Day 1: Tuesday, June 10, 2025

12:00 PM - 1:00 PM

Registration & Networking

 

Track 1

Track 2

 
1:00 PM - 3:00 PM
 

Workshop

Risk and Resilience by Design: Building the Future-Proof Enterprise

In today’s dynamic business environment, where disruptions are becoming more frequent and unpredictable, risk and resilience must be built by design, not by reaction. Organizations that embed resilience into their core business strategy—rather than treating it as a reactive, compliance-driven exercise—are better equipped to navigate operational, cyber, and supply chain risks. This requires a shift from traditional risk management approaches to proactive, integrated frameworks that align risk, resilience, and performance objectives. By leveraging AI, automation, and real-time data analytics, businesses can anticipate threats, monitor risks dynamically, and continuously strengthen their resilience posture. The key to future-proofing operations lies in creating a resilience roadmap that not only mitigates risks but enables businesses to thrive in the face of uncertainty.

Michael Rasmussen

Analyst & Pundit, GRC 20/20 Research & GRC Report

Workshop

The Current State and The Future of Operational Risk Management

Join us for an interactive workshop that delves into the current and future landscape of Operational Risk management. Drawing from Elena Pykhova’s best-selling book, the session will address key challenges faced by professionals and provide strategies for ongoing success. Topics include revitalizing risk implementations, mastering interconnected risk management, enhancing foresight, fostering strong risk cultures, and tackling emerging threats like third-party risks, cybersecurity, and resilience. Gain valuable insights on benchmarking, measuring maturity, and developing a future-focused roadmap for success.

Elena Pykhova

Director and Founder, The Op Risk Company Ltd
 
3:00 PM - 3:30 PM

Break

 
3:30 PM - 4:30 PM
 

Workshop (continued)

Risk and Resilience by Design: Building the Future-Proof Enterprise

In today’s dynamic business environment, where disruptions are becoming more frequent and unpredictable, risk and resilience must be built by design, not by reaction. Organizations that embed resilience into their core business strategy—rather than treating it as a reactive, compliance-driven exercise—are better equipped to navigate operational, cyber, and supply chain risks. This requires a shift from traditional risk management approaches to proactive, integrated frameworks that align risk, resilience, and performance objectives. By leveraging AI, automation, and real-time data analytics, businesses can anticipate threats, monitor risks dynamically, and continuously strengthen their resilience posture. The key to future-proofing operations lies in creating a resilience roadmap that not only mitigates risks but enables businesses to thrive in the face of uncertainty.

Michael Rasmussen

Analyst & Pundit, GRC 20/20 Research & GRC Report

Workshop

Optimize your GRC Framework with AI. What's New and What’s Next?

Optimize your GRC Framework with AI – What’s New and What’s Next? explores the latest enhancements to the AI platform, designed to elevate your GRC capabilities. This session will showcase new features and innovations that empower organizations to streamline risk management, improve compliance, and enhance decision-making. Attendees will discover how AI-driven tools are transforming GRC processes, and gain insights into future developments that will keep your organization ahead in an ever-evolving risk landscape

Sunay Zelawat

Associate Director, Product Management, MetricStream
 
4:30 PM - 5:30 PM
 

Workshop (continued)

Risk and Resilience by Design: Building the Future-Proof Enterprise

In today’s dynamic business environment, where disruptions are becoming more frequent and unpredictable, risk and resilience must be built by design, not by reaction. Organizations that embed resilience into their core business strategy—rather than treating it as a reactive, compliance-driven exercise—are better equipped to navigate operational, cyber, and supply chain risks. This requires a shift from traditional risk management approaches to proactive, integrated frameworks that align risk, resilience, and performance objectives. By leveraging AI, automation, and real-time data analytics, businesses can anticipate threats, monitor risks dynamically, and continuously strengthen their resilience posture. The key to future-proofing operations lies in creating a resilience roadmap that not only mitigates risks but enables businesses to thrive in the face of uncertainty.

Michael Rasmussen

Analyst & Pundit, GRC 20/20 Research & GRC Report

Workshop

Navigating NIS2 & DORA: How to Mitigate Cyber Risk, Ensure Compliance & Resilience

With NIS2 and DORA reshaping the regulatory landscape, organizations must elevate their cybersecurity, compliance, and operational resilience strategies. This session explores how to navigate these evolving mandates, mitigate cyber risks proactively, and embed resilience into your risk management framework. Learn practical approaches to aligning with NIS2 and DORA requirements, leveraging technology to streamline compliance, and fostering a culture of continuous preparedness. Stay ahead of threats and turn regulatory pressure into a competitive advantage.

