Knowledge BaseRisk Map Operating Model Templates Services About Start an Engagement
PivotRisk

Knowledge Base

Practitioner writing on the decisions, structures, and blind spots that separate governance programs that perform from ones that just produce documents.

Customer Trust & Third-Party Risk

The Compliance Decisions We Made Before Writing a Line of Code

Isolation, deletion and minimization are schema decisions wearing compliance costumes, which is why retrofitting them costs a year. Five constraints we fixed while our platform was still a drawing, published where you can check them.

Customer Trust & Third-Party Risk

The Trust Page Written Entirely in Future Tense

Committed to. Pursuing. Embedded in everything we do. No dates, no scope, nothing you could ask for. Here is PivotRisk's own program in present tense, including the parts that are unimpressive.

Customer Trust & Third-Party Risk

You Are Somebody Else's Third Party

A customer sent us a reassessment that was, section for section, the questionnaire we sent our own vendors. They had moved us up a tier and nobody on our side knew. Every complaint you have about vendors, your customers are making about you.

Enterprise Risk

Sources and Methods: The Tradecraft GRC Never Adopted

In 1951 an intelligence estimate said "serious possibility" and readers took it to mean anywhere from one chance in five to four. High is our serious possibility, and the discipline that fixed this published the standard decades ago.

Operational Resilience

Duty of Care Starts With Knowing Where People Are

Something happens in a city and someone senior asks whether we have anyone there. The data exists in five systems that never join, so the roll call gets assembled in a group chat by whoever is awake.

Operational Resilience

The Location Decision Is Made Before Anyone Asks About Risk

The lease had been signed five weeks when someone asked for the continuity plan. The new site was forty minutes from the old one: same grid, same storm track, a second location that bought almost no independence.

Operating Models

Your Exception Register Is Your Real Policy

An auditor asked for the active exceptions to one policy. It took two weeks to assemble, a third had no end date, and several had been granted by people who no longer worked there. That list, not the intranet, described the control environment.

Operating Models

The Issues Log Is Where Findings Go to Age

The examiner sorted the log by age and noted that the oldest open finding predated the program that raised it. Detection gets the budget; remediation gets a column called Status, and Status is a word people type.

Customer Trust & Third-Party Risk

The Promises in Your Security Questionnaire Are Controls Now

Ninety minutes into an incident, nobody on the bridge could say how long we had to notify customers. The commitments were binding, signed, and scattered across contract exhibits no control owner had ever read.

AI & Automation

The AI in Your Stack That Nobody Bought

A vendor assessed two years ago shipped an AI assistant mid-contract, on by default, with a new model provider on the subprocessor list. No purchase, no review, and an assessment that now describes a product that no longer exists.

Operational Resilience

The Annual DR Test Expires the Day You Pass It

A point-in-time test certifies the system as it was that day, and it starts drifting the moment the test ends. Borrow what SRE already solved: validate recovery continuously, as a property you watch, not an event you pass.

Operational Resilience

You're Scoring the Questionnaire, Not the Vendor

A new processor scored a 94 at intake, then breached eleven months later through a subprocessor nobody weighted. The score measured how well the vendor filled out forms, not the risk it carried.

Enterprise Risk

Risk Intelligence You Cannot Audit Is Just an Opinion With a Logo

An auditor asked why a country was rated 3. Nobody could say. A rating you cannot reconstruct is a rating you cannot defend, and by the third handoff, the caveats have fallen off entirely.

Operational Resilience

The Map Is the Missing Control: GIS in Risk and Resilience

Eleven "geographically separated" recovery pairs, all inside the same twelve-mile radius, and the register was correct the whole time. Text doesn't compare; only a coordinate does.

Enterprise Risk

Operational Risk Event Management: The Basel Taxonomy as Your Evidence Layer

A loss event is the only data in your program that isn't a guess, it's what actually happened. Capture it against the Basel event types and it drives likelihood, sets an impact floor in currency, and tests the control that failed.

AI & Automation

AI Governance Is a Risk Register, Not a Committee

Most AI governance starts as a monthly meeting to govern a population nobody counted. The program that works is an inventory, a defensible score, a cadence earned by risk, and a policy people can follow.

Operating Models

GRC Is a Knowledge Management Discipline in Denial

Runbooks, policies, and audit evidence are all knowledge, captured, versioned, decaying. Programs have writers everywhere and librarians nowhere, and an audit is just a retrieval exam you keep cramming for.

Operational Resilience

Your RTO and Your SLA Have Never Met

The RTO is an internal promise from a BIA workshop; the SLA is an external promise from a deal negotiation. Same system, different authors, and one inequality decides whether you can keep both.

Operating Models

The Good Idea Fairy Writes Your Policies

Every aspirational "shall" in a policy is a future audit finding, auditors grade you against your own promises before any framework. The exorcism: no commitment ships without a control, an owner, and evidence.

Operational Resilience

Your BIA Is a Shelf Document

Most BIAs are produced to be had, not used. The working version is a scoring model with three jobs: rank the processes, derive the recovery objectives, and expose the gap between what you've promised and what you can prove.

