient are your critical suppliers? 

    Key takeaways Introduction: What happened at the 2026 World Cup?   Days before the World Cup began, a supplier issue at one of the tournament’s highest-profile venues was narrowly avoided. Reuters reported that a union representing around 2,000 food and beverage workers at SoFi Stadium reached a tentative agreement with Legends Hospitality only days before the tournament. AP described the agreement as averting a…

  • Is the vendor risk assessment dead?

    Is the vendor risk assessment dead?

    Is the traditional vendor questionnaire still fit for purpose?  Imagine beginning a vendor assessment without sending another 200-question form.  Before contacting the third party, you already understand who the organization is, who sits behind it, and whether there are public risk signals that warrant closer attention. You can ask the vendor for the evidence it already holds, identify the gaps that…

  • Governance structure

    Governance structure

    What is a governance structure?  A governance structure is the way an organization organizes authority, oversight, accountability, and decision-making. It explains who has the power to decide, who needs to approve, who must be consulted, what gets escalated, and how leadership can see whether the organization is operating in line with its objectives.  In GRC, a governance structure matters…

  • Governance framework

    Governance framework

    What is a governance framework? A governance framework is the structure an organization uses to guide decision-making, assign accountability, manage oversight, and demonstrate how governance works in practice. It sets out who has authority, which decisions require approval, how issues are escalated, and how governance activity is monitored and reported.  In governance, risk and compliance (GRC), a clear governance…