Categories
AI Today in 5

AI Today in 5: January 6, 2026, The TRAIGA Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the AI Today In 5. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

Top AI stories include:

  1. TRAIGA in Texas. (WRAL News)
  2. 2026 is a seminal year for AI and copyright. (Reuters)
  3. How AI will redefine GRC in 2026. (Governance-Intelligence)
  4. Health companies want clear, more consistent AI rules. (HealthCare IT News)
  5. What does the AI boom look like (to WSJ reporters)? (WSJ)

For more information on the use of AI in Compliance programs, my new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.

Categories
AI Today in 5

AI Today in 5: September 12, 2025, The AI for RCA Episode

Welcome to AI Today in 5, the newest edition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI, so start your day, sit back, enjoy a cup of morning coffee, and listen in to the AI Today In 5, all from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest related to AI.

Top AI stories:

For more information on the use of AI in Compliance programs, my new book, Upping Your Game. You can purchase a copy of the book on Amazon.com.

Categories
Innovation in Compliance

Innovation in Compliance: Navigating Cybersecurity Compliance: From Physical Audits to AI Frameworks with Lori Crooks

Innovation is present in many areas, and compliance professionals must not only be prepared for it but also actively embrace it. Join Tom Fox, the Voice of Compliance, as he visits with top innovative minds, thinkers, and creators in the award-winning Innovation in Compliance podcast. In this episode,  host Tom Fox visits with Lori Crooks, a seasoned professional in the field of cybersecurity and audit assessments, to discuss the evolution of auditing practices from physical infrastructure to cloud and AI.

Lori shares insights from her extensive career, highlighting key federal compliance frameworks like NIST 800-53, FedRAMP, and NIST 800-171. Lori stresses the importance of proactive compliance strategies and scalable GRC programs. As AI integration accelerates, she also addresses the challenges of adapting compliance frameworks to keep pace with technological advancements and the need to foster collaboration within organizations to effectively meet regulatory requirements.

Key highlights:

  • Federal Auditing Frameworks
  • Proactive Compliance Strategies
  • Scalable GRC Programs
  • AI and Compliance Landscape
  • Future of Auditing in the Age of AI

Resources:

Lori Crooks on LinkedIn

Cadra

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Check out my latest book, Upping Your Game-How Compliance and Risk Management Move to 2023 and Beyond, available from Amazon.com.

Innovation in Compliance was recently honored as the number 4 podcast in Risk Management by 1,000,000 Podcasts.

Categories
Innovation in Compliance

Innovation in Compliance – Gaurav Kapoor on Risk Management and the Role of AI in GRC

Innovation comes in many areas, and compliance professionals need to be ready for it and embrace it. Join Tom Fox, the Voice of Compliance, as he visits with top innovative minds, thinkers, and creators in the award-winning Innovation in Compliance podcast. In this episode, Tom Fox interviews Gaurav Kapoor, Vice Chairman, Co-Founder and Board Member of MetricStream, discussing his extensive professional background, from co-founding MetricStream to his current focus on customer intimacy amid AI market disruptions.

Kapoor delves into the evolving landscape of risk management, emphasizing the importance of midyear reviews and integration of various risk themes like operational risk, audit compliance, and cybersecurity. He elaborates on the role of AI in GRC, stating how generative and agent AI can streamline compliance processes and enhance risk management strategies. The conversation also touches on the increasing significance of cybersecurity, geopolitical instability, and climate impact on risk assessment. Kapoor highlights the shift from compliance to a more resilient and risk-aware culture within organizations.

Key highlights:

  • The Importance of July in Risk Management
  • AI’s Role in GRC
  • Emerging Risks and AI Applications
  • Counseling Boards on Risk Management
  • Top Concerns for the Second Half of 2025
  • Evolving Role of Compliance and Risk Officers

Resources:

MetricStream Website and on LinkedIn

Gaurav Kapoor on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Compliance and AI

Compliance and AI: Navigating Risk Management in the AI Era with Gaurav Kapoor

What is the role of Artificial Intelligence in compliance? What about Machine Learning? Are you using ChatGPT? These questions are just three of the many we will explore in this cutting-edge podcast series, Compliance and AI, hosted by Tom Fox, the award-winning Voice of Compliance. In this episode, Tom Fox speaks with Gaurav Kapoor, Vice Chairman, Co-Founder, and Board Member of MetricStream.

Kapoor shares his extensive professional background and the evolving landscape of risk management and compliance, emphasizing the growing importance of cybersecurity, geopolitical risks, climate impacts, and regulatory changes, all within the context of AI advancements. He also discusses how AI can streamline GRC processes, enhance decision-making capabilities, and transform traditional compliance frameworks into more strategic risk management approaches. The conversation also explores the evolving role of Chief Risk Officers and the need for a resilient, risk-aware corporate culture.

