Simplifying risk in a complex world to achieve business objectives – key findings from the Spotlight on Women in GRC 

In this episode of CoreStream GRC’s Spotlight on Women in GRC podcast, Lucy Montague speaks with Sharon Sharples, Chief of Staff and Head of Operational Risk Governance and Insights at Barclays, about her journey from change management into risk leadership, the evolving role of GRC in modern organizations, and why curiosity, simplification, and flexibility will define the…

Esme Dyos Avatar

In this episode of CoreStream GRC’s Spotlight on Women in GRC podcast, Lucy Montague speaks with Sharon Sharples, Chief of Staff and Head of Operational Risk Governance and Insights at Barclays, about her journey from change management into risk leadership, the evolving role of GRC in modern organizations, and why curiosity, simplification, and flexibility will define the future of the profession. Drawing on nearly 3  decades in financial services, Sharon shares her perspective on leadership, creating opportunities for others, and building resilient organizations that can thrive amid constant change. 

Key takeaways from Sharon Sharple’s podcast episode: 

  • Risk is rapidly becoming one of the most dynamic and influential career paths in modern business. 
  • GRC offers broader career opportunities than many professionals realize, with demand growing for both technical and human-centric skills. 
  • Mentorship, sponsorship, and workplace flexibility remain critical drivers of leadership development and talent retention. 
  • Organizations are increasingly focused on simplifying risk frameworks and using AI to make governance more accessible. 
  • The next generation of GRC leaders will need to balance innovation, resilience, and horizon scanning in an increasingly volatile environment. 

Risk is becoming increasingly more important to the board and business  

On our latest episode of Spotlight on Women in GRC, Sharon begins by talking through her career journey that was formed by changed management and projects, which then led to her discovering risk. She  talks about the appeal of risk and why she’s stayed in the function, due to its constant evolution:  

“Operational risk in particular keeps changing. No two days are the same. There’s a lot of focus from regulators, boards, and executives on preventing losses and incidents, so it’s quite a transformative place to be.”  

Sharon Sharples, Director, Group Operational Risk & Risk Oversight Chief of Staff, Head of Governance & Operations

Her observation reflects a broader shift taking place across industries. The World Economic Forum’s Future of Jobs Report 2025 found that employers expect 39% of workers’ core skills to change by 2030 as organizations respond to technological disruption, economic uncertainty, geopolitical pressures, and AI-driven transformation. Curiosity, resilience, analytical thinking, and adaptability are all expected to become increasingly important.

Risk teams are no longer focused solely on compliance. Today’s GRC professionals sit at the intersection of: 

  • cyber security,  
  • AI governance,  
  • operational resilience,  
  • third-party risk,  
  • regulatory change.  

This diversity allows professionals to move between disciplines while gaining visibility across the wider organization. As organizations navigate growing uncertainty, risk functions have become strategic partners in enabling business growth while protecting customers and stakeholders: 

“People don’t appreciate the variety of roles across risk and the different attributes and skills that you need.”  

Sharon Sharples, Director, Group Operational Risk & Risk Oversight Chief of Staff, Head of Governance & Operations

GRC is no longer a niche discipline. It is becoming a gateway to some of the most business-critical roles in modern organizations. GRC Strategy Director, Paul Cadwallader observes this, stating

“The future risk leader is not simply a control expert, they are a business strategist who helps organizations navigate uncertainty.”

Paul Cadwallader, GRC Strategy Director, CoreStream GRC

How to become a senior leader in GRC via sponsorship and support  

When discussing leadership development, Sharon repeatedly returned to 2 themes: support networks and flexibility. 

“I’m a huge advocate of mentors and sponsors. I think it’s fundamental for your career.”  

Sharon Sharples, Director, Group Operational Risk & Risk Oversight Chief of Staff, Head of Governance & Operations

Sharon’s view is backed by wider workplace research. According to Deloitte’s Women @ Work 2024 study, 75% of women aspire to move into senior leadership roles, yet only 10% believe their employer is taking concrete action to improve gender equality, highlighting the importance of accessible development opportunities and support networks. 

