Insights

Research and field notes on governance capability.

Six themes, drawn directly from engagement work — not restated frameworks.

Pillar 01

SME GRC

How mature is your risk management, really — and what does the next step of maturity actually look like.

Pillar 02

Cybersecurity

What should a 50-person company actually implement, versus what a vendor wants to sell them.

Pillar 03

Audit Readiness

Why companies fail audits despite having policies — the evidence gap, explained.

Pillar 04

Third-Party Risk

Your vendor may be your weakest control — concentration risk most SMEs never quantify.

Pillar 05

AI Governance

Your employees are already using AI. Is your governance ready for what they’re doing with it?

Pillar 06

Governance Philosophy

KTR, KRF, Governance of Skepticism, and Governance Economics — the thinking underneath the practice.


Latest

Recent field notes.

SME GRC

Your Board Doesn’t Need a Framework. It Needs a Risk Picture.

The difference between a maturity score and knowing what could actually go wrong.

Third-Party Risk

The Vendor You Trust Most Is Your Biggest Concentration Risk.

What happens to your business the day your critical vendor goes down.

AI Governance

Shadow AI Is Already Inside Your Organization.

Why governance has to catch up to adoption, not the other way around.

Illustrative topics — connect for the current LinkedIn feed and published research.

Get the Weekly GRC Intelligence Brief.

Current news, applied through the Institute’s frameworks — one email a week.