GRC blogs
Explore our blogs for expert insights, industry updates, and practical guidance
Designed to challenge ways of thinking and help your enterprise excel in GRC.

-

Spotlight on Women in GRC: Risk Director on AI, trust & career paths
Read more: Spotlight on Women in GRC: Risk Director on AI, trust & career pathsIn anticipation for the Women in GRC Awards on 2nd July 2026, we’re running a podcast series “Spotlight on Women in GRC”. In this first episode, Head of Marketing, Lucy Montague of CoreStream GRC sits down with Lauren de Thibault, a Risk Director at a leading global telecommunications company and previous Women in GRC Award winner, and shares how a career spanning law, compliance, governance and risk shaped her leadership style. The…
-

What is the Secure Controls Framework and why does it matter for compliance?
Read more: What is the Secure Controls Framework and why does it matter for compliance?Key takeaways Compliance teams are not short of frameworks. They are short of time, clarity and defensible evidence. The Secure Controls Framework, or SCF, is designed to reduce duplication by consolidating 200+ laws, regulations and frameworks into a single control architecture. SCF covers 1,400+ controls across 33 domains, giving organizations a clearer way to understand…
-

Why GRC platforms need to keep pace with business change
Read more: Why GRC platforms need to keep pace with business changeA GRC platform should not only reflect how your business worked on day 1. It should reflect how your business works now and into the future. Contracts change. Ownership models shift. Reporting lines move. New teams come into scope. New obligations appear. Historic records still matter, but they should not make live work harder to…
-

EHS, ESG and GRC: why sustainability compliance now belongs at the heart of risk
Read more: EHS, ESG and GRC: why sustainability compliance now belongs at the heart of riskHow Enhesa and CoreStream GRC GRC help you turn EHS and sustainability pressure into a joined up, defensible GRC program If you want to see how leading organizations are folding EHS and ESG into their core GRC framework, this is the place to start. 1. Integrating Environment, Health & Safety (EHS), Environmental, Social, and Governance…
-

Effective AI-enabled GRC: how to implement trusted, verified AI into risk and compliance
Read more: Effective AI-enabled GRC: how to implement trusted, verified AI into risk and complianceAbstract AI has moved quickly from boardroom curiosity to operational pressure. GRC teams are being asked to reduce manual work, strengthen assurance, and do more with the same headcount. The problem is that generic AI can sound right while producing outputs that are hard to evidence, hard to explain, and impossible to defend in front…
-

A value-based GRC guide for unique SMEs
Read more: A value-based GRC guide for unique SMEsValue-based Governance, Risk and Compliance (GRC) is not about buying an overly complex platform, copying what a global enterprise does and it is more than penalties avoided or hours saved. For smaller and mid-sized businesses, it is much more straightforward than that. It is about aligning GRC to what matters most, the organization’s strategic goals…
-

Short snippet of GRC 2020’s Conflict of Interest solution perspective
Read more: Short snippet of GRC 2020’s Conflict of Interest solution perspectiveAt CoreStream GRC, we believe Conflict of Interest (COI) Management should go beyond checkbox compliance: “A mature program treats conflict management as continuous, not episodic.” It’s one of our most in‑demand solutions precisely because many organizations are rethinking whether their existing approaches truly stand up to today’s regulatory scrutiny. To put that belief to the test, we invited trusted GRC industry analyst Michael Rasmussen to…
-

Gifts and Entertainment software RFP template: questions and scoring
Read more: Gifts and Entertainment software RFP template: questions and scoringEnter your details and we’ll email you the G&E RFP template: From talking with our expert community, we know that for a lot of teams, the search for gifts and entertainment software starts when the current process stops feeling defensible. Maybe declarations still sit across email chains, spreadsheets, shared folders, or basic forms that were never built for sensitive compliance…
-

The value-based guide to GDPR: EU and UK privacy compliance optimization
Read more: The value-based guide to GDPR: EU and UK privacy compliance optimizationAt its best, General Data Protection Regulation (GDPR) was never meant to be a paperwork regime. It was meant to change behavior. GDPR is a framework for making better decisions about data, proving accountability, reducing operational confusion, building trust, and protecting the business as it grows. That is the part too many organizations still miss…
-

Intelligence‑first GRC: the AI webinar every risk & compliance leader should watch
Read more: Intelligence‑first GRC: the AI webinar every risk & compliance leader should watchSpeakers: SANNOS’ CEO and CoreStream GRC’s GRC Strategy Director In the session, we explored why generic AI is falling short in regulated environments, what trusted, evidence-based AI looks like in practice, and how intelligence-first GRC can help teams reduce manual effort without losing confidence, control, or auditability. If you missed the live session, or want…
Ready to speak to our experts?
Discover our case studies
The success stories of flexible intuitive GRC technology
-

GUIDE : Value-based compliance culture
Practical guide to implementing value-based compliance for cultural change This is a practical guide to implementing value-based compliance for real cultural change. Not the “annual training and hope for the best” version. The kind where people make the right call when no one is watching, and you can prove it without a spreadsheet scavenger hunt.…
-

CASE STUDY: UNT Health
Conflict, clarity, and courageous integrity: How UNT Health streamlined compliance with CoreStream GRC About UNT Health The University of North Texas Health Science Center (UNT Health) formerly known as HSC, is a dynamic academic health center with a 50-year legacy. With 6 schools, including the newly added College of Nursing, and 4 research institutes focused…
-

GUIDE: COI sample questions
Conflict of Interest: sample questions to start the conversation Sample prompts from CoreStream GRC to support transparent, ethical governance. Disclaimer: This guide provides sample questions and considerations for discussion only. It is not an exhaustive list and should not be used as a compliance form. Always tailor your conflict of interest process to your organization’s…
Ready to upgrade your GRC tech?
Contact the team and request your demo today.
This form may not be visible due to adblockers, or JavaScript not being enabled.