The Hitchhiker’s Guide to the GRC Technology Galaxy

hggrcgalaxy

Welcome, interstellar travelers, to the Hitchhiker’s Guide to the GRC Technology Galaxy, your improbable companion through the expanding universe of governance, risk, and compliance. In a cosmos where regulations multiply faster than Tribbles, cyber incidents drop like falling whales, and third parties sprout surprises with Vogon-level timing, this podcast is your towel, your Babel Fish, and your improbability drive rolled into one. Each episode, Michael Rasmussen and guests explore the constellation of GRC technology, from digital twins and AI copilots to compliance nebulae and audit wormholes. We chart the domains, decode the jargon, and help you survive vendor poetry that promises everything and delivers nothing. Whether you’re a compliance officer, risk manager, or just someone trying to make sense of improbable business realities, this guide offers clarity, humor, and a reminder of the most important rule of all, don’t panic. End of transmission. Prepare for the next hyperspace jump.

  1. Sep 10

    The Improbable Evolution of GRC: IBM OpenPages in the GRC Galaxy

    In this episode of The Hitchhiker’s Guide to the GRC Technology Galaxy, Michael Rasmussen sits down with Ian Francis, Principal Product Manager at IBM, for a journey through the past, present, and increasingly strange future of GRC technology. The conversation starts with OpenPages and its acquisition by IBM, then follows the platform through the same waves of change that have reshaped the wider GRC market. Michael frames that history through the evolution from GRC 1.0 onward, while Ian offers the view from inside a platform that has had to continually adapt as expectations around risk, technology, usability, and scale have changed. Then AI arrives and makes the galaxy considerably more interesting. Michael and Ian discuss how AI is changing not only what GRC technology can do, but how software itself is designed and developed. That leads into the consequences of vibe coding, questions about architecture, and what happens when the speed of building technology begins to outpace some of the traditional disciplines behind building it well. They also explore digital twins and what they could mean for the next generation of risk technology, before turning back to OpenPages itself. Ian explains where he believes the platform stands out today, how IBM has evolved it beyond its traditional large-enterprise reputation, and why OpenPages is increasingly designed to work for mid-market organizations as well. IBM currently positions OpenPages as a modular platform that can scale across organizations while allowing them to deploy the capabilities they need. The episode closes by setting the coordinates for 2030. What will a GRC platform look like four years from now? How much of it will be driven by AI? What happens to architecture, interfaces, and the way humans interact with risk information? And how much of what we currently call a GRC platform will still be recognizable? After several generations of GRC technology, the destination is still being written. The interesting question is whether 2030 brings another version of the same platform or something we would barely recognize today.

  2. Aug 27

    From Case Closed to Crisis Avoided: Case IQ in the GRC Galaxy

    In this episode of The Hitchhiker’s Guide to the GRC Technology Galaxy, Michael Rasmussen sits down with David McNeill, CEO of Case IQ, and Matt Kuo, Chief Product Officer, to trace how a company with deep roots in investigations and case management has evolved into something much broader. They start with the history of Case IQ, where it came from, and how the platform has expanded across the compliance landscape. Today, that means everything from whistleblowing and investigations to compliance monitoring, approvals and disclosures, and third-party risk. The thread connecting it all is a shift from simply dealing with problems after they appear to finding them earlier, understanding them better, and preventing them from becoming something considerably worse. Case IQ itself describes this as an end-to-end approach spanning detection, prevention, investigation, and remediation. Michael, David, and Matt dig into what makes Case IQ stand out in the market and why customers choose it, but the conversation goes beyond technology. They talk about the depth of Case IQ’s client relationships and the role partnership plays in making compliance technology actually work once the implementation team has gone home and the real world takes over. That leads into a broader discussion about what good compliance should accomplish. Efficiency matters, but so does effectiveness. Does the program actually reduce compliance risk? Can it spot an issue early enough to keep it from becoming a crisis? Can it adapt when regulations, risks, or circumstances change? The conversation looks at Case IQ through those lenses of effectiveness, resilience, and agility, including how connected information can turn lessons from yesterday’s investigation into better prevention tomorrow. Finally, they turn to AI and where Case IQ is today with Clairia, its purpose-built AI assistant for investigations, before looking at what comes next. Clairia already works within case context to help investigators assemble timelines, surface missing information, work with policies, and reduce manual effort, while Case IQ is building more structure around how organizations govern and tailor that assistance. The episode closes with a trip to 2030 and a question worthy of the Guide. In a compliance universe where the next problem rarely has the courtesy to announce itself in advance, how much better can organizations become at seeing it coming?

