Introduction

Michael Rasmussen, globally recognized GRC thought leader and former Forrester analyst who originally defined the Governance, Risk, and Compliance market, recently drafted his perspective on CoreStream GRC’s conflict of interest solution. 

For this analysis, Michael engaged with 3 organizations actively using the CoreStream GRC platform to manage conflicts of interest. While operating in different industries, each organization has configured the solution to address its unique regulatory pressures, operational realities, and business priorities. This preview distils the most important takeaways from those discussions, illustrating how CoreStream GRC’s adaptable approach to conflict of interest management is delivering measurable value across diverse sectors.

Here is a preview of the report:

CoreStream GRC COI Management Client Experiences  

Organizations across industries are using CoreStream GRC to strengthen conflict of interest management and related ethics and compliance processes, achieving improvements in visibility, workflow discipline, reporting, and operational consistency.  

GRC 20/20 has found a consistent pattern: organizations are moving away from email driven, spreadsheet-based, or highly customized legacy approaches toward a more structured, auditable, and business-integrated model.  

In this evaluation, GRC 20/20 conducted three specific client reference discussions that found: 

CLIENT: A UK-based reinsurance organization (~50 employees)

implemented CoreStream GRC for conflicts of interest and gifts and hospitality as an extension of its existing risk and compliance environment. They stated,

“Great to have everything in one system, we’ve rebranded it the risk and compliance system.”

Prior to CoreStream GRC, these processes were manual, fragmented, and largely driven by emails and informal approvals, with limited reporting, no centralized log, and little auditability. With CoreStream GRC, the organization established enterprise-wide conflict declarations, quarterly attestation cycles, compliance review and approval workflows, and a centralized repository for active and historical conflicts. Gifts and hospitality were brought into the same governance model, creating a familiar and consistent user experience across risk and compliance. Results include moving from 40% response rates with the old tool to a 95% response rate. 

CLIENT: A large global private foundation (~5,000 employees) 

selected CoreStream GRC for conflicts of interest and a related disqualified persons process tied to self-dealing prevention. The legacy environment had become expensive to maintain, difficult to evolve, and increasingly misaligned with modern user expectations. CoreStream GRC stood out because it could meet complex requirements without heavy customization and because it demonstrated specific working capabilities rather than generic promises. At the time of the reference discussion, the program was still in implementation and not yet live, but the client had already identified compelling value in fewer false positives, reduced dependence on a single individual for sensitive processes, and a better fit for nuanced foundation workflows. The team were particularly impressed by CoreStream GRC coming to their offices for design workshops, stating 

“They are great partners, flexible, smart, people who know their stuff. I would recommend.” 

CLIENT: A large U.S. healthcare organization (~50,000 team members) 

selected CoreStream GRC as a dedicated conflicts of interest solution after outgrowing a makeshift process that had moved from a learning management system to a repurposed policy management environment. A decisive factor in selecting CoreStream GRC was its ability to integrate Open Payments data:

“a key USP of CoreStream”. 

The client used CoreStream GRC to design a more structured workflow that includes threshold-based flagging, supervisor review, escalation to the next level of leadership, mitigation planning, compliance review, and employee acknowledgment. While the organization had not yet completed a full enterprise-wide campaign, early experience was strongly positive around configurability, workflow automation, and implementation quality. 

Across these client experiences, a clear pattern emerges. CoreStream GRC is proving particularly effective where organizations need to move beyond static disclosure collection and establish a living conflict of interest management process. In smaller regulated environments, this means replacing informal approvals and fragmented tracking with a centralized, auditable system of record. In large, complex environments, it means supporting nuanced workflows, reducing manual review effort, and fitting into mission-critical or healthcare-specific contexts without forcing excessive customization. 

Overall, CoreStream GRC is demonstrating that conflict of interest management can be handled as a practical, business-integrated governance capability rather than a once a-year administrative exercise. The platform supports transparency, decision-making discipline, and defensible oversight while remaining usable enough for broad adoption.  

Want the full 18 page report? 

Or head to the preview section of the report: Short snippet of GRC 2020’s Conflict of Interest solution perspective.

