Podcast: Play in new window | Download (Duration: 9:51 — 13.5MB)
Subscribe: RSS
Summary
Today Marc is chattin’ with Richa Kaul, founder and CEO of an AI-based compliance automation platform. The conversation centered on how AI is reshaping enterprise governance, risk, and compliance (GRC), especially by helping organizations handle growing complexity without simply adding more headcount. The discussion quickly focused on how compliance teams can use automation and AI to streamline vendor risk, regulatory requirements, and other time-consuming workflows. Richa explained that his approach starts by separating what truly requires human judgment from what can be automated.
A major theme was the mismatch between the speed of modern risk and the pace at which organizations can hire. Richa argued that risk is increasing faster than teams can scale, making it unrealistic to solve GRC challenges by just expanding staff. Instead, she framed the real question as what work should remain with humans and what work can be handled by AI or automation. She emphasized that teams are bogged down by urgent audit prep, repetitive tasks, and reactive “fire drills,” which prevents them from focusing on strategic risk reduction.
The chat then moved into visibility and granularity in risk management, particularly around privacy. Richa noted that many CISOs and GRC leaders lack sufficient visibility into their organization’s risks, especially because privacy is cross-functional and touches employees, users, operations, and regulatory obligations. She said this lack of clarity makes it difficult for leaders to confidently communicate risk to boards or determine where to invest time and resources. In her view, the biggest issue is not just managing risk, but being able to see it clearly enough to act on it.
Another key topic was AI governance. Richa pointed out that many companies are paying attention to AI policy at the top level, but are not doing enough to train employees at the operational level, where mistakes are most likely to happen. She described the “last mile” of AI governance as especially vulnerable, since employees may unknowingly expose proprietary information by entering sensitive data into tools like GPT. According to Richa, human behavior is often the weakest link, and effective governance requires education and training throughout the organization, not just policy statements from leadership.
Their chat also touched on industry-specific risk, with healthcare highlighted as a major area of concern. Richa said healthcare compliance appears underinvested compared with financial services, even though both are highly regulated and handle highly sensitive data. She closed by offering a practical starting point for companies facing generative AI challenges: map your most important data, follow it from input to output, identify the systems it touches, and secure each step of the journey. His overall message was optimistic — that even though the risk landscape feels overwhelming, organizations have tools, platforms, and partners that can help them manage it more effectively.
Key Points
- AI can reduce compliance burden by automating repetitive GRC tasks.
- Organizations can’t hire fast enough to keep up with rising risk and regulatory complexity.
- Many leaders lack clear visibility into privacy and cross-functional risk.
- AI governance fails most often at the employee level, not just the policy level.
- Healthcare compliance is highly exposed and may be underinvested relative to its risk.
Key Quotes
- “Risk right now is increasing at a speed and at a rate that teams cannot possibly hire to mitigate.”
- “It is not the question of, should teams get smaller. I think it’s a question of what work should humans be doing and what work can I do instead.”
- “A lot of CISOs tell me that they don’t have the visibility, or at least the granularity of visibility into their risks that they would like.”
- “Humans are the weakest link.”
- “Don’t you need to boil the ocean, but let’s look at what is your highest risk data.”
About Our Guest
Richa Kaul is a technology executive and Head of Product Engineering: Strategy, AI Builder, and Cloud & AI Enterprise Transformation, with 20+ years of experience leading cloud, data, and AI initiatives across Fortune 500 organizations. She has managed portfolios as large as $2B in revenue and $300M in operating budgets, while building global teams of 100+ and advising CxOs on enterprise AI and financial strategy. Richa is known for driving GenAI adoption, modernizing data platforms, advancing AI governance, and delivering scalable, cost-effective transformation across banking, capital markets, asset management, and wealth management.
Follow Our Guest
About Our Host
National co-chair of the Cyber Center for Excellence, Marc Schein, CIC,CLCS is also a Risk Management Consultant at Marsh McLennan Agency. He assists clients by customizing comprehensive commercial insurance programs that minimize the burden of financial loss through cost effective transfer of risk. By conducting a Total Cost of Risk (TCoR) assessment, he can determine any gaps in coverage. As part of an effective risk management insurance team, Marc collaborates with senior risk consultants, certified insurance counselors, and expert underwriters to examine the adequacy of existing client programs and develop customized solutions to transfer risk, improve coverage and minimize premiums.
Follow Our Host