 
5:30 PM - 7:00 PM

Drinks & Reception

 
 

Day 2: Wednesday, June 11, 2025

8:00 AM - 9:00 AM

Registration & Networking Breakfast

 
9:00 AM - 9:05 AM

Welcome Note

Introduction and Welcome

 
9:05 AM - 9:45 AM

Opening Keynote

AI-First Connected GRC - GRC Simplified. Outcomes Amplified

As organisations face a rapidly evolving risk landscape—driven by cyber threats, regulatory changes, and operational complexity—the demand for a smarter, more connected GRC strategy is urgent. This session explores how an AI-first approach is transforming GRC into an intelligent, unified ecosystem. Explore how generative and agentic AI streamline assessments, automate evidence collection, and deliver real-time insights—driving agility, accountability, and strategic impact. Join us to see how AI-powered Connected GRC simplifies governance and amplifies outcomes across the enterprise.

Gaurav Kapoor

Co-founder & Vice Chairman, MetricStream
 
9:45 AM - 10:30 AM

CXO panel

The Evolving Role of a Risk & Compliance Officer

As regulatory landscapes shift and businesses embrace digital transformation, the role of Chief Risk & Compliance Officers is rapidly evolving. Beyond traditional oversight, they now play a strategic role in embedding resilience, managing emerging risks, and leveraging technology for proactive compliance. This session explores how risk professionals can adapt to increasing expectations, harness AI and automation, and drive a culture of accountability, ensuring organizations remain agile in an ever-changing environment.

Rajeev Bhatnagar

Chief Risk and Compliance Officer, International and Treasury Services, BNY

Victoria Stubbs

Managing Director, Compliance, Barclays UK

Dr. Adriane Winter

Chief Compliance Officer / Co-Head of Global Legal, Compliance, Risk and ICS, BSH Home Appliances Group
 
10:30 AM - 11:15 AM

Case Study

Nordea's GRC Journey with MetricStream

Nordea started the GRC journey in 2022 with the ambition to create one Integrated Risk Management Application (IRMA). With the point of departure to implement an enterprise wide GRC solution that would establish common risk processes across all lines of defence, Nordea have now created the foundation to embark on the next step of our GRC MetricStream journey. A journey that take outset in the existing GRC set up, but with the ambition to enable the business usage even more with the support from Artificial Intelligence. With the establishment of one data model we can now utilise date from several risk processes which open the door for even better business usage of our risk management tool.

Jacob Holmehave

Head of Group Risk Office, Nordea

Brian F. Sørensen

Chief Project Manager - Group Risk Change Management, Nordea
 
11:15 AM - 11:35 AM

Break

 
11:35 AM - 12:15 PM

Product Keynote

AI-First Connected GRC: The Next Frontier in Risk and Resilience

As GRC continues to evolve in an increasingly complex risk environment, the next frontier is being shaped by the transformative power of artificial intelligence. AI is the catalyst accelerating every element of Connected GRC. From predictive analytics to intelligent automation and real-time decision support, learn how MetricStream AI-first Connected GRC is redefining how organizations anticipate risk, ensure compliance, and drive strategic agility.

Whether you're a CRO, CISO, risk leader, or compliance executive, this session will equip you with actionable strategies to future-proof your GRC programs and unlock measurable value—at scale.

Raghuram Srinivas

Head of Product, MetricStream
 
12:15 PM - 1:00 PM

Expert Talk 

AI GRC: Accelerating Growth & Innovation with Governance

Artificial Intelligence (AI) is rapidly transforming Governance, Risk, and Compliance (GRC) by automating processes, generating meaningful insights, and enhancing productivity. However, as AI adoption accelerates, organizations must navigate emerging risks such as security threats, ethical dilemmas, bias, disinformation, and social manipulation. GRC professionals must not only leverage AI to optimize risk management and compliance but also establish guardrails to ensure its responsible and ethical use across the enterprise. To fully harness AI’s potential, businesses need robust governance frameworks, proactive risk management, and strong compliance mechanisms that foster trust, accountability, and resilience.

