• Regulatory compliance including SCF compliance frameworks

    Regulatory compliance including SCF compliance frameworks

    What is regulatory compliance? Regulatory compliance is the process of meeting the laws, rules, standards, and requirements set by regulators, governments, and supervisory bodies. It helps organizations understand which external obligations apply, assign ownership, operate controls, collect evidence, and report when required. In governance, risk, and compliance (GRC), regulatory compliance matters because regulatory expectations rarely…

    Read more: Regulatory compliance including SCF compliance frameworks
  • Compliance

    Compliance

    What is compliance? Compliance is the process of meeting the laws, regulations, standards, policies, contractual requirements, and ethical expectations that apply to an organization. In simple terms, compliance helps organizations understand what they are required to do, assign ownership, operate controls, evidence activity, and respond when something goes wrong. In governance, risk, and compliance (GRC),…

    Read more: Compliance
  • UK Corporate Governance Code

    UK Corporate Governance Code

    What is the UK Corporate Governance Code? The UK Corporate Governance Code is the Financial Reporting Council’s corporate governance framework for listed companies in the UK. It sets out principles and provisions covering board leadership, company purpose, division of responsibilities, board composition, succession, evaluation, audit, risk, internal control, and remuneration. The Financial Reporting Council explains…

    Read more: UK Corporate Governance Code
  • AI governance

    AI governance

    What is AI governance? AI governance is the system an organization uses to direct, oversee, control, and evidence the way artificial intelligence is developed, bought, deployed, monitored, and used. It covers who can approve AI use, what risks need to be assessed, what data can be used, how outputs are reviewed, how decisions are documented,…

    Read more: AI governance
  • Board governance

    Board governance

    What is board governance? Board governance is the way a board of directors directs, oversees, and holds an organization accountable. It covers how the board sets strategic direction, challenges management, monitors performance, oversees risk and internal controls, and makes decisions in the interests of the organization and its stakeholders.  In governance, risk, and compliance (GRC), board governance…

    Read more: Board governance
  • Board oversight

    Board oversight

    What is board oversight? Board oversight is the process through which a board of directors monitors, challenges, and holds an organization’s leadership accountable. It helps directors understand whether strategy is being delivered, risks are being managed, controls are operating effectively, and issues are being escalated and resolved.  In governance, risk, and compliance (GRC), board oversight matters because directors cannot…

    Read more: Board oversight
  • Governance roles and responsibilities

    Governance roles and responsibilities

    What are governance roles and responsibilities? Governance roles and responsibilities define who makes decisions, who provides oversight, who owns risk, who manages controls, who monitors compliance, and who must act when issues arise. They explain how authority, accountability, escalation, and reporting work across an organization. In practice, this means knowing who approves what, who owns…

    Read more: Governance roles and responsibilities
  • Board reporting

    Board reporting

    What is board reporting? Board reporting is the process of giving a board of directors the information it needs to oversee an organization, challenge management, and make informed decisions. It brings together relevant updates on strategy, performance, risk, controls, compliance, audit, issues, and actions. In governance, risk, and compliance (GRC), board reporting matters because directors…

    Read more: Board reporting
  • Governance and compliance

    Governance and compliance

    What is governance and compliance? Governance and compliance describes the relationship between how an organization is directed and controlled, and how it meets the obligations that apply to its activities. Governance sets direction, decision-making structures, accountability, oversight, and reporting. Compliance helps ensure the organization meets legal, regulatory, contractual, policy, and ethical requirements. In governance, risk,…

    Read more: Governance and compliance
  • Governance and risk

    Governance and risk

    What is governance and risk? Governance and risk describes how an organization directs, oversees, and makes decisions about uncertainty. Governance sets the structure for decision-making, accountability, reporting, oversight, and challenge. Risk management helps the organization understand what could affect its objectives, how serious those risks are, who owns them, and what action is needed. In…

    Read more: Governance and risk

Continue learning about the world of GRC

  • Coca-Cola’s Fairlife ransomware attack: why risk doesn’t respect the org chart 

    Coca-Cola’s Fairlife ransomware attack: why risk doesn’t respect the org chart 

    Key takeaways  How Fairlife’s cyberattack became a group governance issue  On July 16, 2026, Coca-Cola disclosed that Fairlife, its dairy business, had detected unauthorized access to a section of its network, including production-linked systems. Production at Fairlife’s 4 US factories stopped. Canadian production continued. Product on shelves stayed safe.  A ransomware-as-a-service group calling itself Anubis claimed responsibility, saying it had taken 1 terabyte of data and threatening to leak it. According to…

  • The EU delayed its AI Act deadline: what the Digital Omnibus means for AI governance everywhere

    The EU delayed its AI Act deadline: what the Digital Omnibus means for AI governance everywhere

    Key takeaways  Introduction: the AI compliance deadline GRC teams have been racing toward just moved  For eighteen months, “2 August 2026” has been a fixed point on the calendar for compliance, risk and AI governance teams across Europe, and well beyond. This was the date the EU AI Act’s toughest obligations, covering high-risk AI systems, were due to bite: conformity assessments, technical…

  • When the US government switched off AI: what the Anthropic shutdown means for your GRC program 

    When the US government switched off AI: what the Anthropic shutdown means for your GRC program 

    Key takeaways  Introduction: for many businesses the lights went out when the US government enforced AI restrictions   Picture this: it’s the morning of 13 June 2026 and the compliance team at a mid-sized, European financial services business opens their AI-assisted regulatory monitoring tool – the one they recently rolled out, that surfaces horizon risk items and flags policy changes across five jurisdictions. It is offline, with no warning email, no estimated time of restoration and, critically, no fallback. …