She also noted that many of the most effective development initiatives are simple, colleague-led activities such as: 

  • mentoring,  
  • networking,  
  • knowledge sharing,  
  • sponsorship.  

They don’t require large budgets to generate meaningful impact. As former PepsiCo CEO Indra Nooyi observed, 

“Women helping each other, coaching, mentoring, and providing tips is a great way for us to be our own force.”  

Indra Nooyi, former PepsiCo CEO

Alongside mentorship, Sharon highlighted the continued importance of workplace flexibility. 

“The flexibility brings that about for everybody, but it does help women much more where they are having to care for others.”  

Sharon Sharples, Director, Group Operational Risk & Risk Oversight Chief of Staff, Head of Governance & Operations

Her comments align with Deloitte’s Women @ Work 2024 research, which found that women continue to carry a disproportionate share of caregiving responsibilities and that workplace flexibility remains a major factor influencing retention, wellbeing, and career progression. The study also found that increasing return-to-office requirements have negatively affected productivity, work-life balance, and mental health for many women.

Flexibility is a common theme we’ve found throughout the Spotlight on Women in GRC podcast conversations, on our first episode, Director of Risk, Lauren De Thibault advised listeners to: 

“pick your bosses wisely, as well as picking the next role. And if somebody doesn’t have a good culture, then don’t go for that role. Go somewhere where you can have the flexibility.” 

Lauren de Thibault, Risk Director and former Women in GRC winner 

Organizations do not need costly diversity initiatives to create impact. Mentorship, sponsorship, and flexibility remain some of the highest-return investments available.  

“A little support can go a long way, particularly in regard to employee retention and satisfaction.”

Lucy Montague, Head of Marketing, CoreStream GRC

Simplification key driver of the next wave of GRC transformation 

One of the most compelling themes from the conversation was Sharon’s belief that the future of GRC lies in simplification: 

“We’re working a lot on simplifying the framework and trying to bring that to life across the organization in ways people can understand and apply in their day job.”  

Sharon Sharples, Director, Group Operational Risk & Risk Oversight Chief of Staff, Head of Governance & Operations

Rather than creating more controls or additional layers of bureaucracy, Sharon sees the opportunity to make governance easier to understand and more accessible through technology. 

Her team is currently exploring new GRC platforms, AI capabilities, and knowledge management approaches that help colleagues find the right information at the right time.  

GRC Pundit, and founder of the term GRC, Michael Rasmussen, talks to the importance of simplicity in GRC stating: 

“GRC vendors and professionals should not just do simplicity for its own sake, but simplicity that delivers context, clarity, and connection when and where it’s needed.” 

Michael Rasmussen, GRC Analyst & Pundit, GRC 2020

The organizations that gain the most value from GRC technology will be those that focus on reducing complexity, not creating more of it. This is something our client Wood Group worked hard on: 

“Our mantra through the whole process was going from complex to simple, which is probably more difficult than going the opposite way.”

Neil Baird, Head of Quality, Wood  

The future of GRC belongs to the curious 

When asked about the next era of governance, risk, and compliance, Sharon pointed to a mindset rather than a technology: “We need to be more inquisitive. Horizon scanning and future thinking are really key.”  

As organizations face growing exposure to AI risks, cybercrime, deepfakes, geopolitical uncertainty, and increasingly complex supplier ecosystems, leaders must devote more time to understanding what could happen next, not just managing today’s priorities.  

This is something, the host of Spotlight on Women in GRC also picked up on: 

“That is something I’ve noticed with all the women that I’ve spoken to on this podcast. Everyone has this innate curiosity. There is a real kind of drive to understand and learn and observe. And I think that’s a key trait for someone who wants to progress in GRC.” 