Michael Rasmussen

Analyst & Pundit, GRC 20/20 Research & GRC Report
 
1:00 PM - 2:00 PM

Networking Lunch

 

Track 1

Track 2

 
2:00 PM - 2:40 PM
 

Panel

What’s Next for Operational Risk Management?

As the risk landscape evolves, operational risk management must adapt to new challenges, including emerging technologies, regulatory pressures, and dynamic market conditions. In this session, the panelists will explore what are the key changes expected in operational risk management, how to make operational risk more strategic and how to drive actional insights through emerging technologies like AI, automation and quantification. Join us to understand the practical strategies to elevate your ORM programs and build resilience while maintaining a competitive edge in a dynamic risk environment.

Armel Massimina

Operational Risk Lead, National Bank of Kuwait (International)

Benjamin Rowsell

Head of Enterprise and Operational Risk, Nationwide Building Society

Simon Wallis

Global Head of Risk & Assurance, IQ-EQ

Panel

Towards a Secure Organisation: Top Strategic Priorities for Cyber Risk Leaders

"Towards a Secure Organization" addresses strategic cyber risk priorities for leaders, focusing on cloud environments and their impact on internal IT, Cyber, and Infosec functions. This session explores data protection, compliance, threat mitigation, and third-party governance, providing actionable insights into best practices, regulatory adherence, and the implementation of effective cloud cybersecurity tools and frameworks for enhanced resilience.

Marlon P. Sorongon

CISO, Maybank Philippines

Fox Ahmed

Global Head of Cybersecurity and Technology and Data Protection Regulatory Risk, BNP Paribas
 
2:40 PM - 3:20 PM
 

Expert Talk

The Future of Compliance is Automation

The Future of Compliance is Automation explores how automation is revolutionizing the compliance landscape. This session will focus on the role of advanced technologies like AI and machine learning in streamlining compliance processes, reducing manual efforts, and minimizing errors. Attendees will gain insights into how automated solutions are improving efficiency, ensuring continuous monitoring, and helping organizations stay ahead of regulatory changes. Discover the future of compliance and how to implement automation to drive a smarter, more agile approach.

Elena Garcia Aguado

Head of Compliance, RWE Renewables

Gabor Molnar

Compliance Officer, Knorr-Bremse

Expert Talk

The future of GRC is Multilingual: AI agents for translation now live in Metricstream

In today’s global marketplace, managing risk and ensuring compliance must span diverse regions, markets, and languages. Relying solely on English-based assets and systems is no longer sufficient. To fully support non-English-speaking stakeholders, we must embrace translation and AI. Now, through a new integration with Intento, AI-powered translation agents are live in Metricstream—enabling real-time access to the entire Metricstream ecosystem and all content, in up to 650 languages.

Grigory Sapunov

CTO & Co-Founder, Intento
 
3:20 PM - 3:40 PM

Break

 
3:40 PM - 4:20 PM
 

Panel

Establishing a Strong Compliance Culture: Beyond the Corporate Compliance Code

A strong compliance culture goes beyond a mere tick in the box or having a written compliance code—it requires embedding ethical practices, accountability, and proactive risk management into an organization’s DNA. This session explores strategies to foster an environment where compliance is integral to decision-making, driven by leadership and embraced across all levels. Discover how to align organizational values with daily operations, leverage training and technology, and measure the impact of a truly effective compliance culture.

Chris Knox

Global Director - Financial Services Regulatory Compliance, Microsoft Corporation

Tetiana Isaieva

Head of Compliance, Roche

Dave Pickering

Head of Non-Financial Risk Taskforce, Canada Life UK

Antonios Gkoulousis

Head Of Conduct Risk, Eurobank SA

Panel

Transforming Your GRC Programs with AI innovations

Transforming Your GRC Programs with AI Innovations explores how organizations can revolutionize their governance, risk, and compliance (GRC) programs by incorporating AI-driven solutions. This session will highlight the latest AI innovations that enhance risk assessment, automate compliance processes, and improve decision-making. Attendees will gain insights on how AI can streamline workflows, improve accuracy, and help organizations stay ahead of regulatory changes. Discover practical strategies for integrating AI into your GRC framework for more efficient and effective risk management.

