Posts
-
Start with your business, then assess the vendor #TPRM#Business context Business dependencies, access, data, and recovery options should shape where a third-party review goes deeper.
-
The risk lifecycle needs a continuous evidence pipeline #Risk engineering#Data pipelines#AI How connected evidence, business context, and human review can keep risk identification useful as systems change.
-
Risk changes continuously. Our understanding should too. #Risk engineering#Risk identification#Data pipelines Why I’m building a pipeline that revisits risk scenarios as systems, vendors, and business dependencies change.
-
GRC engineering is more than automation #GRC engineering Writing a script is one part of the work. Getting a process adopted across an organization is another.
-
From control checks to risk questions #GRC engineering#Risk engineering Why evidence needs business context before it becomes a useful candidate risk statement.
-
Lab 01: Continuous risk identification #Labs#Risk identification#Data pipelines Follow evidence through a data pipeline into a candidate risk statement, with citations, business context and explicit uncertainty.
-
Where should a risk management program start? #Risk identification Before choosing the policy, register, or tool, ask what you cannot afford to get wrong.
-
Building an AI-first TPRM program #TPRM#AI#Operating models My proposed operating model: structured intake, organized evidence, a clear methodology, and analyst validation.