For something called Governance, Risk Management, and Compliance, the GRC industry spends a remarkable amount of its time and energy on compliance.
That tension was at the heart of my recent webinar conversation with Maril Vernon, CISSP, GRC Evangelist at Anecdotes. Drawing on her background in offensive security and red teaming, Maril opened the discussion with a familiar experience: an organization completes an audit, assessment, or penetration test and walks away feeling successful, yet a question remains in the back of everyone’s mind.
Did any of this actually make us safer?
Organizations collect evidence, assign scores, document findings, debate severity ratings, and prepare reports. They can often demonstrate that the required activities were performed. What they cannot always demonstrate is whether exposure was materially reduced, whether controls are working in the present environment, or whether the organization is better prepared for what comes next.
As Maril put it during our conversation, the industry has become very good at managing the artifacts of risk without necessarily improving its understanding of risk itself.
That distinction shaped the webinar. This was not simply a conversation about risk registers, control libraries, or frameworks. It was a deeper discussion about why risk became the most important part of GRC and, at the same time, the least operationalized.
The board does not ultimately need another risk dashboard. It needs confidence that the organization understands the uncertainty surrounding its objectives, is taking the right risks, and is becoming more resilient.
The question is straightforward:
If the board asked tomorrow how much risk the organization reduced over the past twelve months, could anyone answer with confidence?
GRC Was Never Intended to Become Compliance Theater
When Maril asked how risk became the missing or underdeveloped component of GRC, I went back to the original intent of the category.
When I defined the GRC market in 2002, the objective was not to create another category of compliance software. The goal was to address fragmentation. Policies lived in one place, controls somewhere else, and audit, compliance, risk, security, legal, finance, procurement, human resources, and operations each maintained their own pieces of the organizational puzzle.
GRC was intended to bring greater coordination and context to this fragmentation.
The OCEG definition captures the outcome. GRC is a capability that enables an organization to:
- Reliably achieve objectives
- Address uncertainty
- Act with integrity
Governance is about setting objectives, making decisions, and directing the organization toward performance. Risk is about addressing the uncertainty that can affect those objectives. Compliance is about acting with integrity and meeting obligations.
During the webinar, I challenged the premise that risk is automatically the most important letter. Governance is where everything begins because governance establishes what the organization is trying to achieve. Risk then becomes meaningful in relation to those objectives.
ISO 31000 reinforces this by defining risk as the effect of uncertainty on objectives. Without the objective, risk has no meaningful context.
Yet compliance quickly captured the GRC market.
The timing was significant. The first generation of GRC technology developed alongside Sarbanes-Oxley, Enron, WorldCom, and an intense focus on internal controls over financial reporting. Compliance was easier to operationalize because it gave organizations obligations, control requirements, evidence, testing procedures, and auditable outcomes.
Risk was more difficult. It required context, judgment, scenario analysis, and an understanding of what the organization was actually trying to accomplish.
Maril observed that organizations naturally gravitated toward what they could most easily measure. Over time, proof of compliance began to substitute for proof of effective risk management.
That is where compliance theater begins. The organization appears mature because it has the documentation, dashboards, and evidence, but it still cannot confidently determine whether risk is increasing or decreasing.
{{ banner-image }}
A Risk Register Is an Inventory, Not an Operating System
One of the central points in our conversation was that many risk programs look mature on paper.
They have risk registers, assessments, heat maps, scoring methodologies, control mappings, remediation plans, and findings backlogs. These tools may all have legitimate value. The problem emerges when they become the program itself.
As I explained to Maril, a risk register is an inventory. It is not an operating system for risk.
It documents what an organization believed about its risks at a particular point in time. It does not necessarily show how those risks are changing, whether controls remain effective, how one exposure affects another, or whether the organization is taking the right risks in pursuit of its objectives.
Maril connected this directly to her experience in offensive security. A security team may close numerous high-severity vulnerabilities and celebrate the reduction in its backlog. But did it actually disrupt an attacker’s path to a critical system? Did it address the underlying exposure, or merely remediate several isolated steps near the end of the attack chain?
The same problem appears throughout GRC. Organizations can complete activities without achieving the intended outcome.
We also discussed what happens when risk is treated as the final item on a board or executive agenda. If risk is discussed only after strategy, growth, operations, technology, finance, and transformation, then it has probably become a compliance exercise.
Every significant item on an executive agenda involves uncertainty. Risk belongs in the discussion of the objective itself, not as a separate appendix reviewed at the end.
Business Does Not Have an Appetite for Risk
The webinar took an important turn when Maril asked how organizations can move from documenting risk to using risk information to support better business decisions.
That requires changing how we communicate with the business.
Organizations often speak about “risk appetite,” but technically, businesses do not have an appetite for risk. They have an appetite for value.
During the webinar, I used the example of asking someone at a conference to leave $50 on their chair during a break. Few people would do this simply because they enjoy taking risks.
But suppose they were told that the $50 might become $200 when they returned.
Suddenly, they would begin assessing the situation. Are the people nearby trustworthy? Is the room secure? Is the promise credible? Does the potential return justify the exposure?
