Control-First GRC: Part 3 — Quantitative Risk, Continuous Resilience, and Governed Automation (2019–Today)
54aac838-9094-4de5-ac24-993672505cbc
About the Control-First GRC Series
Governance, risk, and compliance systems did not emerge as unified control platforms. They developed in stages: first as documentation practices, then as workflow systems, then as cloud evidence collectors, and now as increasingly automated decision environments.
Each stage improved speed, reach, or visibility. Each also introduced new forms of fragility.
This series examines the evolution of GRC through the control failures that defined each era. Its focus is not which platform offered the most features, but which technical and governance properties were required to make evidence trustworthy, decisions reviewable, and institutional accountability durable.
Executive Summary: Modern governance operates under shorter reporting timelines, wider technology dependencies, operational-resilience requirements, and growing use of generative AI. Point-in-time questionnaires and color-coded dashboards remain useful summaries, but they cannot independently establish evidence integrity, materiality, control effectiveness, or decision provenance. The current era requires GRC systems that preserve traceable evidence, support quantified analysis without false precision, and govern automated assistance through bounded authority and human accountability.
I. Exposure Vector
Consider an illustrative board-reporting cycle.
A dashboard shows several risks as red, amber, or green. The supporting narratives were written during the previous quarter. Since then:
- a potentially material cybersecurity incident has been identified;
- business leaders are determining its likely impact;
- an AI assistant has drafted a remediation summary;
- evidence has arrived from several external systems;
- and the board packet is approaching its publication deadline.
The dashboard provides a visual state. It does not automatically answer:
- What evidence supports the rating?
- When was that evidence collected?
- Has its integrity been preserved?
- Which assumptions produced the financial estimate?
- Who determined materiality?
- What language was generated by a machine?
- Who reviewed and approved the final disclosure?
- Can the organization reproduce the decision process later?
Several regulatory developments make those questions increasingly important.
The SEC’s cybersecurity-disclosure rules require covered registrants to disclose material cybersecurity incidents on Form 8-K generally within four business days after determining that an incident is material, subject to limited national-security or public-safety delay procedures. The deadline runs from the materiality determination, not necessarily from the moment the incident first occurs. [1]
The EU Digital Operational Resilience Act entered into application on January 17, 2025. It establishes requirements for in-scope financial entities involving ICT risk management, incident handling and reporting, resilience testing, and ICT third-party risk. It is not a universal law for all organizations or all jurisdictions. [2]
NIST’s Generative AI Profile identifies risks specific to or intensified by generative AI and proposes risk-management actions as a companion to the voluntary AI Risk Management Framework. [3][4]
The institutional problem is therefore no longer only whether controls have been documented. It is whether evidence, calculations, machine assistance, and approval decisions remain traceable under time pressure.
II. Quantitative Context
Intercontinental Exchange enforcement action
In 2024, the SEC announced that Intercontinental Exchange agreed to pay a $10 million civil penalty to settle charges that it caused nine wholly owned subsidiaries to fail to timely notify the Commission of a cyber intrusion as required by Regulation Systems Compliance and Integrity.
This action should be described precisely. It was not a penalty under the SEC’s public-company Form 8-K cybersecurity-disclosure rule. It involved notification obligations under Regulation SCI applicable to covered market entities. [5]
| Economic signal | Public amount | What it demonstrates |
|---|---|---|
| ICE civil penalty | $10,000,000 | Potential consequences of failing to meet applicable cyber-incident notification obligations |
A single enforcement amount is not a universal estimate of cybersecurity exposure. It does, however, demonstrate that notification governance can carry direct financial consequences.
Quantification without false precision
A modern risk register may express exposure in monetary terms, but a dollar amount does not become reliable merely because it is stored precisely.
A defensible quantitative record should distinguish among:
- observed losses;
- estimated frequency;
- estimated impact;
- confidence ranges;
- model assumptions;
- scenario boundaries;
- data sources;
- and accountable reviewers.
Exact storage prevents computational rounding drift. It does not eliminate uncertainty.
