Day 1: Tuesday, June 10, 2025
Registration & Networking
Track 1
Track 2
Workshop
Risk and Resilience by Design: Building the Future-Proof Enterprise
In today’s dynamic business environment, where disruptions are becoming more frequent and unpredictable, risk and resilience must be built by design, not by reaction. Organizations that embed resilience into their core business strategy—rather than treating it as a reactive, compliance-driven exercise—are better equipped to navigate operational, cyber, and supply chain risks. This requires a shift from traditional risk management approaches to proactive, integrated frameworks that align risk, resilience, and performance objectives. By leveraging AI, automation, and real-time data analytics, businesses can anticipate threats, monitor risks dynamically, and continuously strengthen their resilience posture. The key to future-proofing operations lies in creating a resilience roadmap that not only mitigates risks but enables businesses to thrive in the face of uncertainty.

Michael Rasmussen
Analyst & Pundit, GRC 20/20 Research & GRC Report
Workshop
The Current State and The Future of Operational Risk Management
Join us for an interactive workshop that delves into the current and future landscape of Operational Risk management. Drawing from Elena Pykhova’s best-selling book, the session will address key challenges faced by professionals and provide strategies for ongoing success. Topics include revitalizing risk implementations, mastering interconnected risk management, enhancing foresight, fostering strong risk cultures, and tackling emerging threats like third-party risks, cybersecurity, and resilience. Gain valuable insights on benchmarking, measuring maturity, and developing a future-focused roadmap for success.

Elena Pykhova
Director and Founder, The Op Risk Company LtdBreak
Workshop (continued)
Risk and Resilience by Design: Building the Future-Proof Enterprise
In today’s dynamic business environment, where disruptions are becoming more frequent and unpredictable, risk and resilience must be built by design, not by reaction. Organizations that embed resilience into their core business strategy—rather than treating it as a reactive, compliance-driven exercise—are better equipped to navigate operational, cyber, and supply chain risks. This requires a shift from traditional risk management approaches to proactive, integrated frameworks that align risk, resilience, and performance objectives. By leveraging AI, automation, and real-time data analytics, businesses can anticipate threats, monitor risks dynamically, and continuously strengthen their resilience posture. The key to future-proofing operations lies in creating a resilience roadmap that not only mitigates risks but enables businesses to thrive in the face of uncertainty.

Michael Rasmussen
Analyst & Pundit, GRC 20/20 Research & GRC Report
Workshop
Optimize your GRC Framework with AI. What's New and What’s Next?
Optimize your GRC Framework with AI – What’s New and What’s Next? explores the latest enhancements to the AI platform, designed to elevate your GRC capabilities. This session will showcase new features and innovations that empower organizations to streamline risk management, improve compliance, and enhance decision-making. Attendees will discover how AI-driven tools are transforming GRC processes, and gain insights into future developments that will keep your organization ahead in an ever-evolving risk landscape

Sunay Zelawat
Associate Director, Product Management, MetricStreamWorkshop (continued)
Risk and Resilience by Design: Building the Future-Proof Enterprise
In today’s dynamic business environment, where disruptions are becoming more frequent and unpredictable, risk and resilience must be built by design, not by reaction. Organizations that embed resilience into their core business strategy—rather than treating it as a reactive, compliance-driven exercise—are better equipped to navigate operational, cyber, and supply chain risks. This requires a shift from traditional risk management approaches to proactive, integrated frameworks that align risk, resilience, and performance objectives. By leveraging AI, automation, and real-time data analytics, businesses can anticipate threats, monitor risks dynamically, and continuously strengthen their resilience posture. The key to future-proofing operations lies in creating a resilience roadmap that not only mitigates risks but enables businesses to thrive in the face of uncertainty.

