Hello Hello,

Before we move into AI use cases for Risk Management, I want to take a quick step back.

Over the last few posts, we have laid the foundation:

  • I introduced the GRC Automation Maturity Model, a practical way to understand where a GRC team sits today and what more mature AI-enabled operations can look like.

  • I applied that thinking to the Policy Management workstream, from policy gap analysis to the GRC Policy Reviewer Agent.

  • Now we are moving into Risk Management.

A three-step journey from the GRC Automation Maturity Model through Policy Management to the GRC AI Operating Framework.

Before we list use cases, there is one thing worth getting clear: a useful AI workflow is not just a good prompt. It is not even just a capable tool.

You start by defining the operating environment the AI will work in.

THE ONE THING TO TAKE AWAY

Context + Connections → Capabilities → Cadence

Context tells the AI how your GRC work is done. Connections give it access to the right information. Together, they determine what the AI can actually do. Cadence decides when the workflow runs and where its output goes.

The GRC AI Operating Framework showing Context and Connections flowing into Capabilities, then Cadence.

This is the framework I use to think about building anything in ChatGPT, Claude, or another enterprise AI environment.

1. CONTEXT: WHAT THE AI NEEDS TO KNOW

Context is the knowledge layer. It tells an AI tool how work is done in your organisation: your processes, standards, definitions, and decision-making language.

For a Risk Management workflow, that context could include:

  • Your risk-management procedure and methodology.

  • Your risk taxonomy and risk-appetite statement.

  • The template used for risk committee papers.

  • Examples of strong risk narratives.

  • The thresholds for escalation and the roles involved in approval.

For Policy Management, it could be your policy-writing standard, document template, control framework, and review procedure.

A useful test: if a new GRC analyst joined tomorrow, what would they need to read to understand how this work is done properly? That is where you begin building the context.

2. CONNECTIONS: WHERE THE AI GETS THE WORK AND EVIDENCE

Connections are the approved integrations that let the AI access information beyond the chat window. This is where a workflow starts to become useful in day-to-day work.

Depending on the workflow, that may mean connecting to:

  • SharePoint for policies, procedures, evidence packs, and assessment documentation.

  • Confluence for process guidance, control narratives, operating notes, and team knowledge.

  • Airtable for structured risk, action, control, audit, or issue registers.

  • Atlassian or Rovo for remediation tickets, project activity, and connected knowledge sources.

  • Your GRC platform for the approved system of record for risks, controls, audits, issues, or third parties.

The question is not, “What can I connect?” It is, “Which sources does this workflow need to do a useful job?”

Before you connect a source, be clear on four things:

  • Is this the source of truth for the task?

  • Does the workflow need live information, static reference material, or both?

  • Is the connection read-only, or can it write back into a business system?

  • What information should remain out of scope?

3. CAPABILITIES: WHAT CONTEXT AND CONNECTIONS MAKE POSSIBLE

This is the part people normally start with. I think it should come third.

Capabilities are the useful jobs an AI workflow can perform once it has the right context and connections.

For most teams, start narrow and practical:

  • Find the right policy, procedure, evidence, or record.

  • Bring together approved information from several sources into one working view.

  • Draft a first version of a risk narrative, control review, or committee update.

  • Prepare the next step, such as questions for the owner or a proposed remediation action.

With only a prompt, you might brainstorm a risk statement. With the right methodology, reporting template, risk register, and supporting evidence, you can build something far more useful.

A useful capability is not “analyse risks.” It is “use the agreed methodology and available evidence to prepare a first draft for the risk owner to review.”

The more a capability moves towards taking action in a system of record, the more deliberate the design needs to be.

4. CADENCE: WHEN THE WORKFLOW RUNS

Cadence is the operational rhythm. It defines when the AI should run, what triggers it, and where the output should be sent.

There are three simple ways a workflow can run:

  • On demand: a risk manager runs the workflow before preparing a paper for the risk committee.

  • Event-triggered: a new high-priority issue or completed assessment triggers a request for an initial GRC summary.

  • Scheduled: every Monday morning, the workflow sends the GRC owner a draft digest of overdue risk actions and material updates.

Cadence is not only about automation. It is also about the hand-off:

  • Who receives the output?

  • Is it a draft, a notification, a request for missing information, or a report?

  • What happens if the information is incomplete or the output does not look right?

A four-step process flow: define context, connect sources, configure capability, and set cadence.

The sequence matters. You do not begin by asking an AI tool to solve a broad GRC problem. You give it the context to understand the work, connect it to approved sources, configure one useful capability, and decide when that capability should run.

IN PRACTICE: A WEEKLY RISK MANAGEMENT WORKFLOW

Imagine you want to build a weekly risk-management assistant.

  • Context: the risk procedure, risk-appetite statement, escalation criteria, committee-reporting template, and examples of the language your organisation uses.

  • Connections: approved Airtable risk and action registers, SharePoint evidence folders, Confluence process guidance, and relevant Atlassian remediation tickets.

  • Capabilities: retrieve risks that changed during the week, identify overdue actions, pull related evidence, and create a first draft of the weekly risk summary.

  • Cadence: every Monday morning, send the named GRC owner a draft for review before anything is shared more widely.

That is a workflow. Not just a prompt.

ONE IMPORTANT POINT BEFORE YOU BUILD

The four parts sit within the governance boundaries your organisation already has.

Use approved AI tools. Connect only data that the right people are authorised to access. Keep the human reviewer close to the output, especially where it could shape a risk, control, compliance, or business decision.

The aim is not to give an AI tool unlimited access and hope it becomes useful. The aim is to give it the right context, the right connections, a narrow job, and a clear rhythm of work.

Context without connections is a well-briefed assistant with no visibility of live work. Connections without context are access without understanding. Capability is what happens when the two come together. Cadence is what makes it operational.

That is the lens I will use as we move into AI use cases for Risk Management.

Until next time,

Princess David Okoro, CISM
Author, The AI GRC Desk

Find me on LinkedIn: Princess David Okoro