Author: Esme Dyos
-

Regulatory compliance including SCF compliance frameworks
Read more: Regulatory compliance including SCF compliance frameworksWhat is regulatory compliance? Regulatory compliance is the process of meeting the laws, rules, standards, and requirements set by regulators, governments, and supervisory bodies. It helps organizations understand which external obligations apply, assign ownership, operate controls, collect evidence, and report when required. In governance, risk, and compliance (GRC), regulatory compliance matters because regulatory expectations rarely…
-

Compliance
Read more: ComplianceWhat is compliance? Compliance is the process of meeting the laws, regulations, standards, policies, contractual requirements, and ethical expectations that apply to an organization. In simple terms, compliance helps organizations understand what they are required to do, assign ownership, operate controls, evidence activity, and respond when something goes wrong. In governance, risk, and compliance (GRC),…
-

Beyond the token bill: why AI governance now means budgeting, sovereignty and capacity, not just risk
Read more: Beyond the token bill: why AI governance now means budgeting, sovereignty and capacity, not just riskKey takeaways Introduction: the hidden costs of AI for GRC teams In May, engineers at Uber found that they had spent an entire year’s AI budget in just four months. The culprit was Claude Code, rolled out enthusiastically across the organization to speed up software development. It worked. It also cost so much, so fast, that leadership had to step in and cap…
-

Spotlight on Women in GRC: Woman of the Year on intergenerational learning, AI and the future of GRC
Read more: Spotlight on Women in GRC: Woman of the Year on intergenerational learning, AI and the future of GRCIn this special episode of CoreStream GRC’s Spotlight on Women in GRC podcast, Lucy Montague speaks with Yvonne Gordon, 2026 Women in GRC Woman of the Year and Head of Compliance and Continuous Improvement, about her unconventional route into governance, risk and compliance, the importance of mentorship, and why creating opportunities for others has become her personal mission. The…
-

UK Corporate Governance Code
Read more: UK Corporate Governance CodeWhat is the UK Corporate Governance Code? The UK Corporate Governance Code is the Financial Reporting Council’s corporate governance framework for listed companies in the UK. It sets out principles and provisions covering board leadership, company purpose, division of responsibilities, board composition, succession, evaluation, audit, risk, internal control, and remuneration. The Financial Reporting Council explains…
-

AI governance
Read more: AI governanceWhat is AI governance? AI governance is the system an organization uses to direct, oversee, control, and evidence the way artificial intelligence is developed, bought, deployed, monitored, and used. It covers who can approve AI use, what risks need to be assessed, what data can be used, how outputs are reviewed, how decisions are documented,…
-

The EU delayed its AI Act deadline: what the Digital Omnibus means for AI governance everywhere
Read more: The EU delayed its AI Act deadline: what the Digital Omnibus means for AI governance everywhereKey takeaways Introduction: the AI compliance deadline GRC teams have been racing toward just moved For eighteen months, “2 August 2026” has been a fixed point on the calendar for compliance, risk and AI governance teams across Europe, and well beyond. This was the date the EU AI Act’s toughest obligations, covering high-risk AI systems, were due to bite: conformity assessments, technical…
-

Spotlight on Women in GRC: DPO on GDPR, privacy culture and ESG
Read more: Spotlight on Women in GRC: DPO on GDPR, privacy culture and ESGIn this episode of CoreStream GRC’s Spotlight on Women in GRC podcast, Lucy Montague sits down with the series’ first DPO, Lorraine Pinter, to discuss her journey from law into privacy, the evolution of GDPR, building confidence as a leader, and why data protection remains one of the most impactful and personally relevant areas of GRC. The DPO’s podcast episode explores: Starting your…
-

The future of GRC: what principles-based regulation means for GRC teams
Read more: The future of GRC: what principles-based regulation means for GRC teamsKey takeaways Introduction: the GRC rulebook is getting smaller, as accountability grows Ask any compliance officer what’s changed in their job over the last two years, and few will point to a single new regulation. They will point to something harder to pin down: a growing expectation that they explain and defend their own judgment, rather than simply follow a rule written by someone…
-

Board governance
Read more: Board governanceWhat is board governance? Board governance is the way a board of directors directs, oversees, and holds an organization accountable. It covers how the board sets strategic direction, challenges management, monitors performance, oversees risk and internal controls, and makes decisions in the interests of the organization and its stakeholders. In governance, risk, and compliance (GRC), board governance…