Operational Resilience

How to Run a Tabletop That Isn't Theater

Bad tabletops are worse than none, they convert untested assumptions into documented assurance. The real exercise turns on uncomfortable injects, forced decisions, and findings that become owned actions.

Operational Resilience

The Vendor Behind Your Vendor: Fourth-Party Risk and Concentration

Every vendor list conceals a second list, and it concentrates. Your diversified vendor portfolio may be a monoculture one layer down. Map the chain behind what's critical and decide about it out loud.

Operational Resilience

Vendor Reassessment Cadence Should Be Earned, Not Calendared

Annual-for-everyone fails in both directions: too slow for the vendors that can take you down, pure waste on the long tail. Let the risk score set the clock, and let events reset it.

Operating Models

A Control That Isn't Tested Is a Hope

Attestation culture lets a rating become its own evidence. Testing replaces the question with a demand (show me) and lets failed tests move the residual numbers the day they fail.

Operating Models

Regulatory Change Is an Operating-Model Problem

Awareness with nowhere to go is how two-year runways evaporate. The chain that works: scan with ownership, disposition on a clock, decompose into rows, map against the control library, track the gaps.

Enterprise Risk

Your Risk Appetite Statement Is a Slogan Until It Has Thresholds

An appetite statement with no number in it cannot be violated. The chain that makes it real: appetite to tolerance to KRI threshold to a response someone is accountable for.

AI & Automation

AI Agents for GRC: What Actually Works (and What's Just a Chatbot)

Most "AI for GRC" is a chatbot on a policy library. A real GRC agent needs a connected data model and a deterministic engine underneath, so the numbers are auditable.

AI & Automation

From Spreadsheet to Agent: Making Your Risk Data Computable

An agent can only operate a program whose data is computable, structured, linked, rule-driven. That's the real prerequisite for everything AI will do in GRC.

Operating Models

The Connected GRC Model: How Risks, Controls, Issues & Incidents Fit Together

Most programs run four disconnected registers. Connect them and your risk numbers stop being opinions: incidents drive likelihood, controls drive residual, issues degrade controls.

Enterprise Risk

How to Build a Risk Register That Calculates Residual Risk

A step-by-step guide to a register that derives residual risk from control effectiveness (instead of guessing it twice) and produces board-ready output.

Enterprise Risk

The Data-Driven Risk Assessment

Most risk assessments are opinion surveys in a spreadsheet. The data-driven version ties every score to evidence, and produces a decision instead of a heat map.

Enterprise Risk

Integrating Risk Assessments: One Assessment, Many Consumers

Most organizations run the same assessment five times for five audiences. Integration means assessing once, on a shared taxonomy and scale, so the answers finally add up.

Operational Resilience

Incident Command Is the Backbone of Operational Resilience

You can have flawless recovery plans and still fail in the first 30 minutes. Incident command is the structure that turns all your preparation into a coordinated response.

Operating Models

The Frameworks Worth Your Time: OCEG, the UCF, and the SCF

A practitioner's take on three frameworks that actually earn their keep, and how to use them as accelerants without becoming framework-first.

Operational Resilience

Making the Pivot to an SRE-Driven Organization

When engineering runs on SLOs and error budgets, traditional GRC collides with it. Here's how risk and resilience leaders pivot to work in their language, not against it.

Operating Models

The GRC Operating Model Is the Program

You can have the best control library in the industry and still underperform. The framework tells you what to do. The operating model determines whether it actually gets done.

Operating Models

The Case for a Unified Control Library (And How to Build One)

Managing compliance across multiple frameworks separately compounds into an operational problem over time. Here's the faster path to a single source of truth.

Operational Resilience

Operational Resilience Is an Ownership Problem, Not a Framework Problem

Every major resilience framework says roughly the same thing. Most programs still fall apart in a real incident. The frameworks aren't the problem. The ownership is.

Operational Resilience

DORA Is Not an IT Problem

DORA got handed to IT at most organizations and treated as an ICT compliance project. That's a misread of what the regulation actually requires, and it's creating gaps that will surface under scrutiny.

Enterprise Risk

Building an ERM Program From Scratch Without It Becoming a Checkbox Exercise

Leading with a framework almost guarantees you'll build something that looks like a compliance program instead of a risk management program. Those are very different things.

Enterprise Risk

Board Risk Reporting That Actually Drives Decisions

Most board risk reports are written to inform. The best ones are written to decide. That distinction sounds subtle. The operational difference is significant.

Customer Trust

Customer Trust Is a Revenue Function

Security teams have been saying security is a business enabler for years. The ones where it's true built a Customer Trust function and treated it like a sales asset, not a compliance output.

AI & Automation

AI in GRC: What's Actually Useful Right Now

There's a lot of noise about AI transforming governance and compliance. Most of it is vendor marketing. Here's what I've actually found useful, and where the hype is running ahead of reality.

New articles every week.

Practical GRC intelligence, no fluff, no vendor pitches.