Research and field notes on governance capability.
Six themes, drawn directly from engagement work — not restated frameworks.
SME GRC
How mature is your risk management, really — and what does the next step of maturity actually look like.
Cybersecurity
What should a 50-person company actually implement, versus what a vendor wants to sell them.
Audit Readiness
Why companies fail audits despite having policies — the evidence gap, explained.
Third-Party Risk
Your vendor may be your weakest control — concentration risk most SMEs never quantify.
AI Governance
Your employees are already using AI. Is your governance ready for what they’re doing with it?
Governance Philosophy
KTR, KRF, Governance of Skepticism, and Governance Economics — the thinking underneath the practice.
Recent field notes.
Your Board Doesn’t Need a Framework. It Needs a Risk Picture.
The difference between a maturity score and knowing what could actually go wrong.
The Vendor You Trust Most Is Your Biggest Concentration Risk.
What happens to your business the day your critical vendor goes down.
Shadow AI Is Already Inside Your Organization.
Why governance has to catch up to adoption, not the other way around.
Illustrative topics — connect for the current LinkedIn feed and published research.
Get the Weekly GRC Intelligence Brief.
Current news, applied through the Institute’s frameworks — one email a week.