Michael Rasmussen
Analyst & Pundit, GRC 20/20 Research & GRC Report
Workshop
Navigating NIS2 & DORA: How to Mitigate Cyber Risk, Ensure Compliance & Resilience
With NIS2 and DORA reshaping the regulatory landscape, organizations must elevate their cybersecurity, compliance, and operational resilience strategies. This session explores how to navigate these evolving mandates, mitigate cyber risks proactively, and embed resilience into your risk management framework. Learn practical approaches to aligning with NIS2 and DORA requirements, leveraging technology to streamline compliance, and fostering a culture of continuous preparedness. Stay ahead of threats and turn regulatory pressure into a competitive advantage.
Drinks & Reception
Day 2: Wednesday, June 11, 2025
Registration & Networking Breakfast
Welcome Note
Introduction and Welcome
Opening Keynote
AI-First Connected GRC - GRC Simplified. Outcomes Amplified
As organisations face a rapidly evolving risk landscape—driven by cyber threats, regulatory changes, and operational complexity—the demand for a smarter, more connected GRC strategy is urgent. This session explores how an AI-first approach is transforming GRC into an intelligent, unified ecosystem. Explore how generative and agentic AI streamline assessments, automate evidence collection, and deliver real-time insights—driving agility, accountability, and strategic impact. Join us to see how AI-powered Connected GRC simplifies governance and amplifies outcomes across the enterprise.

Gaurav Kapoor
Co-founder & Vice Chairman, MetricStreamCXO panel
The Evolving Role of a Risk & Compliance Officer
As regulatory landscapes shift and businesses embrace digital transformation, the role of Chief Risk & Compliance Officers is rapidly evolving. Beyond traditional oversight, they now play a strategic role in embedding resilience, managing emerging risks, and leveraging technology for proactive compliance. This session explores how risk professionals can adapt to increasing expectations, harness AI and automation, and drive a culture of accountability, ensuring organizations remain agile in an ever-changing environment.

Rajeev Bhatnagar
Chief Risk and Compliance Officer, International and Treasury Services, BNY
Victoria Stubbs
Managing Director, Compliance, Barclays UK
Dr. Adriane Winter
Chief Compliance Officer / Co-Head of Global Legal, Compliance, Risk and ICS, BSH Home Appliances GroupCase Study
Nordea's GRC Journey with MetricStream
Nordea started the GRC journey in 2022 with the ambition to create one Integrated Risk Management Application (IRMA). With the point of departure to implement an enterprise wide GRC solution that would establish common risk processes across all lines of defence, Nordea have now created the foundation to embark on the next step of our GRC MetricStream journey. A journey that take outset in the existing GRC set up, but with the ambition to enable the business usage even more with the support from Artificial Intelligence. With the establishment of one data model we can now utilise date from several risk processes which open the door for even better business usage of our risk management tool.

Jacob Holmehave
Head of Group Risk Office, Nordea
Brian F. Sørensen
Chief Project Manager - Group Risk Change Management, NordeaBreak
Product Keynote
AI-First Connected GRC: The Next Frontier in Risk and Resilience
As GRC continues to evolve in an increasingly complex risk environment, the next frontier is being shaped by the transformative power of artificial intelligence. AI is the catalyst accelerating every element of Connected GRC. From predictive analytics to intelligent automation and real-time decision support, learn how MetricStream AI-first Connected GRC is redefining how organizations anticipate risk, ensure compliance, and drive strategic agility.
Whether you're a CRO, CISO, risk leader, or compliance executive, this session will equip you with actionable strategies to future-proof your GRC programs and unlock measurable value—at scale.

Raghuram Srinivas
Head of Product, MetricStreamExpert Talk
AI GRC: Accelerating Growth & Innovation with Governance
Artificial Intelligence (AI) is rapidly transforming Governance, Risk, and Compliance (GRC) by automating processes, generating meaningful insights, and enhancing productivity. However, as AI adoption accelerates, organizations must navigate emerging risks such as security threats, ethical dilemmas, bias, disinformation, and social manipulation. GRC professionals must not only leverage AI to optimize risk management and compliance but also establish guardrails to ensure its responsible and ethical use across the enterprise. To fully harness AI’s potential, businesses need robust governance frameworks, proactive risk management, and strong compliance mechanisms that foster trust, accountability, and resilience.