Thoralf Knuth

Chief Data Protection Officer, Robert Bosch

Dane Pedro

Head of UK Compliance & MLRO, Mollie UK

Libby Denchfield

Chief Platform & Functions Officer, Legal, Risk, Compliance & Corporate Secretariat, Standard Chartered Bank
 
4:20 PM - 5:00 PM
 

Panel

The Journey Towards Operational Resilience: Key Priorities for Risk and Resilience Leaders

The Journey Towards Operational Resilience delves into the critical priorities for risk and resilience leaders as they navigate today's dynamic risk landscape. This session will explore strategies to build resilience across people, processes, and technology, ensuring organizations can withstand and recover from disruptions. Attendees will learn key insights on aligning risk management with business continuity, fostering a resilient culture, and adopting innovative approaches to safeguard operations in an increasingly uncertain world.

Sarah Garrington

Head of Resilience, Royal London Group

Tim Armit

Head of Operational Resilience and Business Continuity, QBE

Nick Fuller

Global Head of Resilience Risk Management, BNY

Renisha Rajpaul

Group Executive Head: Business Risk Management, Vodacom

Product Session

Stay Ahead of Cyber Risk: What’s New in MetricStream CyberGRC

Stay Ahead of Cyber Risk: What’s New in MetricStream CyberGRC explores the latest updates to MetricStream's CyberGRC solution designed to combat evolving cyber threats. This session will highlight new features that enhance risk visibility, streamline incident response, and ensure robust compliance with the latest cybersecurity regulations. Attendees will learn how MetricStream CyberGRC empowers organizations to proactively manage cyber risk, strengthen their security posture, and remain resilient in the face of an increasingly complex threat landscape.

 
5:00 PM - 5:40 PM

GRC Journey Awards

The GRC Journey Awards honor outstanding MetricStream customers and partners who are shaping the future of governance, risk, and compliance. These awards recognize organizations and individuals who demonstrate exceptional vision, execution, and impact in advancing risk-aware cultures, driving operational resilience, and delivering business value through innovative GRC strategies and solutions.

 
5:40 PM - 7:00 PM

Drinks & Reception

 
 

Day 3: Thursday, June 12, 2025

8:00 AM - 9:00 AM

Registration & Networking Breakfast

 
9:00 AM - 9:05 AM

Welcome Note

Introduction and Welcome

 
9:05 AM - 9:50 AM

Opening Keynote

Shaping the Future of GRC with AI and Resilience

As interconnected risks escalate and transformative forces continue to accelerate, how can you and your risk teams stay proactive and current? Discover the power of connection in Governance, Risk, and Compliance (GRC) as we explore the future of risk, from people to processes to next-generation technologies like Gen AI. We will discuss key trends and how to apply them to take your GRC programs, career, and insights to the next level. Join us as we delve into the dynamic realms of GRC and AI to navigate complex risk and regulatory landscapes with agility and resilience.

Gunjan Sinha

Executive Chairman, MetricStream
 
9:50 AM - 10:35 AM

Customer Stories

The Cost of Doing Nothing: The Business Case for Automating Your GRC Program

Discover how automating GRC processes can eliminate inefficiencies, reduce costs, and strengthen risk management. This session explores the hidden pitfalls of manual, siloed systems and offers practical guidance on streamlining GRC through the right mix of technology and talent. Industry experts will share real-world insights, highlight best practices, and walk through how to measure the ROI of GRC automation—helping you move forward confidently on your GRC transformation journey.

Mark Avery Chiang

Deputy CRO, Hargreaves Lansdown

Wilna Meiring

Managing Executive: Corporate Risk and Security , Vodacom Group
 
10:35 AM - 10:55 AM

Break

 
10:55 AM - 11:35 AM

CXO Panel

Managing Interconnected Risks: Why It Should Be a Boardroom Priority

In today’s complex business landscape, risks are no longer isolated—they are deeply interconnected, spanning cybersecurity, supply chains, regulations, and reputation. Boards must recognize that a siloed approach to risk management is no longer sufficient. This session explores why leaders must adopt a holistic risk strategy, enhance cross-functional collaboration, and leverage data-driven insights to anticipate and mitigate cascading threats, ensuring long-term resilience and sustainable business growth.