About Michael Rasmussen

Michael Rasmussen is an internationally recognized thought leader and pioneer in governance, risk management, and compliance (GRC). With over 30 years of experience, he has extensive expertise in enterprise GRC strategy and processes supported by robust information and technology architectures. Known as the ‘Father of GRC’, Michael was the first to define and model the GRC market in February 2002 while at Forrester, setting the foundation for the modern understanding of GRC.

Frequently asked questions

1. What makes CoreStream GRC’s conflict of interest management different according to Michael Rasmussen?

According to Michael Rasmussen, CoreStream GRC stands out because it treats conflict of interest (COI) management as a living, business‑integrated governance process, not just a once‑a‑year disclosure exercise. Through client discussions across insurance, healthcare, and foundation environments, Rasmussen observed that CoreStream GRC enables organizations to move beyond static forms and email‑driven approvals toward structured workflows, centralized records, auditability, and ongoing oversight. This approach supports real decision‑making discipline and defensible compliance while remaining usable enough for broad employee adoption.

2. How are organizations using CoreStream GRC to improve conflict of interest compliance outcomes?

Organizations using CoreStream GRC are improving conflict of interest compliance by replacing fragmented, manual processes with enterprise‑wide declarations, automated workflows, and centralized repositories. In regulated environments, such as a UK‑based reinsurance firm, this shift delivered a dramatic increase in disclosure completion rates, from 40% to 95%, and established consistent quarterly attestations and approval cycles. Across all client examples, CoreStream GRC improved visibility, accountability, reporting quality, and operational consistency, making conflict management more reliable and auditable.

3. Why did large and complex organizations select CoreStream GRC for conflict of interest management?

Large organizations selected CoreStream GRC because it supports complex, nuanced conflict scenarios without heavy customization. A global private foundation valued CoreStream GRC’s ability to reduce false positives, eliminate dependence on single individuals for sensitive determinations, and align with foundation‑specific self‑dealing and disqualified‑person requirements. A large U.S. healthcare organization highlighted CoreStream GRC’s integration with Open Payments data as a key differentiator, enabling threshold‑based flagging, escalation, mitigation planning, and defensible oversight within healthcare‑specific regulatory expectations.

4. What business value does CoreStream GRC deliver beyond basic conflict disclosure?

Beyond collecting disclosures, CoreStream GRC delivers business value by establishing conflict of interest management as an ongoing governance capability. Clients reported reduced manual review effort, stronger workflow discipline, improved transparency, and better alignment with broader risk, ethics, and compliance programs. Whether supporting smaller regulated organizations or enterprise‑scale healthcare systems, CoreStream GRC enables conflicts of interest to be actively managed, reviewed, mitigated, and documented, helping organizations demonstrate effective oversight, regulatory readiness, and ethical accountability.

Continue your reading

  • Short snippet of GRC 2020’s Conflict of Interest solution perspective

    Short snippet of GRC 2020’s Conflict of Interest solution perspective

    At CoreStream GRC, we believe Conflict of Interest (COI) Management should go beyond checkbox compliance: “A mature program treats conflict management as continuous, not episodic.” It’s one of our most in‑demand solutions precisely because many organizations are rethinking whether their existing approaches truly stand up to today’s regulatory scrutiny.  To put that belief to the test, we invited trusted GRC industry analyst Michael Rasmussen to…

  • Preview: Michael Rasmussen’s Perspective on CoreStream GRC’s Enterprise Risk Management Solution

    Preview: Michael Rasmussen’s Perspective on CoreStream GRC’s Enterprise Risk Management Solution

    CoreStream GRC for Enterprise Risk Management We invited renowned GRC analyst and expert Michael Rasmussen, who coined the term Governance, Risk, and Compliance (GRC), to conduct an impartial review of our Enterprise Risk Management (ERM) solution. To ensure a comprehensive and unbiased evaluation, Michael spoke directly with several of our enterprise risk users to gather…

  • Paul Cadwallader joins Michael Rasmussen’s new podcast to discuss the state and future of GRC

    Paul Cadwallader joins Michael Rasmussen’s new podcast to discuss the state and future of GRC

    We recently had the privilege of welcoming Michael Rasmussen, GRC 2020 analyst, author, and founder of The GRC Report, to our London offices to record a very special premier episode for his new podcast series: “Hitchhiker’s guide to the GRC galaxy.“  Paul Cadwallader, GRC Strategy Director at CoreStream GRC, sat down with Michael for a…