Michael Rasmussen
Analyst & Pundit, GRC 20/20 Research & GRC ReportNetworking Lunch
Track 1
Track 2
Panel
What’s Next for Operational Risk Management?
As the risk landscape evolves, operational risk management must adapt to new challenges, including emerging technologies, regulatory pressures, and dynamic market conditions. In this session, the panelists will explore what are the key changes expected in operational risk management, how to make operational risk more strategic and how to drive actional insights through emerging technologies like AI, automation and quantification. Join us to understand the practical strategies to elevate your ORM programs and build resilience while maintaining a competitive edge in a dynamic risk environment.

Armel Massimina
Operational Risk Lead, National Bank of Kuwait (International)
Benjamin Rowsell
Head of Enterprise and Operational Risk, Nationwide Building Society
Simon Wallis
Global Head of Risk & Assurance, IQ-EQ
Panel
Towards a Secure Organisation: Top Strategic Priorities for Cyber Risk Leaders
"Towards a Secure Organization" addresses strategic cyber risk priorities for leaders, focusing on cloud environments and their impact on internal IT, Cyber, and Infosec functions. This session explores data protection, compliance, threat mitigation, and third-party governance, providing actionable insights into best practices, regulatory adherence, and the implementation of effective cloud cybersecurity tools and frameworks for enhanced resilience.

Marlon P. Sorongon
CISO, Maybank Philippines
Fox Ahmed
Global Head of Cybersecurity and Technology and Data Protection Regulatory Risk, BNP ParibasExpert Talk
The Future of Compliance is Automation
The Future of Compliance is Automation explores how automation is revolutionizing the compliance landscape. This session will focus on the role of advanced technologies like AI and machine learning in streamlining compliance processes, reducing manual efforts, and minimizing errors. Attendees will gain insights into how automated solutions are improving efficiency, ensuring continuous monitoring, and helping organizations stay ahead of regulatory changes. Discover the future of compliance and how to implement automation to drive a smarter, more agile approach.

Elena Garcia Aguado
Head of Compliance, RWE Renewables
Gabor Molnar
Compliance Officer, Knorr-Bremse
Expert Talk
The future of GRC is Multilingual: AI agents for translation now live in Metricstream
In today’s global marketplace, managing risk and ensuring compliance must span diverse regions, markets, and languages. Relying solely on English-based assets and systems is no longer sufficient. To fully support non-English-speaking stakeholders, we must embrace translation and AI. Now, through a new integration with Intento, AI-powered translation agents are live in Metricstream—enabling real-time access to the entire Metricstream ecosystem and all content, in up to 650 languages.

Grigory Sapunov
CTO & Co-Founder, IntentoBreak
Panel
Establishing a Strong Compliance Culture: Beyond the Corporate Compliance Code
A strong compliance culture goes beyond a mere tick in the box or having a written compliance code—it requires embedding ethical practices, accountability, and proactive risk management into an organization’s DNA. This session explores strategies to foster an environment where compliance is integral to decision-making, driven by leadership and embraced across all levels. Discover how to align organizational values with daily operations, leverage training and technology, and measure the impact of a truly effective compliance culture.

Chris Knox
Global Director - Financial Services Regulatory Compliance, Microsoft Corporation
Tetiana Isaieva
Head of Compliance, Roche
Dave Pickering
Head of Non-Financial Risk Taskforce, Canada Life UK
Antonios Gkoulousis
Head Of Conduct Risk, Eurobank SA
Panel
Transforming Your GRC Programs with AI innovations
Transforming Your GRC Programs with AI Innovations explores how organizations can revolutionize their governance, risk, and compliance (GRC) programs by incorporating AI-driven solutions. This session will highlight the latest AI innovations that enhance risk assessment, automate compliance processes, and improve decision-making. Attendees will gain insights on how AI can streamline workflows, improve accuracy, and help organizations stay ahead of regulatory changes. Discover practical strategies for integrating AI into your GRC framework for more efficient and effective risk management.