The appetite is not for risk. The appetite is for value.
Maril immediately connected with this framing because it shifts risk from an abstract discussion about threats to a decision about what the organization is trying to gain.
That is how risk professionals need to engage the business. The conversation should not begin with a risk register or control deficiency. It should begin with the objectives of the executive or business function.
What is marketing trying to achieve? What is operations trying to protect? What is technology enabling? What value is procurement pursuing through a supplier relationship? What outcome does the board expect from a strategic investment?
I shared an encounter with a chief marketing officer who told me that the chief risk officer had never asked about marketing risk. This was extraordinary considering the importance of reputation, customer trust, market perception, and brand value.
The issue was that the organization’s risk function had evolved primarily around Sarbanes-Oxley and financial controls. It was called risk management, but it was not engaging with risk across the actual business.
Risk Must Be Communicated as a Business Story
Maril also raised one of the perennial difficulties facing security and risk professionals: even when they understand the exposure, they often struggle to communicate it in a way that resonates with executives.
Data alone is not enough. Neither is fear.
In the webinar, I described an organization that used Monte Carlo analysis and bow-tie risk analysis to evaluate exposure to a potential collapse in the Egyptian currency. While economists expected the currency to fall within approximately a year, the organization’s analysis suggested a much shorter timeframe.
The organization acted and avoided significant losses.
The quantitative analysis gave the board numerical context, but the bow-tie analysis told the story. It showed the event in the center, the conditions and causes on one side, and the consequences and mitigating measures on the other.
The combination of structured quantification and visual storytelling created understanding.
The same organization later used a bow tie to explain cyber risk. The board’s response was essentially, “We finally understand what you have been telling us.” That understanding helped secure funding for a cyber risk technology initiative.
Maril emphasized that executive communication is not merely about presenting more technical information. It is about helping leaders understand what the information means to the business. Risk professionals need to explain what could happen, how it would affect objectives, what choices are available, and what the organization gains or gives up through each decision.
Attackers Do Not Care About Organizational Silos
A major portion of our discussion focused on connected risk.
Maril observed that attackers do not care where one organization’s third-party risk boundary ends or where another function’s responsibility begins. They will use whatever path gets them to their objective.
A cyber incident does not remain a cyber risk. It can become an operational disruption, regulatory investigation, financial loss, legal dispute, reputational crisis, and customer trust problem.
A supplier failure does not remain within procurement. It can interrupt production, compromise data, create sanctions exposure, and undermine resilience.
AI risk, cyber risk, third-party risk, operational risk, compliance risk, and strategic risk may be managed by different teams, but they are connected through the objectives, processes, systems, data, and relationships of the same organization.
This is what I mean by connected risk.
Connected risk does not mean that everything should be centralized in one department. Organizations need a federated model in which different functions retain their expertise and accountability while operating with shared context.
During the webinar, I compared this to a symphony orchestra. The violins, cellos, brass, woodwinds, and percussion each have separate parts. They are not collapsed into a single instrument. But without a conductor, they can drift into different tempos and interpretations.
The role of the conductor is not to play every instrument. It is to ensure that the different parts come together as a coherent performance.
Risk management requires the same orchestration. It needs both organizational leadership and technology capable of seeing across domains, identifying relationships, and connecting information to the business context.
Without that orchestration, every department may manage its own piece effectively while the organization still fails to understand the complete exposure.
Compliance Looks Backward; Risk Must Look Ahead
Maril and I repeatedly returned to the difference between evidence of past activity and intelligence about current or future exposure.
I used the analogy of driving a high-performance car while looking only in the rearview mirror.
Many GRC programs spend enormous effort collecting assessments, reconciling spreadsheets, documenting controls, and building reports. By the time the information reaches executives or the board, the environment may have changed.
One organization took approximately 200 hours to assemble a board risk report. By the time the report was completed, some of the conditions it described had existed for months and had already developed into active problems.
At that point, the organization was not managing risk. It was reporting incidents and events after the uncertainty had already materialized.
The rearview mirror is necessary. Organizations need to understand what happened and learn from it. The dashboard is also necessary because it shows the current condition of the organization.
But the driver’s primary attention must be on the road ahead.
Risk management should help the organization understand what is developing on the horizon, how conditions may change, and what decisions must be made before an exposure becomes an event.
Maril connected this to the pace of modern digital environments. Technology, systems, data, APIs, suppliers, and AI-enabled processes are changing continuously. A point-in-time assessment cannot, by itself, support continuous confidence.
Controls Need to Become Intelligence
The webinar’s title focused on risk, but the conversation repeatedly returned to controls because controls are where many organizations believe risk is being managed.
The problem is that organizations often know a control was documented or tested without understanding what risk it is reducing.
Maril framed this in practical terms: compliance may tell us that an activity was performed once and that the control worked when it was tested. But what happens if the control fails tomorrow? What undesirable outcome was it designed to prevent? Are there multiple layers of defense? Has the environment changed?
Controls should not exist simply as artifacts for an auditor. They should provide intelligence about the organization’s ability to achieve its objectives.
