Send us Fan Mail

In this episode, Michael Rasmussen, a leading expert in governance, risk, and compliance, shares insights into the origins of GRC, its ongoing evolution, and its critical role in managing complex third-party ecosystems amid rapid technological change. Discover how organizations can stay ahead of regulatory pressures and operational risks through innovative frameworks and proactive dependency mapping.
Key Topics Covered:

  • How Michael Rasmussen pioneered the GRC concept with the first market models in February 2002
  • The seven generations of GRC, from Sarbanes Oxley-driven GRC 1.0 to GRC 7.0 focusing on orchestration and AI
  • The importance of treating risk as an appetite for value, not risk itself
  • Why periodic risk assessments are insufficient in dynamic environments and the need for continuous intelligence
  • Bridging the gap between technical threat detection and business risk perspective
  • The risks associated with opaque AI supply chains and shadow tech, and how to govern them proactively
  • Critical dependencies in third-party ecosystems and how to map and manage them effectively
  • Practical steps organizations can take today, such as dependency mapping and defining systemically critical vendors
  • The role of organizational culture and personal routines in staying informed and resilient

Timestamps:

  • 00:00 - Introduction to Michael Rasmussen and his GRC background
  • 02:45 - The origin story: How the GRC acronym was created in 2002
  • 05:00 - The seven generations of GRC: From reactive to orchestrated AI-driven frameworks
  • 09:00 - Common industry misconceptions and what should be retired in risk management
  • 11:12 - How personal experiences and career pivots shaped Rasmussen’s expertise
  • 15:13 - The future of vendor risk ecosystems and the dangers of shadow tech
  • 17:24 - Governing non-transparent AI supply chains ahead of regulation
  • 19:49 - Bridging the gap: Connecting technical threat intelligence with operational risk
  • 22:13 - The importance of contextual analysis over simple scoring in third-party risk
  • 24:32 - Risk management lessons from Star Trek and risk appetite misconceptions
  • 27:27 - Practical advice: Building dependency maps for critical business services
  • 29:09 - Final thoughts on identifying systemically critical vendors and ensuring resilience
  • Want me to turn this into a LinkedIn post next?

Support the show

Podden och tillhörande omslagsbild på den här sidan tillhör Gregory Rasner . Innehållet i podden är skapat av Gregory Rasner och inte av, eller tillsammans med, Poddtoppen.