The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Security & GRC Decoded
Security & GRC Decoded artwork

What Does ‘Technical’ Even Mean in GRC? ft Alan Luk @ Grammarly

Security & GRC Decoded · 2025-06-12 · 1h 10m

0:00--:--

Topics in this episode

Risk managementcompliancegrcSecurity ComplianceContinuous Assurance

Episode notes

Is it time to stop pretending GRC is technical? Alan Luk makes the case for a new kind of compliance leader - and it might surprise you. In this sharp and unfiltered episode of Security & GRC Decoded , Alan Luk , Director of GRC at Grammarly (and former Microsoft and PwC leader), joins Raj to dismantle common myths about GRC - and why even your engineers might be thinking about it all wrong. Drawing from over 20 years of experience, Alan makes the case for why GRC should be seen as a program management function , not a technical one - and how that shift unlocks better controls, less friction with engineering, and less painful audits. From audit war stories to his vision for continuous assurance, Alan brings blunt honesty, practical insight, and some well-earned hot takes to the mic.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • The Financial Stakes of Risk Management in a Self-Insured CaptiveThe Canary Report: Safety & Risk Management · on Risk management77 / 100
  • Corporate Finance Explained | Interest Rate Risk ManagementFinPod · on Risk management75 / 100
  • From Demo to Production- Building Enterprise AI Agents That Actually Work with Microsoft Copilot Studio with Elliot Margot [MVP]M365.FM · on compliance
  • How Jamie Dimon Built a Fortress Balance Sheet at JPMorganThe CEO Diary with Fexingo · on Risk management

More from Security & GRC Decoded

All episodes →
  • The Evolution of Modern GRC ft. James Huang, Head of GRC @ Gong86 / 100
  • The Trust Gap in AI: Why Agents Need a New Certification Model ft Rajiv Dattani & David Meyer @ AIUC76 / 100
  • Beyond Checkbox Compliance: Why GRC Must Become an Engineering Discipline ft Sheron Chakalakal, Head of GRC @ UiPath88 / 100
  • From Compliance Theater to GRC Infrastructure: Why AI Breaks Traditional GRC ft Jasmine Kaur, Principal of Security & Assurance Engineering @ CoreWeave96 / 100
  • The GRC Illusion: Why Third-Party Risk Is Still Broken ft Val Dobrushkin, Director of GRC @ Tricentis86 / 100
Explore the best B2B Ops podcasts →
All Security & GRC Decoded episodes →