Lucy Montague, Head of Marketing, CoreStream GRC

The challenge for GRC leaders will be maintaining the balance between innovation and protection. Customers expect seamless, AI-powered experiences, while organizations remain responsible for managing risk, compliance, and resilience. That tension is likely to define the future of the profession.  

Final thoughts on Chief of Staff and Head of Operational Risk Governance and Insights podcast episode 

A common thread ran through Sharon’s perspective on leadership, technology, and risk: simplicity creates capacity. 

By simplifying frameworks, investing in people, embracing technology responsibly, and fostering curiosity, organizations can move beyond seeing GRC as a control function and start treating it as a strategic enabler. 

As Sharon put it: 

“Most things are achievable. It just might be quite difficult. Get the right people around you and the support, and you can move mountains.”  

Sharon Sharples, Director, Group Operational Risk & Risk Oversight Chief of Staff, Head of Governance & Operations

That’s a lesson that applies not only to careers, but to the future of GRC itself. 

About Sharon Sharples 

Sharon Sharples is Chief of Staff and Head of Operations & Governance for Operational Risk & Risk Oversight at Barclays, with more than 25 years of experience in financial services spanning operational risk, governance, transformation, and strategy. Throughout her career, she has led large-scale change programs and risk initiatives across complex, highly regulated environments. 

A passionate advocate for inclusion and talent development, Sharon has held leadership roles across Barclays’ diversity and inclusion networks and is a recognized industry voice on risk leadership, operational resilience, and the future of GRC. She holds an MBA with Distinction and has received numerous awards for her contributions to leadership and inclusion, including Women in GRC Inclusion Champion of the Year 2025. 

About Spotlight on Women in GRC podcast  

CoreStream GRC’s Spotlight on Women in GRC podcast series has been created in the to continue spreading the great work of the Women in GRC awards, all year-round.   

Across the series, CoreStream GRC Head of Marketing Lucy Montague speaks with women working across governance, risk and compliance to explore their career paths, leadership lessons and views on the future of the profession. 

Condensed transcript for the podcast  

Lucy: 

Welcome to Spotlight on Women in GRC, a podcast series created to continue the conversation sparked by the Women in GRC Awards and carry those insights beyond the event. Backed by CoreStream GRC, the series shines a light on the women shaping governance, risk, and compliance, exploring their backgrounds, experiences, and perspectives on what’s changing across the industry. 

I’m your host, Lucy Montague, and today I’m joined by Sharon Sharples. Sharon, could you introduce yourself and tell us a little about your current role and career journey? 

Sharon: 

I’m Sharon Sharples and currently work at Barclays as Chief of Staff and Head of Operational Risk Governance and Insights. I’ve been with Barclays for seven years and have spent almost 30 years in financial services. 

Most of my career was in change management and strategy, but I realized that project and change managers are managing risk all the time. That naturally led me into risk management, particularly operational risk, which has become the focus of the latter part of my career. 

Lucy: 

What is it about risk that has kept you there? 

Sharon: 

What I love about operational risk is that it’s constantly evolving. No two days are the same. There’s significant regulatory focus, increasing board attention, and a real drive across organizations to prevent incidents and losses before they happen. 

It’s also an area being shaped by technology, cyber security, fraud, and emerging risks. It’s always changing, which keeps it interesting. 

Lucy: 

Women make up a large proportion of entry-level GRC roles, yet we still see a significant drop-off at senior leadership level. Why do you think that gap exists? 

Sharon: 

Historically, risk has often been viewed as a discipline that requires highly mathematical or analytical skills, which has traditionally attracted more men than women. What people don’t always appreciate is the variety of roles available across risk and the diverse skills needed to succeed. 

There are leadership, governance, communication, organizational, and stakeholder management skills that are equally important. As more women see examples of successful female leaders in these types of roles, I think we’ll continue to see progress at senior levels. 

Lucy: 

What helped you take the leap into senior leadership? 

Sharon: 

A combination of self-belief and support from others. 

