• Compliance audit

    Compliance audit

    What is a compliance audit? A compliance audit is a structured review that checks whether an organization is meeting specific laws, regulations, standards, policies, contractual requirements, or internal controls. It helps confirm whether compliance requirements are understood, owned, evidenced, and operating in practice. In governance, risk, and compliance (GRC), a compliance audit matters because it…

  • Compliance reporting

    Compliance reporting

    What is compliance reporting? Compliance reporting is the process of collecting, analyzing, and presenting information that shows whether an organization is meeting its compliance obligations. It helps leadership, boards, auditors, regulators, and internal stakeholders understand compliance status, control effectiveness, issues, breaches, remediation, and areas needing attention. In governance, risk, and compliance (GRC), compliance reporting matters…

  • Compliance management software

    Compliance management software

    What is compliance management software? Compliance management software is a digital system that helps organizations manage compliance obligations, controls, policies, evidence, issues, remediation, and reporting in 1 connected place. It gives compliance teams a clearer way to understand what requirements apply, who owns them, what actions are due, and what evidence proves compliance activity has…

  • Too much faith in frameworks: The governance limits of industry standard certifications

    Too much faith in frameworks: The governance limits of industry standard certifications

    Key takeaways  Introduction: when GRC certification becomes destination  At a recent CoreStream GRC webinar on the modern CISO’s compliance stack, the panel was asked a blunt question: are there any regulations, frameworks or certifications that organizations place too much faith in? Tom Cornelius, founder of the Secure Controls Framework and senior partner at ComplianceForge, didn’t hesitate. He named SOC 2 and ISO 27001 directly, and called the market that…

  • Lombard Odier’s money-laundering conviction shows why flagging a compliance risk isn’t enough 

    Lombard Odier’s money-laundering conviction shows why flagging a compliance risk isn’t enough 

    Key takeaways  Introduction: failure to go beyond filing a risk report leads to an AML conviction  In 2012, a Geneva private bank, Lombard Odier, noticed unusual activity connected to one relationship manager’s client accounts and reported their suspicions to Switzerland’s Money Laundering Reporting Office.  14 years of legal process, and one collapsed prosecution against the alleged ringleader, later, Switzerland’s Federal Criminal Court…

  • Spotlight on Women in GRC: Emma Price on curiosity, creativity and why value-based GRC starts with better questions 

    Spotlight on Women in GRC: Emma Price on curiosity, creativity and why value-based GRC starts with better questions 

    In this episode of CoreStream GRC’s Spotlight on Women in GRC podcast, Lucy Montague sits down with Emma Price, Partner at Brave, former Deloitte partner and one of the UK’s leading voices in risk and resilience.   With more than 25 years of experience helping boards navigate uncertainty, Emma shares:  Curiosity: The skill that launched a 25-year career in GRC and a…