Author: Esme Dyos
-

CoreStream GRC shortlisted for Best Use of AI in GRC, and together with SANNOS for Technology Innovation in GRC at the #RISK Awards 2026
Read more: CoreStream GRC shortlisted for Best Use of AI in GRC, and together with SANNOS for Technology Innovation in GRC at the #RISK Awards 2026London, 9th September 2026 – CoreStream GRC, in partnership with SANNOS AI, is proud to announce that it has been shortlisted for the Technology Innovation in GRC: SME category at the RISK Awards 2026, recognizing innovative solutions that are transforming how Governance, Risk & Compliance is delivered. Recognition for innovation in modern GRC “Innovation isn’t defined by the size of an organization, it’s defined by how effectively new ideas are turned into…
-

Norway’s BankID outage shows what DORA-grade third-party risk management actually requires
Read more: Norway’s BankID outage shows what DORA-grade third-party risk management actually requiresFor 2 days, millions of Norwegians couldn’t sign a contract, complete a house sale or access a health record because a single supplier’s infrastructure failed for the second time in 5 years. What happens when an entire country’s digital ID depends on a single supplier? On the morning of 3 September 2026, a real estate agent in…
-

CoreStream GRC & BRAVE: a differentiated transformative partnership helping directors move from managing risk to confident decision making
Read more: CoreStream GRC & BRAVE: a differentiated transformative partnership helping directors move from managing risk to confident decision makingObjectives@Risk™ Powered by CoreStream GRC combines objective-centric governance, risk and resilience expertise with flexible GRC technology to enable better decisions in an increasingly uncertain and fast-moving world. Organizations are operating in an environment where disruption is no longer an occasional event. Recent Corporate Governance Institute research highlighted the confidence paradox amongst boards. 85% are confident in the information they receive but only 35% feel they adequately understand and have access to…
-

There are no new risks, only new combinations: how pre-mortems and digital twins help GRC teams anticipate cascading risks
Read more: There are no new risks, only new combinations: how pre-mortems and digital twins help GRC teams anticipate cascading risksKey takeaways Introduction: when risks combine resilience can suffer When national governments began locking down in spring 2020, few risk registers anywhere carried a line for “global shortage of automotive microchips.” Carmakers, forecasting a pandemic-driven collapse in demand, canceled their orders just as consumer electronics manufacturers absorbed the freed-up capacity to build laptops and games consoles for people stuck at…
-

Risk
Read more: RiskWhat is risk? Risk is the effect of uncertainty on an organization’s objectives. In simple terms, risk is what could happen that may affect whether an organization achieves what it set out to do. In governance, risk, and compliance (GRC), risk matters because decisions are rarely made with perfect certainty. Organizations need a clear way…
-

Third party risk management
Read more: Third party risk managementThird party risk management is the process of identifying, assessing, monitoring, and managing the risks that come from working with external organizations. These third parties can include suppliers, vendors, contractors, service providers, consultants, technology providers, outsourced partners, and other external relationships. In governance, risk, and compliance (GRC), third party risk management matters because organizations are…
-

The CareCloud data breach: a third-party risk warning for healthcare compliance teams
Read more: The CareCloud data breach: a third-party risk warning for healthcare compliance teamsKey takeaways Introduction: the changing face of a healthcare data hack In early August 2026, patients of various US healthcare providers began opening data breach notifications from a company many had never heard of: CareCloud, the cloud-based electronic health record and billing platform their doctor’s office quietly ran in the background. The letter said their…
-

CoreStream GRC to attend Gartner’s Enterprise Risk, Audit & Compliance Conference 2026
Read more: CoreStream GRC to attend Gartner’s Enterprise Risk, Audit & Compliance Conference 2026CoreStream GRC, the GRC platform that truly works for you, is pleased to be attending the Gartner Enterprise Risk, Audit & Compliance Conference 2026 in Grapevine, Texas, bringing together risk, audit, compliance, and governance leaders to explore the future of enterprise risk management, AI, regulatory intelligence, and business resilience. Traditional risk programs are often too rigid and retrospective to…
-

Spotlight on Women in GRC on value-based internal audit and why business value matters more than findings
Read more: Spotlight on Women in GRC on value-based internal audit and why business value matters more than findingsIn a recent Spotlight on Women in GRC podcast, Lucy Montague sat down with Rachel Paddon, Director of Internal Audit and Risk at Coats Group plc, to discuss the evolution of internal audit, risk-based assurance, and the growing expectation for GRC functions to deliver measurable business value. Having recently expanded her remit from internal audit into enterprise…
-

Healthcare compliance and HIPPA
Read more: Healthcare compliance and HIPPAWhat is healthcare compliance and HIPAA? Healthcare compliance is the process of meeting the laws, regulations, standards, policies, ethical rules, and patient safety requirements that apply to healthcare organizations. HIPAA, often misspelled as HIPPA, is 1 of the most important healthcare compliance laws in the United States because it sets rules for protecting health information…