Back Issues This Week → Calendar → Current Issue → Popular →

All issuesVolume 328, Issue 5IT NewsCompliance

How To Integrate AI Into A GRC Strategy

SC Media, Thursday, July 31st, 2025

A Fortune 500 financial services firm discovers their AI-enhanced governance, risk, and compliance (GRC) platform has been quietly sending sensitive control documentation to an external LLM for over six months.

A Fortune 500 financial services firm discovers their AI-enhanced governance, risk, and compliance (GRC) platform has been quietly sending sensitive control documentation to an external LLM for over six months.

The discovery comes only when the company fails a routine SOC 2 audit requirement for data localization. It triggers a compliance nightmare, transforming their 'clean' compliance posture into a material weakness requiring disclosure along with the prospect of notifying every client whose security questionnaires and audit evidence had been exposed to unapproved third-party processing.

more →  ·  More from Compliance →