← All briefings

Control-First GRC: Part 3 — Quantitative Risk, Continuous Resilience, and Governed Automation (2019–Today)

54aac838-9094-4de5-ac24-993672505cbc

About the Control-First GRC Series

Governance, risk, and compliance systems did not emerge as unified control platforms. They developed in stages: first as documentation practices, then as workflow systems, then as cloud evidence collectors, and now as increasingly automated decision environments.

Each stage improved speed, reach, or visibility. Each also introduced new forms of fragility.

This series examines the evolution of GRC through the control failures that defined each era. Its focus is not which platform offered the most features, but which technical and governance properties were required to make evidence trustworthy, decisions reviewable, and institutional accountability durable.

Executive Summary: Modern governance operates under shorter reporting timelines, wider technology dependencies, operational-resilience requirements, and growing use of generative AI. Point-in-time questionnaires and color-coded dashboards remain useful summaries, but they cannot independently establish evidence integrity, materiality, control effectiveness, or decision provenance. The current era requires GRC systems that preserve traceable evidence, support quantified analysis without false precision, and govern automated assistance through bounded authority and human accountability.

I. Exposure Vector

Consider an illustrative board-reporting cycle.

A dashboard shows several risks as red, amber, or green. The supporting narratives were written during the previous quarter. Since then:

  • a potentially material cybersecurity incident has been identified;
  • business leaders are determining its likely impact;
  • an AI assistant has drafted a remediation summary;
  • evidence has arrived from several external systems;
  • and the board packet is approaching its publication deadline.

The dashboard provides a visual state. It does not automatically answer:

  • What evidence supports the rating?
  • When was that evidence collected?
  • Has its integrity been preserved?
  • Which assumptions produced the financial estimate?
  • Who determined materiality?
  • What language was generated by a machine?
  • Who reviewed and approved the final disclosure?
  • Can the organization reproduce the decision process later?

Several regulatory developments make those questions increasingly important.

The SEC’s cybersecurity-disclosure rules require covered registrants to disclose material cybersecurity incidents on Form 8-K generally within four business days after determining that an incident is material, subject to limited national-security or public-safety delay procedures. The deadline runs from the materiality determination, not necessarily from the moment the incident first occurs. [1]

The EU Digital Operational Resilience Act entered into application on January 17, 2025. It establishes requirements for in-scope financial entities involving ICT risk management, incident handling and reporting, resilience testing, and ICT third-party risk. It is not a universal law for all organizations or all jurisdictions. [2]

NIST’s Generative AI Profile identifies risks specific to or intensified by generative AI and proposes risk-management actions as a companion to the voluntary AI Risk Management Framework. [3][4]

The institutional problem is therefore no longer only whether controls have been documented. It is whether evidence, calculations, machine assistance, and approval decisions remain traceable under time pressure.

II. Quantitative Context

Intercontinental Exchange enforcement action

In 2024, the SEC announced that Intercontinental Exchange agreed to pay a $10 million civil penalty to settle charges that it caused nine wholly owned subsidiaries to fail to timely notify the Commission of a cyber intrusion as required by Regulation Systems Compliance and Integrity.

This action should be described precisely. It was not a penalty under the SEC’s public-company Form 8-K cybersecurity-disclosure rule. It involved notification obligations under Regulation SCI applicable to covered market entities. [5]

Economic signalPublic amountWhat it demonstrates
ICE civil penalty$10,000,000Potential consequences of failing to meet applicable cyber-incident notification obligations

A single enforcement amount is not a universal estimate of cybersecurity exposure. It does, however, demonstrate that notification governance can carry direct financial consequences.

Quantification without false precision

A modern risk register may express exposure in monetary terms, but a dollar amount does not become reliable merely because it is stored precisely.

A defensible quantitative record should distinguish among:

  • observed losses;
  • estimated frequency;
  • estimated impact;
  • confidence ranges;
  • model assumptions;
  • scenario boundaries;
  • data sources;
  • and accountable reviewers.

Exact storage prevents computational rounding drift. It does not eliminate uncertainty.