Thoralf Knuth
Chief Data Protection Officer, Robert Bosch
Dane Pedro
Head of UK Compliance & MLRO, Mollie UK
Libby Denchfield
Chief Platform & Functions Officer, Legal, Risk, Compliance & Corporate Secretariat, Standard Chartered BankPanel
The Journey Towards Operational Resilience: Key Priorities for Risk and Resilience Leaders
The Journey Towards Operational Resilience delves into the critical priorities for risk and resilience leaders as they navigate today's dynamic risk landscape. This session will explore strategies to build resilience across people, processes, and technology, ensuring organizations can withstand and recover from disruptions. Attendees will learn key insights on aligning risk management with business continuity, fostering a resilient culture, and adopting innovative approaches to safeguard operations in an increasingly uncertain world.

Sarah Garrington
Head of Resilience, Royal London Group
Tim Armit
Head of Operational Resilience and Business Continuity, QBE
Nick Fuller
Global Head of Resilience Risk Management, BNY
Renisha Rajpaul
Group Executive Head: Business Risk Management, Vodacom
Product Session
Stay Ahead of Cyber Risk: What’s New in MetricStream CyberGRC
Stay Ahead of Cyber Risk: What’s New in MetricStream CyberGRC explores the latest updates to MetricStream's CyberGRC solution designed to combat evolving cyber threats. This session will highlight new features that enhance risk visibility, streamline incident response, and ensure robust compliance with the latest cybersecurity regulations. Attendees will learn how MetricStream CyberGRC empowers organizations to proactively manage cyber risk, strengthen their security posture, and remain resilient in the face of an increasingly complex threat landscape.
GRC Journey Awards
The GRC Journey Awards honor outstanding MetricStream customers and partners who are shaping the future of governance, risk, and compliance. These awards recognize organizations and individuals who demonstrate exceptional vision, execution, and impact in advancing risk-aware cultures, driving operational resilience, and delivering business value through innovative GRC strategies and solutions.
Drinks & Reception
Day 3: Thursday, June 12, 2025
Registration & Networking Breakfast
Welcome Note
Introduction and Welcome
Opening Keynote
Shaping the Future of GRC with AI and Resilience
As interconnected risks escalate and transformative forces continue to accelerate, how can you and your risk teams stay proactive and current? Discover the power of connection in Governance, Risk, and Compliance (GRC) as we explore the future of risk, from people to processes to next-generation technologies like Gen AI. We will discuss key trends and how to apply them to take your GRC programs, career, and insights to the next level. Join us as we delve into the dynamic realms of GRC and AI to navigate complex risk and regulatory landscapes with agility and resilience.

Gunjan Sinha
Executive Chairman, MetricStreamCustomer Stories
The Cost of Doing Nothing: The Business Case for Automating Your GRC Program
Discover how automating GRC processes can eliminate inefficiencies, reduce costs, and strengthen risk management. This session explores the hidden pitfalls of manual, siloed systems and offers practical guidance on streamlining GRC through the right mix of technology and talent. Industry experts will share real-world insights, highlight best practices, and walk through how to measure the ROI of GRC automation—helping you move forward confidently on your GRC transformation journey.

Mark Avery Chiang
Deputy CRO, Hargreaves Lansdown
Wilna Meiring
Managing Executive: Corporate Risk and Security , Vodacom GroupBreak
CXO Panel
Managing Interconnected Risks: Why It Should Be a Boardroom Priority
In today’s complex business landscape, risks are no longer isolated—they are deeply interconnected, spanning cybersecurity, supply chains, regulations, and reputation. Boards must recognize that a siloed approach to risk management is no longer sufficient. This session explores why leaders must adopt a holistic risk strategy, enhance cross-functional collaboration, and leverage data-driven insights to anticipate and mitigate cascading threats, ensuring long-term resilience and sustainable business growth.

