Author: Erin Hardwick
-

Lombard Odier’s money-laundering conviction shows why flagging a compliance risk isn’t enough
Read more: Lombard Odier’s money-laundering conviction shows why flagging a compliance risk isn’t enoughKey takeaways Introduction: failure to go beyond filing a risk report leads to an AML conviction In 2012, a Geneva private bank, Lombard Odier, noticed unusual activity connected to one relationship manager’s client accounts and reported their suspicions to Switzerland’s Money Laundering Reporting Office. 14 years of legal process, and one collapsed prosecution against the alleged ringleader, later, Switzerland’s Federal Criminal Court…
-

Spotlight on Women in GRC: Emma Price on curiosity, creativity and why value-based GRC starts with better questions
Read more: Spotlight on Women in GRC: Emma Price on curiosity, creativity and why value-based GRC starts with better questionsIn this episode of CoreStream GRC’s Spotlight on Women in GRC podcast, Lucy Montague sits down with Emma Price, Partner at Brave, former Deloitte partner and one of the UK’s leading voices in risk and resilience. With more than 25 years of experience helping boards navigate uncertainty, Emma shares: Curiosity: The skill that launched a 25-year career in GRC and a…
-

CoreStream GRC 3.6 Release Notes
Read more: CoreStream GRC 3.6 Release Notes1.0 Document purpose This document provides a summary of the highlights of the CoreStream GRC Release 3.6 release. Major Platform releases are finalized every 2-3 months depending on client and strategic priorities. These release notes are part of CoreStream GRC’s approach to keeping clients and partners informed of the improvements we are delivering. This document…
-

Coca-Cola’s Fairlife ransomware attack: why risk doesn’t respect the org chart
Read more: Coca-Cola’s Fairlife ransomware attack: why risk doesn’t respect the org chartKey takeaways How Fairlife’s cyberattack became a group governance issue On July 16, 2026, Coca-Cola disclosed that Fairlife, its dairy business, had detected unauthorized access to a section of its network, including production-linked systems. Production at Fairlife’s 4 US factories stopped. Canadian production continued. Product on shelves stayed safe. A ransomware-as-a-service group calling itself Anubis claimed responsibility, saying it had taken 1 terabyte of data and threatening to leak it. According to…
-

Simplifying risk in a complex world to achieve business objectives – key findings from the Spotlight on Women in GRC
Read more: Simplifying risk in a complex world to achieve business objectives – key findings from the Spotlight on Women in GRCIn this episode of CoreStream GRC’s Spotlight on Women in GRC podcast, Lucy Montague speaks with Sharon Sharples, Chief of Staff and Head of Operational Risk Governance and Insights at Barclays, about her journey from change management into risk leadership, the evolving role of GRC in modern organizations, and why curiosity, simplification, and flexibility will define the…
-

Regulatory compliance including SCF compliance frameworks
Read more: Regulatory compliance including SCF compliance frameworksWhat is regulatory compliance? Regulatory compliance is the process of meeting the laws, rules, standards, and requirements set by regulators, governments, and supervisory bodies. It helps organizations understand which external obligations apply, assign ownership, operate controls, collect evidence, and report when required. In governance, risk, and compliance (GRC), regulatory compliance matters because regulatory expectations rarely…
-

Compliance
Read more: ComplianceWhat is compliance? Compliance is the process of meeting the laws, regulations, standards, policies, contractual requirements, and ethical expectations that apply to an organization. In simple terms, compliance helps organizations understand what they are required to do, assign ownership, operate controls, evidence activity, and respond when something goes wrong. In governance, risk, and compliance (GRC),…
-

Beyond the token bill: why AI governance now means budgeting, sovereignty and capacity, not just risk
Read more: Beyond the token bill: why AI governance now means budgeting, sovereignty and capacity, not just riskKey takeaways Introduction: the hidden costs of AI for GRC teams In May, engineers at Uber found that they had spent an entire year’s AI budget in just four months. The culprit was Claude Code, rolled out enthusiastically across the organization to speed up software development. It worked. It also cost so much, so fast, that leadership had to step in and cap…
-

Spotlight on Women in GRC: Woman of the Year on intergenerational learning, AI and the future of GRC
Read more: Spotlight on Women in GRC: Woman of the Year on intergenerational learning, AI and the future of GRCIn this special episode of CoreStream GRC’s Spotlight on Women in GRC podcast, Lucy Montague speaks with Yvonne Gordon, 2026 Women in GRC Woman of the Year and Head of Compliance and Continuous Improvement, about her unconventional route into governance, risk and compliance, the importance of mentorship, and why creating opportunities for others has become her personal mission. The…
-

UK Corporate Governance Code
Read more: UK Corporate Governance CodeWhat is the UK Corporate Governance Code? The UK Corporate Governance Code is the Financial Reporting Council’s corporate governance framework for listed companies in the UK. It sets out principles and provisions covering board leadership, company purpose, division of responsibilities, board composition, succession, evaluation, audit, risk, internal control, and remuneration. The Financial Reporting Council explains…