Lucy Da Piedade

Managing Director, Former Chief Controls Officer, Barclays Bank

Sowmya Murthy

Chief Risk Officer, Allianz Technology

Carlos Martin

Executive Director - Risk Management & Compliance, JPMorgan

Michael Rasmussen

Analyst & Pundit, GRC 20/20 Research & GRC Report
 
11:35 AM - 12:15 PM

Case Study 

Zurich Insurance's GRC Journey with MetricStream

How to Successfully Implement a GRC Solution in Less Than a Year? What are the absolute golden rules to follow to move from manual tasks to state-of-the-art GRC technology? How can you continue the journey to become best in class? How do you establish trust within the golden triangle of IT, GRC vendor, and business? Join this session to get answers to these questions and more.

Fabien Robichon

Head of Compliance Analytics and Innovation, Zurich Insurance Group

Dino Placido Bivona

IT Business Partner - GRC Corporate Functions, Zurich Insurance Group
 
12:15 PM - 1:15 PM

Networking Lunch

 

Track 1

Track 2

 
1:15 PM - 1:55 PM
 

Case Study

MetricStream – Operational Risk Module Implementation

A walkthrough of the IQ-EQ MetricStream implementation journey including lessons learned and the continued embedding of MetricStream across the Group.

Simon Wallis

Global Head of Risk & Assurance, IQ-EQ

Product Session

Begin Your Operational Resilience Journey with MetricStream

Begin Your Operational Resilience Journey with MetricStream guides organizations in building a strong foundation for resilience in the face of disruptions. This session will showcase how MetricStream’s solutions empower businesses to identify, assess, and mitigate risks while ensuring business continuity. Attendees will learn how to integrate resilience strategies into their operations, enhance crisis management capabilities, and drive proactive risk management. Discover how MetricStream’s approach enables organizations to thrive in an unpredictable and complex risk landscape.

 
1:55 PM - 2:35 PM
 

Expert Talk

Integrating Value into GRC – A Fresh Perspective

In today’s rapidly evolving business landscape, Governance, Risk Management, and Compliance (GRC) systems are often perceived as cumbersome, abstract, and disconnected from the core purpose of creating and preserving value. This session will challenge conventional approaches to GRC and present innovative, thought-provoking ideas to transform these systems into dynamic, value-driven frameworks that resonate with organizations and their people. Join this session to explore how we can make GRC exciting, impactful, and integral to the future of risk management.

Nam Phong Ho

Founder, Board Member and Strategic Advisor, Alpha Flow Zenith

Product Session

What's New in MetricStream's Operational Risk and Enterprise Risk Management

Discover the latest innovations in MetricStream’s Operational Risk and Enterprise Risk Management solutions. This session will spotlight new features that enhance risk visibility, streamline risk assessments, and elevate control testing efficiency. Learn how AI-driven insights, integrated issue management, and intuitive dashboards empower risk teams to act faster and smarter. Whether you're modernizing risk frameworks or strengthening resilience, explore how MetricStream is driving the next generation of risk management excellence across the enterprise.

 
2:35 PM - 2:55 PM

Break

 
2:55 PM - 3:35 PM
 

Panel

Driving Operational Efficiency and Business Growth through Collaborative Internal Audits

In today’s dynamic business landscape, internal audits are no longer just a compliance exercise—they are a strategic tool for driving operational efficiency and growth. This session explores how organizations can foster collaboration between audit, risk, and business teams to enhance transparency, identify opportunities, and streamline processes. Learn best practices for leveraging technology, data insights, and cross-functional partnerships to transform audits into a value-driven function that strengthens resilience and accelerates business success.

Nick Woods

Chief Auditor - Risk, Credit, Financial Crime, NatWest Group

Claudia Iacobucci

Head of Assurance, Risk and Internal Controls, ABB

Product Session

Level Up Your Compliance Posture with MetricStream’s All-New Compliance Management

Level Up with MetricStream’s All-New Compliance Management showcases the latest features designed to enhance compliance processes and drive greater efficiency. This session will explore how MetricStream’s advanced solutions streamline compliance tracking, automate workflows, and provide real-time visibility into regulatory requirements. Attendees will learn how to leverage these new capabilities to improve accuracy, reduce manual effort, and ensure proactive compliance. Discover how MetricStream’s innovative tools help organizations stay ahead of evolving regulations while mitigating compliance risks.

 
3:35 PM - 3:50 PM

Closing Keynote

 
3:50 PM - 5:50 PM

Drinks & Reception