Lucy Da Piedade
Managing Director, Former Chief Controls Officer, Barclays Bank
Sowmya Murthy
Chief Risk Officer, Allianz Technology
Carlos Martin
Executive Director - Risk Management & Compliance, JPMorgan
Michael Rasmussen
Analyst & Pundit, GRC 20/20 Research & GRC ReportCase Study
Zurich Insurance's GRC Journey with MetricStream
How to Successfully Implement a GRC Solution in Less Than a Year? What are the absolute golden rules to follow to move from manual tasks to state-of-the-art GRC technology? How can you continue the journey to become best in class? How do you establish trust within the golden triangle of IT, GRC vendor, and business? Join this session to get answers to these questions and more.

Fabien Robichon
Head of Compliance Analytics and Innovation, Zurich Insurance Group
Dino Placido Bivona
IT Business Partner - GRC Corporate Functions, Zurich Insurance GroupNetworking Lunch
Track 1
Track 2
Case Study
MetricStream – Operational Risk Module Implementation
A walkthrough of the IQ-EQ MetricStream implementation journey including lessons learned and the continued embedding of MetricStream across the Group.

Simon Wallis
Global Head of Risk & Assurance, IQ-EQ
Product Session
Begin Your Operational Resilience Journey with MetricStream
Begin Your Operational Resilience Journey with MetricStream guides organizations in building a strong foundation for resilience in the face of disruptions. This session will showcase how MetricStream’s solutions empower businesses to identify, assess, and mitigate risks while ensuring business continuity. Attendees will learn how to integrate resilience strategies into their operations, enhance crisis management capabilities, and drive proactive risk management. Discover how MetricStream’s approach enables organizations to thrive in an unpredictable and complex risk landscape.
Expert Talk
Integrating Value into GRC – A Fresh Perspective
In today’s rapidly evolving business landscape, Governance, Risk Management, and Compliance (GRC) systems are often perceived as cumbersome, abstract, and disconnected from the core purpose of creating and preserving value. This session will challenge conventional approaches to GRC and present innovative, thought-provoking ideas to transform these systems into dynamic, value-driven frameworks that resonate with organizations and their people. Join this session to explore how we can make GRC exciting, impactful, and integral to the future of risk management.

Nam Phong Ho
Founder, Board Member and Strategic Advisor, Alpha Flow Zenith
Product Session
What's New in MetricStream's Operational Risk and Enterprise Risk Management
Discover the latest innovations in MetricStream’s Operational Risk and Enterprise Risk Management solutions. This session will spotlight new features that enhance risk visibility, streamline risk assessments, and elevate control testing efficiency. Learn how AI-driven insights, integrated issue management, and intuitive dashboards empower risk teams to act faster and smarter. Whether you're modernizing risk frameworks or strengthening resilience, explore how MetricStream is driving the next generation of risk management excellence across the enterprise.
Break
Panel
Driving Operational Efficiency and Business Growth through Collaborative Internal Audits
In today’s dynamic business landscape, internal audits are no longer just a compliance exercise—they are a strategic tool for driving operational efficiency and growth. This session explores how organizations can foster collaboration between audit, risk, and business teams to enhance transparency, identify opportunities, and streamline processes. Learn best practices for leveraging technology, data insights, and cross-functional partnerships to transform audits into a value-driven function that strengthens resilience and accelerates business success.

Nick Woods
Chief Auditor - Risk, Credit, Financial Crime, NatWest Group
Claudia Iacobucci
Head of Assurance, Risk and Internal Controls, ABB
Product Session
Level Up Your Compliance Posture with MetricStream’s All-New Compliance Management
Level Up with MetricStream’s All-New Compliance Management showcases the latest features designed to enhance compliance processes and drive greater efficiency. This session will explore how MetricStream’s advanced solutions streamline compliance tracking, automate workflows, and provide real-time visibility into regulatory requirements. Attendees will learn how to leverage these new capabilities to improve accuracy, reduce manual effort, and ensure proactive compliance. Discover how MetricStream’s innovative tools help organizations stay ahead of evolving regulations while mitigating compliance risks.
Closing Keynote
Drinks & Reception