I always felt capable of more, but mentors, sponsors, and supportive colleagues helped me recognize opportunities and build confidence. I’ve also learned the value of saying yes to new challenges and taking on responsibilities beyond my role. Those experiences build exposure, networks, and confidence over time. 

I’m a huge advocate of mentorship and sponsorship. You should never think you’re the only person with the answers. There’s always value in another perspective. 

Lucy: 

Have you experienced barriers during your career? 

Sharon: 

Yes, although some of them only became obvious in hindsight. 

There were situations where I felt I didn’t quite fit in, or feedback wasn’t clearly articulated. Looking back, some of those experiences were linked to being a woman in the workplace. 

I’ve also experienced the challenges that come with being a working parent. Even with a supportive family, balancing caring responsibilities alongside career ambitions can be difficult. 

The positive news is that I’ve seen significant progress over the years. Flexible working, shared parental responsibilities, and greater awareness around allyship are helping remove some of those barriers. 

Lucy: 

If a recent graduate asked why they should consider a career in GRC, what would you say? 

Sharon: 

I’d say it’s one of the most interesting places to build a career. 

The profession is constantly evolving, it’s incredibly broad, and the skills are highly transferable. You can move between risk, compliance, governance, cyber security, operational resilience, and many other areas. 

One of the biggest advantages is that GRC gives you visibility across an entire organization. You gain a unique perspective on how different teams and functions work together. 

Lucy: 

What skills do you think are most important for success in GRC? 

Sharon: 

Curiosity is essential. 

You need to be open-minded, inquisitive, and willing to ask difficult questions. It’s important to challenge assumptions and understand why things happen. 

At the same time, you need to be solution-oriented. GRC isn’t just about identifying problems; it’s about helping organizations find practical ways to manage and reduce risk. 

Lucy: 

How can organizations do a better job of supporting women into leadership roles? 

Sharon: 

Role models, mentors, and sponsors are incredibly important. 

Many organizations assume supporting women requires large investments, but a lot can be achieved through networking, knowledge-sharing, mentoring, and creating opportunities for people to learn from one another. 

Flexibility is another key factor. While flexibility benefits everyone, it’s especially important for people balancing careers with caring responsibilities. Creating an environment where people can thrive without sacrificing other parts of their lives makes a huge difference. 

Lucy: 

Can you share a moment in your career that you’re particularly proud of? 

Sharon: 

One that stands out is completing my MBA with distinction. 

I left university early when I was younger and felt like I’d failed academically. Years later, while working full time and raising a family, I completed a master’s degree and achieved a distinction. 

That experience reinforced the fact that careers aren’t linear. Sometimes the timing simply isn’t right the first time around, and that’s okay. 

Lucy: 

What are you and your team most focused on right now? 

Sharon: 

A major focus is simplifying risk management. 

We’re looking at how we make risk frameworks easier for people to understand and apply in their day-to-day work. We want risk management to feel practical and relevant rather than something that’s separate from the business. 

We’re also exploring how technologies such as AI and modern GRC platforms can help colleagues access information more effectively and make better decisions. 

Lucy: 

Looking ahead, what do you think will define the next era of GRC? 

Sharon: 

Curiosity and horizon scanning. 

As risk professionals, we need to spend more time thinking about what’s coming next—whether that’s AI, cyber threats, geopolitical issues, supply chain complexity, or changing customer expectations. 

The challenge will be balancing innovation with resilience. Organizations need to move forward and embrace new technologies while continuing to protect customers, colleagues, and the business. 

Lucy: 

What’s the best piece of career advice you’ve ever received? 

Sharon: 

Treat people with respect, even when you disagree with them. 

You never know when you’ll work with someone again. Professional relationships matter, and it’s important to remember that most people are trying to achieve the same overall goal, even when perspectives differ. 

Lucy: 

Finally, what would you like listeners to take away from this conversation? 

Sharon: 

Most things are achievable. 

They might be difficult, and they might take longer than you expect, but with the right support, the right people around you, and a willingness to keep learning, you can achieve far more than you think.

