• Risk

    Risk

    What is risk? Risk is the effect of uncertainty on an organization’s objectives. In simple terms, risk is what could happen that may affect whether an organization achieves what it set out to do. In governance, risk, and compliance (GRC), risk matters because decisions are rarely made with perfect certainty. Organizations need a clear way…

    Read more: Risk
  • Third party risk management

    Third party risk management

    Third party risk management is the process of identifying, assessing, monitoring, and managing the risks that come from working with external organizations. These third parties can include suppliers, vendors, contractors, service providers, consultants, technology providers, outsourced partners, and other external relationships. In governance, risk, and compliance (GRC), third party risk management matters because organizations are…

    Read more: Third party risk management
  • Healthcare compliance and HIPPA 

    Healthcare compliance and HIPPA 

    What is healthcare compliance and HIPAA? Healthcare compliance is the process of meeting the laws, regulations, standards, policies, ethical rules, and patient safety requirements that apply to healthcare organizations. HIPAA, often misspelled as HIPPA, is 1 of the most important healthcare compliance laws in the United States because it sets rules for protecting health information…

    Read more: Healthcare compliance and HIPPA 
  • Audit management 

    Audit management 

    What is audit management? Audit management is the process of planning, coordinating, executing, documenting, reporting, and tracking audits from start to finish. It gives organizations a structured way to decide what should be audited, why it matters, what evidence is needed, who owns findings, and how remediation is tracked through to closure. In governance, risk,…

    Read more: Audit management 
  • General Data Protection Regulation (GDPR) and Data Privacy management 

    General Data Protection Regulation (GDPR) and Data Privacy management 

    What is GDPR and Data Privacy management? The General Data Protection Regulation (GDPR) is the EU data protection law that governs how organizations collect, use, store, share, protect, and delete personal data. Data privacy management is the ongoing process organizations use to meet GDPR and other privacy obligations in practice. In governance, risk, and compliance…

    Read more: General Data Protection Regulation (GDPR) and Data Privacy management 
  • Compliance audit

    Compliance audit

    What is a compliance audit? A compliance audit is a structured review that checks whether an organization is meeting specific laws, regulations, standards, policies, contractual requirements, or internal controls. It helps confirm whether compliance requirements are understood, owned, evidenced, and operating in practice. In governance, risk, and compliance (GRC), a compliance audit matters because it…

    Read more: Compliance audit
  • Compliance reporting

    Compliance reporting

    What is compliance reporting? Compliance reporting is the process of collecting, analyzing, and presenting information that shows whether an organization is meeting its compliance obligations. It helps leadership, boards, auditors, regulators, and internal stakeholders understand compliance status, control effectiveness, issues, breaches, remediation, and areas needing attention. In governance, risk, and compliance (GRC), compliance reporting matters…

    Read more: Compliance reporting
  • Compliance management software

    Compliance management software

    What is compliance management software? Compliance management software is a digital system that helps organizations manage compliance obligations, controls, policies, evidence, issues, remediation, and reporting in 1 connected place. It gives compliance teams a clearer way to understand what requirements apply, who owns them, what actions are due, and what evidence proves compliance activity has…

    Read more: Compliance management software
  • Regulatory compliance including SCF compliance frameworks

    Regulatory compliance including SCF compliance frameworks

    What is regulatory compliance? Regulatory compliance is the process of meeting the laws, rules, standards, and requirements set by regulators, governments, and supervisory bodies. It helps organizations understand which external obligations apply, assign ownership, operate controls, collect evidence, and report when required. In governance, risk, and compliance (GRC), regulatory compliance matters because regulatory expectations rarely…

    Read more: Regulatory compliance including SCF compliance frameworks
  • Compliance

    Compliance

    What is compliance? Compliance is the process of meeting the laws, regulations, standards, policies, contractual requirements, and ethical expectations that apply to an organization. In simple terms, compliance helps organizations understand what they are required to do, assign ownership, operate controls, evidence activity, and respond when something goes wrong. In governance, risk, and compliance (GRC),…

    Read more: Compliance

Continue learning about the world of GRC

  • Norway’s BankID outage shows what DORA-grade third-party risk management actually requires  

    Norway’s BankID outage shows what DORA-grade third-party risk management actually requires  

    For 2 days, millions of Norwegians couldn’t sign a contract, complete a house sale or access a health record because a single supplier’s infrastructure failed for the second time in 5 years. What happens when an entire country’s digital ID depends on a single supplier?  On the morning of 3 September 2026, a real estate agent in…

  • The CareCloud data breach: a third-party risk warning for healthcare compliance teams

    The CareCloud data breach: a third-party risk warning for healthcare compliance teams

    Key takeaways Introduction: the changing face of a healthcare data hack In early August 2026, patients of various US healthcare providers began opening data breach notifications from a company many had never heard of: CareCloud, the cloud-based electronic health record and billing platform their doctor’s office quietly ran in the background. The letter said their…

  • Lombard Odier’s money-laundering conviction shows why flagging a compliance risk isn’t enough 

    Lombard Odier’s money-laundering conviction shows why flagging a compliance risk isn’t enough 

    Key takeaways  Introduction: failure to go beyond filing a risk report leads to an AML conviction  In 2012, a Geneva private bank, Lombard Odier, noticed unusual activity connected to one relationship manager’s client accounts and reported their suspicions to Switzerland’s Money Laundering Reporting Office.  14 years of legal process, and one collapsed prosecution against the alleged ringleader, later, Switzerland’s Federal Criminal Court…