Metricstream Logo
×
Blogs

The Board Is Asking a Different Question. Is Your GRC Function Ready to Answer It?

blog-28jul-26
5 min read

Introduction

Over the years, one question has consistently found its way into almost every boardroom discussion around Governance, Risk, and Compliance.

The question is "Are we covered?" which is really shorthand for a cluster of harder questions, including:

  • Are our controls effective?
  • Are we compliant with regulations?
  • Did we pass the audit?

Those questions are still important, and they always will be. But lately, I've noticed another question creeping into those conversations. Not loudly. Not dramatically. Just... more frequently than before.

The question is: "Are we ready?", which translates to:

  • Ready for what comes next
  • Ready for something we didn't see coming

And that, in my opinion, is a very different conversation.

From Reactive to Anticipatory

Risk management has traditionally been built around understanding the past. And then an incident happens.

  • We investigate it
  • We identify the gaps
  • We strengthen the controls
  • We update the framework

That's how mature GRC programs evolve, and there's absolutely nothing wrong with that. The problem is that many of today's risks don't give us the luxury of learning from history first.

  • A supplier's security weakness can quickly become your problem
  • A business unit experimenting with an AI tool can unknowingly create compliance or privacy issues before governance teams are even aware of it
  • A geopolitical event thousands of miles away can suddenly disrupt a supply chain that looked perfectly stable only a few months ago

These aren't simply familiar risks happening faster. They're entirely new combinations of technology, regulation, and business operating together in ways we've never really experienced before.

If we're only looking backward, we'll always be one step behind.

One thing I've learned through my journey in both business development and GRC is that resilience has never been about reacting the fastest. It's about being prepared before everyone else is forced to react.

Years ago, I wrote about what I called ARIA: Awareness, Readiness, Innovation, and Adaptability. I still believe those four qualities matter today, perhaps even more than they did then. Technology is evolving faster than governance. Business models are changing faster than policies. And customer expectations are changing faster than organizations can often keep up.

In an environment like this, awareness alone isn't enough. Readiness has become a competitive advantage.

To be fair, I don't think GRC teams are getting this wrong because they lack capability. Most teams are doing exceptional work despite limited resources, growing regulatory expectations, and businesses that are constantly trying to move faster.

Many still carry the perception that compliance slows innovation. Personally, I've never believed that. When GRC is embedded into business the right way, it actually helps organizations move faster.

  • Leaders make better decisions because they understand the risks
  • Teams innovate with greater confidence because someone has already thought about the unintended consequences
  • Good governance doesn't create hesitation. It creates clarity, and clarity allows businesses to move

What Boards Really Expect from GRC Leaders in the Age of AI

Whenever I speak with senior leaders, three expectations keep coming up. 

The first is anticipation.

Leadership teams don't just want to know what happened last quarter; they want to understand what's changing around them before it becomes tomorrow's problem. Whether that's AI, changing regulations, geopolitical uncertainty, or evolving cyber threats, they expect GRC to help connect those signals early.

The second is integration.

Businesses don’t experience risk in silos. Cyber doesn't stop at the IT department. Third-party risk doesn't end with procurement. Privacy isn't just Legal's responsibility. Everything is connected. The organizations that manage this well are those in which GRC acts as the bridge between functions, rather than another independent function producing reports.

The third, and perhaps the most important, is communication.

Some of the best GRC professionals I've worked with weren't necessarily the ones who knew every regulation by heart. They were the ones who could explain risk in business language.

Instead of discussing control deficiencies, they talked about customer trust. Instead of talking about inherent risk ratings, they talked about growth, reputation, and strategic decisions.

That's when boards stop seeing GRC as a reporting function and start seeing it as a business partner.

If there's one area where I believe this evolution is becoming impossible to ignore, it's Artificial Intelligence. Almost every organization, including GRC teams themselves, is experimenting with AI in one form or another. Some formally, many informally.

The technology is moving incredibly fast. Regulations are trying to keep pace. Meanwhile, the risks extend far beyond cybersecurity. It can affect privacy, bias, ethics, intellectual property, transparency, and customer trust.

Traditional governance frameworks weren't really built for this kind of challenge, which is exactly why GRC has an opportunity to lead rather than follow. The organizations that establish sensible AI governance today won't just reduce risk. They'll create confidence for the business to innovate responsibly.

Final Thoughts

I'll leave you with one final thought.

The value of a GRC leader isn't measured by the number of policies they've written or dashboards they've produced. It's measured by whether leadership feels more confident making important decisions because of the conversations they've had.

Sometimes the most valuable thing we can say isn't: "Everything looks good."

Sometimes it's: "Here's where we need to be better prepared."

That honesty builds trust. And trust has always been one of the strongest foundations of good governance. As boards continue asking whether organizations are truly ready, not just compliant, I believe the role of GRC is becoming more strategic than ever before. However, the question is no longer whether we'll be invited into those conversations. It's whether we're prepared to lead them.

Solomon

Solomon D'souza Senior Director, Global Inside Sales • Inside Sales - North America

Solomon D’souza is the Senior Director, Global Head of Business Development, with 15+ years’ experience in business development, compliance, corporate training, and enterprise software for financial services. He builds high-performance teams, designs and executes pilot programs, and aligns technology, people, and processes to improve business performance. Solomon excels at gap and learning-need analysis, resource planning, and implementing standards that drive measurable process improvement. He is known for strong cross-functional relationship building, advising senior executives on risk and compliance decisions, and managing complex client engagements. Progressive and decisive, Solomon translates corporate strategy into actionable plans and effectively handles multiple priorities to achieve strategic objectives.