Key highlights:

  • Gaurav Kapoor’s Professional Journey
  • The Importance of July in Risk Management
  • AI’s Role in GRC
  • Emerging Risks and AI Applications
  • Counseling Boards on Risk Management
  • Top Concerns for the Rest of 2025
  • Shifting from Compliance to Risk Resilience

Resources:

MetricStream Website and on LinkedIn

Gaurav Kapoor on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
FCPA Compliance Report

#Risk New York Speaker Series – Exploring the Future of GRC with Michael Rasmussen

Join Tom Fox and hundreds of other GRC professionals in the city that never sleeps, New York City, on July 9 & 10 for one of the top conferences around, #Risk New York. The current US landscape, shaped by evolving policies, rapid advancements in AI, and shifting global dynamics, demands adaptive strategies and cross-functional collaboration.

At #RISK New York, you will master the New Regulatory Reality by getting ahead of US regulatory shifts and their impact. Conquer AI and Tech Risk by Safeguarding Your Organization in an AI-Driven World and Understanding the Implications of Major Tech Investments. Navigate Financial and Crypto Volatility by Protecting Your Assets and Exploring Solutions in a Dynamic Market. Strengthen Your GRC Framework by Leveraging Governance, Risk, and Compliance for Strategic Advantage. Protect Digital Trust by addressing challenges in cybersecurity and data privacy and combating misinformation. All while meeting with the country’s top #Risk management professionals.

In this episode, Tom Fox welcomes Michael Rasmussen, a renowned expert in Governance, Risk Management, and Compliance (GRC), often referred to as the ‘father of GRC.’ Michael shares insights into his contributions to the field, including his work with the SEG GRC Capability Model. The conversation highlights Michael’s anticipated presentation on ‘The Future of GRC’ at the upcoming risk conference in New York City. Drawing inspiration from Star Trek (TOS, and how can you not love that?), Michael emphasizes the importance of managing business risks effectively. The discussion also touches on the benefits of face-to-face interactions and networking opportunities at such conferences.

Resources:

#Risk Conference Series

#RiskNYC—Tickets and Information

Michael Rasmussen on LinkedIn

Categories
Innovation in Compliance

Innovation in Compliance: Paige Hanson and Brandon Woolf on Compliance as a Service and Affordable GRC Software for SMBs

Innovation comes in many forms, and compliance professionals need to not only be ready for it but also embrace it. Curious about Compliance as a Service and AI integration? Well, this episode is for you, as I have Paige Hanson and Brandon Woolf, co-founders of SecureLabs, discuss not only how AI technology can revolutionize compliance but also how the use of AI systems in Compliance as a Service is set to revolutionize the regulatory landscape.

Paige Hanson and Brandon Woolf are seasoned cybersecurity professionals. Hanson’s perspective, shaped by her role in developing a national training program for law enforcement and co-founding SecureLabs, emphasizes the importance of integrating security and compliance within organizations to foster a security-first culture and facilitate cross-departmental communication. She envisions a future where advanced AI systems enhance security environments and advocate for auditable processes for small to medium-sized enterprises.

Woolf, with his background in diverse cybersecurity roles, advocates for the integration of security and compliance within an organization. He highlights the importance of having a wide range of frameworks available to cater to the diverse needs of different industries and clients and sees a growing trend, especially for SMBs, in compliance as a service due to increasing security threats.

Key Highlights:

  • SecureLabs: Affordable GRC Software for SMB Compliance
  • Enhancing Organizational Culture Through Security Integration
  • Cybersecurity Compliance Benefits through Auditable Processes
  • Compliance Audits: Minimizing Fines Through Documentation
  • AI-driven Compliance Solutions for Enhanced Security

Resources:

Paige Hanson on LinkedIn 

Brandon Woolf on LinkedIn

securelabs.ai

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Innovation in Compliance

Innovation in Compliance – Matt Kunkel and Nick Kathmann on Dynamic GRC Systems with AI-driven Controls

Innovation comes in many forms, and compliance professionals must be ready for and embrace it. Today, I visited with Matt Kunkel, CEO of LogicGate, and Nick Kathmann, CISO at LogicGate, to consider how a dynamic GRC can help drive efficiency, compliance, and profitability.

With a background in business analysis and self-taught coding, Kunkel identified a need for a more comprehensive and user-friendly approach to governance, risk, and compliance (GRC) solutions, leading to the creation of Logic Gate. The platform was designed to meet businesses’ evolving needs without requiring constant developer intervention, utilizing a flexible data model and advanced graph database technology for superior efficiency.

