Join us for the ISACA Chicago Chapter Virtual Meeting - July 2026
Topic: From Manual to Meaningful: Intelligence-Driven Decision Enablement Across the GRC Lifecycle
_______________________________________________________________
Artificial intelligence is changing how GRC teams manage risk and create value, but many organizations still view AI in two narrow ways: as a tool to automate manual work or as a technology risk owned by IT and cybersecurity. In practice, AI affects business decisions, delegated actions, data use, third-party exposure, policy compliance, and stakeholder impact across the enterprise.
This session will examine how AI can be used across the GRC lifecycle to turn manual activities into actionable intelligence. Discussion topics may include AI governance, regulatory analysis, risk assessments, control evaluation, evidence collection, third-party risk, executive reporting, and value-based risk prioritization. Attendees will consider how AI can improve consistency, reduce cognitive burden, and strengthen the link between GRC activity and business outcomes.
The session will also address the governance of AI behavior, especially as agentic AI begins to act within business processes, influence decisions, and operate with greater autonomy. Just as organizations monitor human activity for policy violations, privacy concerns, legal exposure, ethical issues, and harmful business outcomes, they need practical approaches for understanding and governing how AI systems behave, what decisions they shape, who they affect, and where accountability belongs.
Participants will leave with practical use cases, implementation considerations, and a value-centric lens for evolving GRC programs from manual compliance work toward intelligence-driven decision enablement and measurable business value.
-
Identify practical opportunities to apply AI across the GRC lifecycle to improve efficiency, consistency, and analytical insight.
-
Explain why AI governance extends beyond IT and cybersecurity to include AI behavior, decision influence, privacy, legal, ethical, and stakeholder impacts.
-
Recognize how emerging AI governance expectations can inform practical risk management, impact assessment, transparency, and control evaluation.
-
Apply value-centric and quantitative risk approaches to translate GRC intelligence into prioritization, resource allocation, and business decisions.
_______________________________________________________________
Gavin Grounds, CEO and Co‑Founder of Mercury Risk and Compliance, brings extensive experience from Meta, Verizon, and other global enterprises, where he led large‑scale cybersecurity and risk programs. His work centers on modernizing risk quantification and automating controls testing—areas rapidly transforming how organizations measure and manage cyber and regulatory exposure.
Grace Beason, Director of Governance, Risk and Compliance at Guidewire Software and Co‑Founder/COO of Mercury Risk and Compliance, has experience guiding global GRC operations across technology, financial services, healthcare, and public sector environments. She has led enterprise compliance and security programs for organizations operating in 70+ countries and has been recognized for excellence in GRC program leadership and compliance automation.
_______________________________________________________________
CPE: Two credits will be earned by participating in this webinar.
Note: ISACA members are requested to register with the same email ID as that in their ISACA profile for direct CPE uploads.
_______________________________________________________________
Co-founder and CEO | Mercury Risk and Compliance, Inc.
_______________________________________________________________
Co-founder and COO | Mercury Risk and Compliance, Inc.