Making AI Work for GRC

The Key Foundations for Success

 

“AI can and will transform GRC, but only for those who lay the groundwork.”

 

About the Author

Lee Childs

Lee Childs

Lee Childs is the Center of Excellence lead for Risk & Compliance at Wrangu and is a certified ServiceNow IRM specialist.
He leverages over 25 years of experience in the IT industry, with extensive knowledge ranging from architectural roles to Pre Sales management, to guide clients on their Governance, Risk, and Compliance (GRC) journey. His role involves helping organisations understand and solve their business challenges using ServiceNow solutions.


Yes, AI is here. Yes, it promises to transform the governance, risk, and compliance (GRC) landscape. But let’s face it, are you truly ready to harness its power?

Throughout my career, I’ve worked with organisations of all shapes and sizes, from multinational giants to agile start-ups. Yet few were truly prepared for AI to solve their challenges. Why? Because they lacked the foundations needed for AI to deliver meaningful results.

Many have purchased AI tools. But have they solved their problems? No. AI cannot work in isolation.

 

The Real Potential of AI in GRC

Used effectively, AI can streamline core GRC processes that have traditionally been time-consuming and manual:

  • Accelerating analysis: Reading, classifying, and summarising large volumes of documentation in minutes, freeing teams from repetitive review work.
  • Improving efficiency: Generating concise, context-rich summaries that enable faster, more informed handovers between functions.
  • Driving consistency: Identifying language patterns across controls and policies to reduce duplication.

When guided by a clear strategy, AI can be a game-changer for GRC.

But to reach that point, organisations first need to establish the right foundations.


Foundation 1 Know What You’re Solving For

It isn’t that they cannot find the solution. It is that they cannot see the problem.” – G.K Chesterton

Before implementing AI, organisations must first understand the problems they are trying to solve. What outcomes are you pursuing, and why?

Buying a tool because you think it will solve your problems will only add to them. There must be tangible business cases warranting the investment.

 

Foundation 2 Data Readiness

Next, and most critically, you need data that is reliable, consistent, and usable to train AI models effectively. AI is a powerful tool, but it is not a silver bullet. As Grady Booch wisely said, “A fool with a tool is still a fool.”

In my experience, organisations tend to fall into one of these categories:

  • Too siloed and fragmented, burdened by disparate processes and years of unaligned data.
  • Moving from spreadsheets with ambition but no foundational systems or long-term vision.
  • Stuck on outdated tools, eager for modernisation but trapped by archaic processes.

Or, often, a mix of all three.

Data is the foundation on which the AI house is built, it must be strong, or it will collapse. Preparing the ground and understanding the data you have is important before you start.

 

Foundation 3 A Shared, Long-Term Vision

Successful AI adoption requires vision, communication, and cooperation.

Like all major GRC projects, this is not a one-and-done effort. Sponsors must recognise that managing risk, like maintaining security, is continuous. It demands investment in organisational change management, cultural transformation, and a unified vision with interconnected processes driving a common goal:

To mitigate uncertainty and empower the business to thrive.

Whether you follow the three lines of defence, four, or five, it doesn’t matter. What matters is that processes are structured, embedded, and adopted.

Just as data analytics required a clear purpose before creating measurable impact, AI needs a defined vision before it can deliver value.

 

Foundation 4 Governance, Structure, and Accountability

AI algorithms are only as effective as the data and governance behind them. Quality, ethics, and robustness are vital for trustworthy outcomes. Frameworks such as the EU AI Act, the OECD AI Principles, and the NIST AI Risk Management Framework all highlight this importance.

Organisations need:

  • Data and AI governance – Clear accountabilities and standardised processes for data management.
  • Transparency and explainability – AI decisions must be understandable and auditable.
  • Fairness, safety, and accountability – Systems must be designed to avoid bias, prevent harm, and ensure responsibility.
  • Leadership and vision – Strong oversight to align AI initiatives with organisational strategy.
  • Training and iteration – Ongoing refinement to improve accuracy and relevance.
  • Collaboration and skills – The ability to work effectively with AI, including prompt design and critical evaluation of outputs.

Those of us in the GRC field bear a special responsibility. Governance and ethical guardrails are essential to realising AI’s potential while protecting the integrity of our organisations and the data we manage.

As Jason Lemkin aptly put it, “AI agents are incredibly powerful, but they cannot be trusted, and that is by design. If you want to use AI agents, you need to 100% understand what data they can touch, because they will touch it, and you cannot predict what they will do with it.”

AI can and will transform GRC, but only for those who lay the groundwork, building the systems, culture, and data foundation that allow the technology to shine.