III. What Modern GRC Must Enforce

Evidence governance

Modern failure modeControl-system requirement
Screenshot or export detached from its sourceRecord source, collection time, scope, integrity data, and review history
New evidence overwrites the previous stateMaintain versioned or append-only history
Board packet cannot be reproducedRetain the evidence set, calculations, narrative version, and approvals used for publication
Disclosure timeline tracked informallyRecord incident milestones, materiality determination, accountable decision-makers, and applicable deadline

Quantitative-risk governance

Modern failure modeControl-system requirement
Color rating presented without analytical basisLink the rating to evidence, methodology, assumptions, and owner
Single dollar value presented as certaintySupport ranges, scenarios, confidence, and sensitivity
Approximate binary floating-point arithmeticUse exact decimal types or integer minor units for recorded currency
Recalculation silently changes prior reportsVersion models, inputs, assumptions, and outputs

AI governance

An AI assistant should not be treated as an accountable control owner or final approver.

The system should instead record and retain enough information to reconstruct its contribution:

  • the model or service used;
  • model or deployment version when available;
  • versioned instructions or prompt templates;
  • retrieved or supplied source material;
  • relevant configuration settings;
  • generated output;
  • subsequent human edits;
  • reviewer identity;
  • approval decision;
  • and the action ultimately taken.

Identical output across repeated AI runs should not be promised unless the underlying system can actually guarantee it.

AI-assisted failureControl-system requirement
Generated text cannot be traced to its sourcesRecord source references and generation context
Prompt or policy changes without historyVersion instructions, policies, and templates
Assistant acts beyond approved authorityEnforce bounded permissions and explicit action limits
Generated conclusion is treated as attestationRequire named human review and approval
Model output silently changes a governed recordRecord proposed and accepted changes separately
Sensitive information is sent to an unapproved serviceApply data classification, minimization, provider approval, and access controls

Architectural checklist

  • Validate and authorize external data before it affects governed workspace state
  • Preserve evidence lineage from collection through publication
  • Record incident and materiality-decision milestones separately
  • Store currency using exact decimal representations or integer minor units
  • Preserve uncertainty, assumptions, ranges, and model versions alongside estimates
  • Version AI instructions and retain relevant generation records
  • Restrict automated systems to explicitly authorized actions
  • Require human approval for attestations, formal findings, material disclosures, and external publication
  • Make published reports reproducible from retained evidence, calculations, narratives, and approvals

IV. Verification Protocol

  1. Confirm that the SEC’s Form 8-K deadline generally begins after a registrant determines that a cybersecurity incident is material.
  2. Do not describe the rule as requiring public disclosure within four business days of every intrusion.
  3. Confirm that the ICE action concerned Regulation SCI notification obligations rather than the public-company Form 8-K rule.
  4. Confirm that DORA applies to in-scope EU financial entities and relevant ICT third-party arrangements; do not present it as a blanket global requirement.
  5. Confirm that NIST AI RMF materials are voluntary guidance unless another authority has incorporated them into a binding obligation.
  6. Test whether evidence, risk calculations, AI contributions, human edits, and approval decisions can be reconstructed after publication.
  7. Reject any claim of “autonomous compliance” unless the organization has defined the system’s authority, failure behavior, oversight, accountability, and auditability.

Key Takeaways

  • Continuous governance requires evidence whose scope, provenance, integrity, and approval history remain reconstructable under time pressure.
  • Quantitative risk depends on transparent assumptions, ranges, and accountable review—not only exact arithmetic.
  • AI can accelerate governance work, but it cannot replace accountable human judgment, attestation, or approval.

V. Sources & Citations

  • [1] U.S. Securities and Exchange Commission, Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure (July 26, 2023) https://www.sec.gov/newsroom/press-releases/2023-139 Announces rules requiring disclosure of material cybersecurity incidents and periodic cybersecurity-risk-management information.

  • [2] European Insurance and Occupational Pensions Authority, Digital Operational Resilience Act https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en States that DORA entered into application on January 17, 2025 and applies to financial entities’ ability to withstand, respond to, and recover from ICT disruptions.

  • [3] National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework https://www.nist.gov/itl/ai-risk-management-framework Provides voluntary risk-management guidance for organizations designing, developing, deploying, or using AI systems.

  • [4] National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1 (July 2024) https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf Identifies risks specific to or intensified by generative AI and proposes corresponding risk-management actions.

  • [5] U.S. Securities and Exchange Commission, SEC Charges Intercontinental Exchange and Nine Affiliates with Failing to Inform the Commission of Cyber Intrusion (2024) https://www.sec.gov/newsroom/press-releases/2024-63 Records ICE’s $10 million settlement concerning charges that it caused nine wholly owned subsidiaries to fail to provide timely notification under Regulation SCI.