Frequently Asked Questions about GRC, Operational Risk, and Risk Leadership 

What is GRC and why is it important? 

GRC stands for governance, risk, and compliance. It helps organizations align business objectives with effective governance, proactive risk management, and regulatory compliance. In today’s environment, GRC is increasingly important because organizations must manage cyber threats, AI governance, operational resilience, third-party risk, and fast-changing regulatory expectations. 

Is GRC a good career path? 

Yes, GRC is becoming one of the most valuable career paths for professionals who want broad exposure across business strategy, technology, operations, regulation, and leadership. As Sharon Sharples explains in the Spotlight on Women in GRC podcast, risk roles are constantly evolving and offer opportunities to work across areas such as operational risk, compliance, cyber security, AI governance, and enterprise resilience. 

What skills do you need to succeed in GRC? 

The most important GRC skills include curiosity, analytical thinking, communication, stakeholder management, resilience, and the ability to simplify complex information. Technical knowledge is valuable, but modern GRC leaders also need strong judgment, commercial awareness, and the confidence to ask challenging questions. 

How can women progress into senior GRC leadership roles? 

Women can progress into senior GRC leadership roles through a combination of visible role models, mentoring, sponsorship, flexible working, and access to stretch opportunities. Sharon highlights the importance of support networks, while the wider conversation shows that organizations can improve retention and leadership development by creating inclusive, flexible environments where people can grow. 

How is AI changing governance, risk, and compliance? 

AI is changing GRC by helping organizations automate manual processes, improve access to risk information, strengthen monitoring, and support faster decision-making. However, AI also creates new governance challenges around transparency, accountability, data privacy, ethics, and operational resilience. The next era of GRC will require organizations to balance innovation with responsible risk management. 

What is operational risk management? 

Operational risk management is the process of identifying, assessing, managing, and monitoring risks that arise from people, processes, systems, suppliers, and external events. It is especially important in complex, highly regulated sectors such as financial services, where preventing incidents, losses, and disruption is a priority for boards, regulators, and customers. 

Why is simplification important in GRC? 

Simplification is important because overly complex risk frameworks can make governance harder to understand and apply. Effective GRC should help people make better decisions, not create unnecessary bureaucracy. By simplifying frameworks, using clearer language, and improving access to guidance, organizations can make risk management more practical and valuable across the business. 

What will define the future of GRC? 

The future of GRC will be defined by curiosity, horizon scanning, AI governance, operational resilience, cyber risk, third-party risk management, and the ability to adapt to uncertainty. Future GRC leaders will need to understand emerging risks while helping their organizations innovate safely and responsibly. 

  • Simplifying risk in a complex world to achieve business objectives – key findings from the Spotlight on Women in GRC 

    Simplifying risk in a complex world to achieve business objectives – key findings from the Spotlight on Women in GRC 

    In this episode of CoreStream GRC’s Spotlight on Women in GRC podcast, Lucy Montague speaks with Sharon Sharples, Chief of Staff and Head of Operational Risk Governance and Insights at Barclays, about her journey from change management into risk leadership, the evolving role of GRC in modern organizations, and why curiosity, simplification, and flexibility will define the…

  • Regulatory compliance including SCF compliance frameworks

    Regulatory compliance including SCF compliance frameworks

    What is regulatory compliance? Regulatory compliance is the process of meeting the laws, rules, standards, and requirements set by regulators, governments, and supervisory bodies. It helps organizations understand which external obligations apply, assign ownership, operate controls, collect evidence, and report when required. In governance, risk, and compliance (GRC), regulatory compliance matters because regulatory expectations rarely…

  • Compliance

    Compliance

    What is compliance? Compliance is the process of meeting the laws, regulations, standards, policies, contractual requirements, and ethical expectations that apply to an organization. In simple terms, compliance helps organizations understand what they are required to do, assign ownership, operate controls, evidence activity, and respond when something goes wrong. In governance, risk, and compliance (GRC),…