  3. Aug 13

    A Guide Out of the Compliance Labyrinth: MCO in the GRC Galaxy

    In this episode of The Hitchhiker’s Guide to the GRC Technology Galaxy, Michael Rasmussen sits down with Brian Fahey, CEO of MyComplianceOffice, to trace MCO’s journey and explore what it actually means to build an integrated compliance platform in financial services. It is a particularly useful question because compliance itself has not exactly evolved according to a master plan. Michael compares the modern compliance function to the Winchester Mystery House, endlessly expanded over the years until you end up with staircases leading nowhere, doors opening into walls, and processes whose original purpose has long since been forgotten. Financial services firms have accumulated regulations, systems, controls, data, and responsibilities in much the same way. MCO’s answer has been to bring those pieces together into what the conversation describes as a single compliance operations center. Michael and Brian unpack what integration means beyond simply putting several products under the same logo, what makes MCO different at its core, and how a connected approach can give compliance teams a clearer view across employees, transactions, third parties, obligations, and the other moving parts of a modern program. That leads to another idea running through the episode, captured in a quote Michael recalls, though with some uncertainty over whether to credit E.F. Schumacher or Einstein: “Any intelligent fool can make things bigger, more complex, and more violent. It takes a touch of genius — and a lot of courage to move in the opposite direction.” The point for GRC is less mysterious. Adding complexity is easy. Making complexity comprehensible is considerably harder. The conversation also turns to AI, how MCO is approaching it, and where it can meaningfully improve compliance without simply adding another layer of technology to an already crowded architecture. From there, Michael and Brian look ahead to 2030 and consider how MCO itself may evolve as both technology and financial-services compliance continue to change. They finish on perhaps the most important connection of all. Regulatory confidence and business confidence are not separate destinations. Done well, compliance should provide both, giving regulators confidence that obligations are being met and the business confidence to move forward knowing that its risks are understood and under control.

  4. Jul 30

    Everything Is Connected: LogicGate in the GRC Galaxy

    In this episode of The Hitchhiker's Guide to the GRC Technology Galaxy, Michael Rasmussen sits down with the team from LogicGate to explore how one of the GRC market's leading platforms grew from a simple idea that still shapes it today. Governance, risk, and compliance work better when everything is connected. The conversation traces LogicGate's journey from its origins to becoming one of the industry's leading enterprise GRC platforms, unpacking the architectural decisions that shaped its evolution, including why relationships between risks, controls, people, assets, and processes matter just as much as the individual data points themselves. Michael and the LogicGate team discuss who their customers are, where they come from, and why organizations choose LogicGate over spreadsheets, legacy platforms, or homegrown solutions. They also explore the remarkable culture the company has built, how that culture has been intentionally cultivated as the business has grown, and why clients often experience that culture long before they experience the technology. The discussion then returns to the platform itself, covering the breadth of use cases LogicGate supports, some of the most demanding customer implementations, and how flexibility has become one of its defining characteristics. Finally, they look toward 2030 and discuss how LogicGate sees both the platform and the broader GRC market evolving as organizations demand more connected, intelligent, and adaptive approaches to governance. In a galaxy where every risk seems connected to five others, and usually through the one thing you weren't looking at, this episode argues that understanding the connections may be more valuable than collecting more data.

  5. Jul 16

    So Long, and Thanks for All the Paperwork: RegScale in the GRC Galaxy

    In this episode of The Hitchhiker's Guide to the GRC Technology Galaxy, Michael Rasmussen sits down with Eric Erston, Chief Revenue Officer of RegScale, to discuss what happens when you stop treating compliance as a paperwork exercise and start treating it as a living system. The conversation begins with the story of RegScale and how it started, how it has evolved over the years, and why it chose a fundamentally different path from much of the GRC market. Instead of periodic assessments, endless evidence collection, and audit preparation that feels like starting over every year, RegScale was built around continuous controls monitoring, compliance as code, and automation from the ground up. Michael and Eric explore the kinds of organizations that gravitate toward RegScale, the use cases where it excels, and what differentiates it in an increasingly crowded market. They discuss practical lessons learned from helping organizations modernize compliance programs, including the shift from manual effort to continuous assurance, and why automation should remove work rather than simply move it somewhere else. The discussion also turns to one of RegScale's most demanding customers (not by name, but by the extraordinary scale and complexity of the challenges they solve) and how that relationship continues to push the platform beyond what its creators originally imagined. Finally, they look toward 2030 and consider where continuous compliance, AI, and machine-readable governance are heading as organizations demand greater speed, stronger assurance, and less administrative burden. In a galaxy where bureaucracy has somehow become a business process, RegScale is betting on a future where compliance happens continuously and paperwork becomes little more than an interesting historical artifact.