This requires moving beyond binary pass-or-fail reporting and asking more meaningful questions:
- What objective or business outcome does the control support?
- What uncertainty is it intended to address?
- What would happen if it failed?
- What other controls or capabilities provide protection?
- Has the environment changed since the last assessment?
- Is the control materially reducing exposure?
- What data demonstrates that it continues to operate effectively?
When control information is connected to objectives, operational telemetry, business processes, threats, and consequences, it becomes business intelligence.
That is the transition from documenting controls to understanding risk.
Risk and Resilience Are Stronger Together
Our conversation also explored the relationship between risk and resilience.
For decades, organizations have often managed risk in one area and business continuity or disaster recovery in another. These functions may report through different structures, use different technology, and speak different languages.
They belong together.
Risk management is forward-looking. It helps the organization anticipate uncertainty, consider scenarios, and navigate around obstacles. Resilience is about how the organization responds, recovers, and adapts when disruption occurs.
During the webinar, I compared this to running down a street. Risk management is looking ahead, observing traffic, bicycles, uneven pavement, and other potential obstacles. Resilience is what happens after you trip: how quickly you get back up and continue running.
Maril expanded the concept by emphasizing adaptation. Resilience is not only about preventing and recovering. It is about learning from current conditions and changing how the organization prepares for tomorrow.
Risk, resilience, and intelligence therefore reinforce one another. Risk helps the organization understand what could happen. Intelligence provides the data and context necessary to make decisions. Resilience enables the organization to absorb disruption and adapt.
We also discussed why the word resilience often receives stronger business engagement than risk. Risk can sound negative or threatening. It becomes something that business managers pass around like a hot potato because no one wants to “own” it.
Resilience is different. Every executive wants their strategy, operation, process, and function to be resilient.
This does not mean abandoning the language or discipline of risk management. It means connecting risk to an outcome the business immediately understands and values.
Many Black Swans Are Actually Failures of Awareness
Toward the end of the webinar, an audience question asked how organizations should prepare for black-swan events.
The answer is not that organizations can predict everything. They cannot.
But many events called black swans were not unimaginable or unprecedented. Pandemics, geopolitical conflict, extreme weather, supply-chain disruption, cyberattacks, financial crises, and infrastructure failures have been discussed in historical experience, scenarios, research, intelligence reports, and even fiction.
An event does not become a black swan simply because an organization ignored the possibility.
Maril observed that organizations often claim nobody could have seen an event coming when, in reality, people did see it coming. Leadership simply chose not to prioritize the exposure.
That distinction is critical.
The purpose of risk management is not to provide complete certainty. The world is uncertain. Instead, risk management should reduce uncertainty sufficiently that executives can move forward with an informed degree of confidence.
I shared the story of a risk leader who was asked during a job interview to explain the value of risk management. His answer was that, if he did the job correctly, executives would have no surprises in achieving their objectives.
He did not mean that nothing unexpected would ever happen. He meant that leadership would have considered the plausible scenarios, understood critical dependencies, and evaluated the choices available.
The greatest failure is not that an event occurs. It is that the organization encounters a foreseeable event without having seriously considered it.
The Future Requires Facilitators, Not Control Librarians
As the webinar moved toward its conclusion, Maril asked what successful GRC programs will do differently over the next several years.
The answer is that they will become more contextual, connected, continuous, and decision-oriented.
Future risk leaders will need to understand both the digital fabric of the organization and the business objectives that technology supports. They will need to facilitate conversations across functions, translate technical exposure into business consequences, and connect strategy with operational reality.
The risk leader should build bridges, not burn them.
Technology, data, automation, and AI will support this evolution, but automating the existing process is not enough. Faster evidence collection does not automatically produce better risk management. Automating a fragmented and backward-looking program simply enables the organization to perform the wrong activity more efficiently.
Successful programs will use technology to connect controls, risks, objectives, assets, processes, suppliers, threats, incidents, and business outcomes. They will continuously evaluate what is changing and provide intelligence that helps the organization act.
From Compliance Activity to Business Confidence
Maril closed the webinar by returning to her offensive-security perspective.
Attackers do not care what the organization’s attestation says. They do not care what appears in the risk register, dashboard, or policy. They care about what is true in the environment today.
That may be the best summary of the entire conversation.
The future of GRC depends on getting closer to the truth: understanding what is happening in the organization, across its controls, systems, suppliers, data, and business operations.
Risk is constantly changing. The organization’s understanding of risk must therefore change with it.
The goal is not to remove every uncertainty or prevent every possible event. That is impossible. The goal is to reduce uncertainty sufficiently that the organization can make better decisions tomorrow than it could today.
Perhaps risk is not truly the missing letter in GRC. It has always been present in the acronym.
What has been missing is the operational capability to connect risk to objectives, monitor how exposure changes, understand whether controls are effective, and use that intelligence to direct the business with confidence.
Watch the complete on-demand webinar with Michael Rasmussen and Maril Vernon: https://www.anecdotes.ai/thank-you/the-missing-letter-in-grc