Kathmann, with over 20 years of experience in security and compliance, stresses the importance of industry expertise in delivering effective solutions, focusing on ensuring the platform meets the highest security standards and adapts to changing business requirements seamlessly. Kunkel and Kathmann’s perspectives highlight the crucial role of innovative technology in simplifying GRC processes and addressing the complex regulatory, risk, and compliance needs of organizations.

Key Highlights:

  • Adaptive Logic Gate Platform for GRC
  • Harnessing Data for Strategic Compliance Oversight
  • Real-time Risk Optimization for Business Growth
  • Cyber Risk Alignment Between CISO and CEO
  • Executive Level Engagement for Cybersecurity Strategy
  • Tailoring Risk Communication to Stakeholder Priorities
  • Dynamic GRC Systems with AI-driven Controls

Resources:

Matt Kunkel on LinkedIn 

Nick Kathmann on LinkedIn 

LogicGate

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
FCPA Compliance Report

FCPA Compliance Report – Ryan Lougheed on Teamwork and Communication: Lessons from Esports and GRC

Welcome to the award-winning FCPA Compliance Report, the longest-running podcast in compliance. In this episode, Tom Fox welcomes Ryan Lougheed, Director, of Product Management at Onspring.

Ryan Lougheed has over twelve years of experience in the Governance, Risk, and Compliance (GRC) field, currently serving as the director of a platform at Onspring, a SaaS GRC platform and business process automation platform. Drawing from his background in esports, Lougheed believes that teamwork and communication are crucial in both the GRC space and the world of esports. He emphasizes the importance of effective and efficient communication, especially in high-stress situations, and believes that these skills can be carried over to a compliance-focused career.

In the context of esports, Lougheed explains that communication is vital in a team of five players and that professional esports organizations provide resources such as physical trainers and sports psychologists to support their players’ communication skills. He also notes that the esports industry is evolving, with larger companies creating brands around individual streamers and organizations acting as agents to help grow the streaming culture. Join Tom Fox and Ryan Lougheed on this episode of the FCPA Compliance Report podcast to delve deeper into the importance of teamwork and communication in GRC.

 Key Highlights

  • GRC Collaboration and Communication
  • Streamlining compliance with Onspring’s centralized platform
  • Streamlining Communication in High-Stress Compliance Situations
  • Leveraging Esports Skills for GRC Success

Resources

Ryan Lougheed on LinkedIn

Onspring

Tom Fox

Instagram

Facebook

YouTube

Twitter

Categories
Innovation in Compliance

Third-Party Management: A risk-based approach – Part 4: Adam Bailey on Reporting

Welcome to a special 5-part podcast series sponsored by Diligent. Over this series, we will consider a risk-based approach to third-party risk management. Over this series, I will visit with Michael Parker, the Director of Advisory and Consulting Services; Stephanie Font, Director of the Optimizations Group; Kairi Isse, Managed Services Group Manager; Adam Bailey, Senior Vice President, Product Management and Alexander Cotoia, from the Volkov Law Group. In this Part 4, I visit with Adam Bailey to look at the role of the Board in risk, audit, compliance, and ESG and the reporting from executive teams and GRC practitioners to take risks and seize chances.

Bailey has worked to help organizations better manage their risk by providing insight and clarity to boards of directors. He strived to enable executive teams and GRC practitioners to assess and manage strategic risks, ultimately connecting boards, practitioners, and executives together to innovate and drive growth. With the complexity of third-party relationships continuing to grow, companies need to adopt a continuous improvement approach to contend with unforeseen risks. A corporate compliance function is not just something nice to have, but a must and a Board needs clear and relevant data to make the best decisions. Organizations need to use the necessary tools to ensure that Boards have the visibility to manage their third parties and make informed decisions.


Key Highlights

1. A compliance function must support leaders through its reporting work.
2. Companies can effectively manage third-party risk with a risk-based approach and robust processes.
3. Connecting Board, senior executives, and practitioners together to enable organizations to take risks and innovate is critical.

Notable Quotes

  1. “The key to this effective risk management is truly the follow-up, the ongoing follow-up to ensure that all the controls are in place and, if needed, are changed.”
  2. “Continuous blanket monitoring of all third parties with every risk asset you can think of is just not feasible and probably wouldn’t deliver the outcomes that we need.”
  3. “We know that change is constant, regulators are looking for risk management policies and practices which continually improve and evolve over time.”
  4. “We need robust processes and systems in place to make sure that when you create your third-party profile, it’s screened against sanctions lists, embargo watch lists, et cetera, to provide the rich data that’s there.”

Resources

Adam Bailey on LinkedIn

Check out Diligent’s 3rd party products and services here.