  6. Jun 4

    Beyond the AI Hype Cycle: Complyance in the GRC Galaxy

    In this episode of The Hitchhiker’s Guide to the GRC Technology Galaxy, Michael Rasmussen sits down with Richa Kaul, founder and CEO of Complyance, for a conversation about one of the most crowded buzzword fields in the modern GRC universe: AI. The discussion begins with the story of Complyance, how it emerged, and what has helped it stand out in an increasingly competitive market. From there, Michael and Richa dive headfirst into the growing gap between AI marketing and AI reality. Every platform seems to have an AI strategy. Every vendor claims to have agentic AI. But what does that actually mean, and more importantly, what is it actually doing? Together they explore the difference between AI as a feature, AI as a marketing term, and AI as a genuine system of action that performs work on behalf of GRC teams. The conversation focuses on practical outcomes rather than promises, including how Complyance applies AI to third-party risk management, internal controls, evidence collection, questionnaire responses, and continuous monitoring. Along the way, Richa shares the questions organizations should be asking when evaluating AI-powered GRC solutions, how to distinguish meaningful capabilities from demonstrations and prototypes, and why the future belongs to platforms that can combine intelligence with action. The discussion closes with a look toward 2030 and how both Complyance and the broader GRC market may evolve as AI becomes more deeply embedded in governance, risk, and compliance programs.

  7. May 28

    The Restaurant at the End of the GRC Universe

    In this episode of The Hitchhiker’s Guide to the GRC Technology Galaxy, field researcher and intergalactic GRC hitchhiker Michael Rasmussen is joined by Graeme Keith and Stefan Gershater for a conversation that is slightly unusual for the series because there is no technology vendor in sight. Instead, it’s two deeply experienced risk practitioners looking at the GRC technology market from the outside and asking a fairly uncomfortable question: Has the industry become so distracted by AI that it never properly solved the basics in the first place? The discussion explores a GRC landscape crowded with platforms, overlapping promises, and increasingly indistinguishable products. Graeme and Stefan argue that many vendors are still wrestling with foundational architectural problems while simultaneously racing to attach AI to everything in sight. Along the way, they compare the current AI wave to The Restaurant at the End of the Universe and ask whether AI will ultimately destroy the GRC technology galaxy or accelerate it. The consensus is more grounded than apocalyptic. AI is an amplifier. If your approach to risk and governance is fundamentally sound, AI may accelerate value. If your processes are broken, AI simply helps you fail faster. The conversation also dives into quantitative risk, uncertainty, machine learning, decision-making, and why so many organizations still struggle to distinguish useful technology from what Michael jokingly compares to the Wizard of Oz, where much of the magic disappears once someone pulls back the curtain. They close with practical advice for organizations trying to navigate an overcrowded and noisy market, including how to think critically about vendors, architecture, AI claims, and what truly differentiates good GRC technology from polished demos and marketing theater.

  8. May 22

    The Practical Improbability of Value: CoreStream in the GRC Galaxy

    In this episode of The Hitchhiker’s Guide to the GRC Technology Galaxy, Michael Rasmussen sits down with Richard Eddolls, co-founder and Platform Director of CoreStream, for a conversation about what happens when a GRC platform is built around one deceptively difficult idea—delivering real value. Richard shares the origins of CoreStream, how the company evolved from its early beginnings, and how its core DNA has stayed remarkably consistent over the years. Simplicity, flexibility, and measurable outcomes remain central to the way CoreStream approaches GRC, even as the market itself has become larger, noisier, and increasingly crowded with overlapping promises. The discussion explores why CoreStream focuses so heavily on outcomes rather than features, how configurability became one of the company’s defining strengths, and why organizations ranging from highly regulated enterprises to complex global manufacturers have gravitated toward the platform. Michael also shares a story about a major European manufacturer whose RFP process ultimately revealed something larger than a list of requirements. CoreStream stood out not just for meeting the brief, but for helping the organization think differently about where value could actually be created. Along the way, they unpack the breadth of use cases CoreStream supports, the philosophy behind its no-code approach, and how its partnership with Sannos fits into the company’s evolving AI strategy. Rather than chasing hype, the focus remains on practical applications that improve efficiency, decision-making, and organizational effectiveness. The episode closes with a look toward 2030 and what CoreStream may become as GRC continues to evolve from a compliance exercise into something more connected, adaptive, and operationally meaningful. In a galaxy full of dashboards, acronyms, and feature lists, this conversation keeps returning to a simpler question. Does the technology actually create value?

Ratings & Reviews

5
out of 5
3 Ratings

About

Welcome, interstellar travelers, to the Hitchhiker’s Guide to the GRC Technology Galaxy, your improbable companion through the expanding universe of governance, risk, and compliance. In a cosmos where regulations multiply faster than Tribbles, cyber incidents drop like falling whales, and third parties sprout surprises with Vogon-level timing, this podcast is your towel, your Babel Fish, and your improbability drive rolled into one. Each episode, Michael Rasmussen and guests explore the constellation of GRC technology, from digital twins and AI copilots to compliance nebulae and audit wormholes. We chart the domains, decode the jargon, and help you survive vendor poetry that promises everything and delivers nothing. Whether you’re a compliance officer, risk manager, or just someone trying to make sense of improbable business realities, this guide offers clarity, humor, and a reminder of the most important rule of all, don’t panic. End of transmission. Prepare for the next hyperspace jump.

You Might Also Like