Why GRC now demands real investment and expertise
Security governance, risk and compliance has moved from an annual exercise to a continuous one, and the bar for what counts as evidence has risen with it.
AI is already in use across most mid-market organisations, often through tools nobody formally approved. The question that follows is not a technical one. It is who decides what is allowed, on what evidence, and who answers for it.
In this session, Phil Allas, GRC Consultant at Tecala, looks at why security governance, risk and compliance has become harder, more expensive and more scrutinised, and what happens to that picture once AI adoption is added on top.
The discussion moves from the current state of GRC in the Australian market to the specific gaps AI exposes, and the practical actions leaders can take before the next audit, insurance renewal or board question.
Security GRC used to be an annual exercise. It is now continuous. Client security questionnaires, cyber insurance renewals, privacy reform, supplier due diligence and board reporting each arrive on their own schedule, and each one asks for evidence rather than intent. Mid-market organisations are carrying obligations designed for much larger businesses, usually without a dedicated risk function to carry them.
AI lands on top of that. Copilot, embedded assistants and business-led tools are already in use, and the common response is to write an AI policy. A policy only holds if what sits underneath it exists: known data, agreed ownership, and controls someone can evidence. This session starts one level down, at the GRC foundations, then shows what AI actually changes and what it does not.
Security governance, risk and compliance has moved from an annual exercise to a continuous one, and the bar for what counts as evidence has risen with it.
The current state of security GRC in Australia: what organisations are being asked to prove, and where the available offerings leave them short.
The specific gaps AI creates, from tools nobody approved to data exposure and unclear accountability for decisions.
How to frame AI risk so it can be ranked and acted on rather than listed, what to do first, and audience questions.
Product Manager, Tecala
Andre will cover what changes once AI is in the environment, and which decisions and controls need to be in place before use expands across the business.
GRC Consultant, Tecala
Phil benchmarks mid-market security governance against recognised standards and turns the result into a prioritised set of actions leaders can take to their board.
Register for this 30-minute advisory webinar to see where governance should start, what AI adoption changes, and which actions to prioritise first.