Why GRC Must Move From Periodic Reviews To Continuous Governance

Direct Source Verification: This story is aggregated from Forbes (forbes.com). Full reporting rights and copyright belong to the primary publisher.
It begins with greater visibility into key risks and the link between controls and tangible evidence of effectiveness, so the right people can act when things change.​

Ramachander Rao Thallada is a Governance, Risk, and Compliance (GRC) Executive for Manulife, a modern North American financial institution.

gettyFor a long time, GRC processes have relied heavily on regular evaluations. Policies are set, control assessments are conducted after a specified period, documentation of these assessments is maintained, and corrective actions are implemented to address identified gaps.

Based on my experience with large-scale technology projects and complex enterprise settings, a disconnect is growing between the pace of technological advancement and the regularity of governance evaluations. Cloud computing solutions, automated data flows, connected applications and intelligent systems can advance constantly. A control that worked well during the evaluation period may operate in a completely different environment a few months later.

Periodic assessments show risk status at a single point in time. One of the main problems is that technology tends to change between assessments, so a static view of risk status is not possible.

Imagine an environment where applications exchange data via hundreds of data flows. New data sources can be added, permissions can change, transformations can change, and dependencies between systems can change. While each change may seem insignificant, together they affect the organization’s risk status.

In my experience, the problem usually doesn’t arise from a lack of policies, but from maintaining visibility into whether those expectations continue to be met as the technical context changes. Mature organizations tend to have many policies, standards and approval processes; the key difficulty is keeping an eye on whether those expectations remain relevant to the prevailing situation.

When governance groups discover issues through subsequent assessments or audits, the assessment will necessarily be retrospective. By then, an incorrect setup, quality issue or access control issue could have persisted for weeks or months. Governance must be an ongoing process.

Continuous governance is not about daily audits or about automating all GRC decisions. Instead, it involves building systems that continuously provide evidence that key systems and controls are working as expected. This includes automation of monitoring, exception alerts, access control verification, data quality measures, log files, dependencies and dashboards to provide visibility into critical processes. However, the goal is not just to gather more data but to identify a change in risk level early enough for appropriate human action.

In fact, one may use continuous monitoring instead of waiting for a quarterly audit to discover improper access permissions. Similarly, instead of identifying a data quality problem after a managerial report emerges, one may introduce validation when generating or transforming data.

This change also appears in research on governance in technologically complex settings. Vasudevan Ananthakrishnan examines governance issues in large-scale data integration in his 2026 research titled “Governance Frameworks for Large-Scale ETL Ecosystems in Complex Data Environments.” The research addresses the practical issue that becomes increasingly important for organizations as they grow—maintaining visibility into data lineage, transformation, quality, accessibility and dependencies across many data pipelines.

The governance framework proposed in this research combines centralized metadata management, pipeline monitoring, data quality management and access policies rather than separating them.

For GRC professionals, this research matters not for ETL technology per se, but for the governance concept it represents. The ability of organizations to track the source of data, the transformation of data, permissions to access data and exceptions in real time transforms governance from something performed after the fact into something intrinsic to the environment in which the activity takes place. This becomes particularly relevant for GRC professionals because their ability to monitor risks depends on having the right policy and showing that it works.

In pursuit of continuous governance, it’s common to automate everything. In my opinion, however, this approach is wrong.

Indeed, automation works very well for repeated actions—configuration monitoring, evidence gathering, threshold validation and exception detection. But you can’t dispense with the human factor when analyzing exceptions and understanding the business context.

The goal should therefore be automated visibility combined with human accountability.

Based on my experience, companies embarking on continuous governance must focus on four areas. First, identify the key controls. All controls require continuous monitoring. Companies need to focus on areas that pose significant operational, security, regulatory or data risks in the event of failure.

The second is to align governance with operational data. Leaders can link the GRC process to access logs, configuration modifications, data quality metrics and system alerts. This gives governance staff up-to-date information on control effectiveness and any issues that may arise before the next review.

Thirdly, automate strategically. While automation can help reduce repetitive activities, the escalation and decision processes must be well defined. Organizations can automate regular tasks such as evidence collection and exception identification while establishing clear escalation procedures and decision accountability. Lastly, assign responsibility.

Periodic evaluations and audits will continue to exist, since these processes provide structured and independent oversight that continuous governance alone can never consistently provide. However, they increasingly need to be part of a larger governance framework.

With the increased use of cloud-based services, AI capabilities, automation and data platforms, the time gap between technological change and its potential effects has narrowed. GRC frameworks must be able to see through it.

The future of governance is therefore not about eliminating periodic governance reviews. It is about closing the gaps between them. Companies that know how to track their systems, spot changes and abnormalities and tie them to the people responsible for decision-making will be able to control risks without compromising innovation.

The broader takeaway for leaders is that continuous governance doesn’t mean rebuilding the GRC process from scratch. It begins with greater visibility into key risks and the link between controls and tangible evidence of effectiveness, so the right people can act when things change.

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Original Source
https://www.forbes.com/councils/forbestechcouncil/2026/09/18/why-grc-must-move-from-periodic-reviews-to-continuous-governance/
Visit Forbes ↗
SHARE STORY:
𝕏 f in

Related Coverage in Environment