• UK Corporate Governance Code

    UK Corporate Governance Code

    What is the UK Corporate Governance Code? The UK Corporate Governance Code is the Financial Reporting Council’s corporate governance framework for listed companies in the UK. It sets out principles and provisions covering board leadership, company purpose, division of responsibilities, board composition, succession, evaluation, audit, risk, internal control, and remuneration. The Financial Reporting Council explains…

    Read more: UK Corporate Governance Code
  • AI governance

    AI governance

    What is AI governance? AI governance is the system an organization uses to direct, oversee, control, and evidence the way artificial intelligence is developed, bought, deployed, monitored, and used. It covers who can approve AI use, what risks need to be assessed, what data can be used, how outputs are reviewed, how decisions are documented,…

    Read more: AI governance
  • Board governance

    Board governance

    What is board governance? Board governance is the way a board of directors directs, oversees, and holds an organization accountable. It covers how the board sets strategic direction, challenges management, monitors performance, oversees risk and internal controls, and makes decisions in the interests of the organization and its stakeholders.  In governance, risk, and compliance (GRC), board governance…

    Read more: Board governance
  • Board oversight

    Board oversight

    What is board oversight? Board oversight is the process through which a board of directors monitors, challenges, and holds an organization’s leadership accountable. It helps directors understand whether strategy is being delivered, risks are being managed, controls are operating effectively, and issues are being escalated and resolved.  In governance, risk, and compliance (GRC), board oversight matters because directors cannot…

    Read more: Board oversight
  • Governance roles and responsibilities

    Governance roles and responsibilities

    What are governance roles and responsibilities? Governance roles and responsibilities define who makes decisions, who provides oversight, who owns risk, who manages controls, who monitors compliance, and who must act when issues arise. They explain how authority, accountability, escalation, and reporting work across an organization. In practice, this means knowing who approves what, who owns…

    Read more: Governance roles and responsibilities
  • Board reporting

    Board reporting

    What is board reporting? Board reporting is the process of giving a board of directors the information it needs to oversee an organization, challenge management, and make informed decisions. It brings together relevant updates on strategy, performance, risk, controls, compliance, audit, issues, and actions. In governance, risk, and compliance (GRC), board reporting matters because directors…

    Read more: Board reporting
  • Governance and compliance

    Governance and compliance

    What is governance and compliance? Governance and compliance describes the relationship between how an organization is directed and controlled, and how it meets the obligations that apply to its activities. Governance sets direction, decision-making structures, accountability, oversight, and reporting. Compliance helps ensure the organization meets legal, regulatory, contractual, policy, and ethical requirements. In governance, risk,…

    Read more: Governance and compliance
  • Governance and risk

    Governance and risk

    What is governance and risk? Governance and risk describes how an organization directs, oversees, and makes decisions about uncertainty. Governance sets the structure for decision-making, accountability, reporting, oversight, and challenge. Risk management helps the organization understand what could affect its objectives, how serious those risks are, who owns them, and what action is needed. In…

    Read more: Governance and risk
  • Governance structure

    Governance structure

    What is a governance structure?  A governance structure is the way an organization organizes authority, oversight, accountability, and decision-making. It explains who has the power to decide, who needs to approve, who must be consulted, what gets escalated, and how leadership can see whether the organization is operating in line with its objectives.  In GRC, a governance structure matters…

    Read more: Governance structure
  • Governance framework

    Governance framework

    What is a governance framework? A governance framework is the structure an organization uses to guide decision-making, assign accountability, manage oversight, and demonstrate how governance works in practice. It sets out who has authority, which decisions require approval, how issues are escalated, and how governance activity is monitored and reported.  In governance, risk and compliance (GRC), a clear governance…

    Read more: Governance framework

Continue learning about the world of GRC

  • Coca-Cola’s Fairlife ransomware attack: why risk doesn’t respect the org chart 

    Coca-Cola’s Fairlife ransomware attack: why risk doesn’t respect the org chart 

    Key takeaways  How Fairlife’s cyberattack became a group governance issue  On July 16, 2026, Coca-Cola disclosed that Fairlife, its dairy business, had detected unauthorized access to a section of its network, including production-linked systems. Production at Fairlife’s 4 US factories stopped. Canadian production continued. Product on shelves stayed safe.  A ransomware-as-a-service group calling itself Anubis claimed responsibility, saying it had taken 1 terabyte of data and threatening to leak it. According to…

  • The EU delayed its AI Act deadline: what the Digital Omnibus means for AI governance everywhere

    The EU delayed its AI Act deadline: what the Digital Omnibus means for AI governance everywhere

    Key takeaways  Introduction: the AI compliance deadline GRC teams have been racing toward just moved  For eighteen months, “2 August 2026” has been a fixed point on the calendar for compliance, risk and AI governance teams across Europe, and well beyond. This was the date the EU AI Act’s toughest obligations, covering high-risk AI systems, were due to bite: conformity assessments, technical…

  • When the US government switched off AI: what the Anthropic shutdown means for your GRC program 

    When the US government switched off AI: what the Anthropic shutdown means for your GRC program 

    Key takeaways  Introduction: for many businesses the lights went out when the US government enforced AI restrictions   Picture this: it’s the morning of 13 June 2026 and the compliance team at a mid-sized, European financial services business opens their AI-assisted regulatory monitoring tool – the one they recently rolled out, that surfaces horizon risk items and flags policy changes across five jurisdictions. It is offline, with no warning email, no estimated time of restoration and, critically, no fallback. …