III. What Modern GRC Must Enforce
Evidence governance
| Modern failure mode | Control-system requirement |
|---|---|
| Screenshot or export detached from its source | Record source, collection time, scope, integrity data, and review history |
| New evidence overwrites the previous state | Maintain versioned or append-only history |
| Board packet cannot be reproduced | Retain the evidence set, calculations, narrative version, and approvals used for publication |
| Disclosure timeline tracked informally | Record incident milestones, materiality determination, accountable decision-makers, and applicable deadline |
Quantitative-risk governance
| Modern failure mode | Control-system requirement |
|---|---|
| Color rating presented without analytical basis | Link the rating to evidence, methodology, assumptions, and owner |
| Single dollar value presented as certainty | Support ranges, scenarios, confidence, and sensitivity |
| Approximate binary floating-point arithmetic | Use exact decimal types or integer minor units for recorded currency |
| Recalculation silently changes prior reports | Version models, inputs, assumptions, and outputs |
AI governance
An AI assistant should not be treated as an accountable control owner or final approver.
The system should instead record and retain enough information to reconstruct its contribution:
- the model or service used;
- model or deployment version when available;
- versioned instructions or prompt templates;
- retrieved or supplied source material;
- relevant configuration settings;
- generated output;
- subsequent human edits;
- reviewer identity;
- approval decision;
- and the action ultimately taken.
Identical output across repeated AI runs should not be promised unless the underlying system can actually guarantee it.
| AI-assisted failure | Control-system requirement |
|---|---|
| Generated text cannot be traced to its sources | Record source references and generation context |
| Prompt or policy changes without history | Version instructions, policies, and templates |
| Assistant acts beyond approved authority | Enforce bounded permissions and explicit action limits |
| Generated conclusion is treated as attestation | Require named human review and approval |
| Model output silently changes a governed record | Record proposed and accepted changes separately |
| Sensitive information is sent to an unapproved service | Apply data classification, minimization, provider approval, and access controls |
Architectural checklist
- Validate and authorize external data before it affects governed workspace state
- Preserve evidence lineage from collection through publication
- Record incident and materiality-decision milestones separately
- Store currency using exact decimal representations or integer minor units
- Preserve uncertainty, assumptions, ranges, and model versions alongside estimates
- Version AI instructions and retain relevant generation records
- Restrict automated systems to explicitly authorized actions
- Require human approval for attestations, formal findings, material disclosures, and external publication
- Make published reports reproducible from retained evidence, calculations, narratives, and approvals
IV. Verification Protocol
- Confirm that the SEC’s Form 8-K deadline generally begins after a registrant determines that a cybersecurity incident is material.
- Do not describe the rule as requiring public disclosure within four business days of every intrusion.
- Confirm that the ICE action concerned Regulation SCI notification obligations rather than the public-company Form 8-K rule.
- Confirm that DORA applies to in-scope EU financial entities and relevant ICT third-party arrangements; do not present it as a blanket global requirement.
- Confirm that NIST AI RMF materials are voluntary guidance unless another authority has incorporated them into a binding obligation.
- Test whether evidence, risk calculations, AI contributions, human edits, and approval decisions can be reconstructed after publication.
- Reject any claim of “autonomous compliance” unless the organization has defined the system’s authority, failure behavior, oversight, accountability, and auditability.
Key Takeaways
- Continuous governance requires evidence whose scope, provenance, integrity, and approval history remain reconstructable under time pressure.
- Quantitative risk depends on transparent assumptions, ranges, and accountable review—not only exact arithmetic.
- AI can accelerate governance work, but it cannot replace accountable human judgment, attestation, or approval.
V. Sources & Citations
-
[1] U.S. Securities and Exchange Commission, Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure (July 26, 2023) https://www.sec.gov/newsroom/press-releases/2023-139 Announces rules requiring disclosure of material cybersecurity incidents and periodic cybersecurity-risk-management information.
-
[2] European Insurance and Occupational Pensions Authority, Digital Operational Resilience Act https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en States that DORA entered into application on January 17, 2025 and applies to financial entities’ ability to withstand, respond to, and recover from ICT disruptions.
-
[3] National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework https://www.nist.gov/itl/ai-risk-management-framework Provides voluntary risk-management guidance for organizations designing, developing, deploying, or using AI systems.
-
[4] National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1 (July 2024) https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf Identifies risks specific to or intensified by generative AI and proposes corresponding risk-management actions.
-
[5] U.S. Securities and Exchange Commission, SEC Charges Intercontinental Exchange and Nine Affiliates with Failing to Inform the Commission of Cyber Intrusion (2024) https://www.sec.gov/newsroom/press-releases/2024-63 Records ICE’s $10 million settlement concerning charges that it caused nine wholly owned subsidiaries to fail to provide timely notification under Regulation SCI.