Michael Rasmussen
GRC Analyst & Pundit, GRC 20/20 Research
Michael Rasmussen
Michael Rasmussen is an internationally recognized pundit on governance, risk management, and compliance (GRC) – with specific expertise on the topics of enterprise GRC, GRC technology, corporate compliance, and policy management. With 27+ years of experience, Michael helps organizations improve GRC processes, design and implement GRC architecture, and select technologies that are effective, efficient, and agile. He is a sought-after keynote speaker, author, and advisor and is noted as the “Father of GRC” — being the first to define and model the GRC market in February 2002 while at Forrester.
Michael has contributed to U.S. Congressional reports and committees, and currently serves on the Leadership Council of the OCEG and chairs the OCEG Technology Council, OCEG Policy Management Group, and the OCEG GRC Architect Group.
Michael is quoted extensively in the press and is respected for his commentary on broadcast news channels. He is an Honorary Life Member in The Institute of Risk Management for his contributions to risk management and GRC. In June 2007, Treasury & Risk recognized Michael as one of the 100 most influential people in finance with specific accolades noting his work in “Governance and Compliance: Saving the Planet and the Corporation” and as a “Rising Star in Rocky Times: Corporate America’s Outstanding Executives.”
Prior to founding GRC 20/20 Research, Michael was a Vice-President and ‘Top Analyst’ at Forrester Research, Inc. Before Forrester, he led the risk/compliance consulting practice at a professional services firm, and prior to that has specific experience managing compliance and risk within commercial organizations.
Michael’s educational experience consists of a Juris Doctorate in law and a Bachelor of Science in Business. Michael is currently pursuing a Master of Divinity at Trinity Evangelical Divinity School with a research focus in ethics and church history. He is a GRCP (GRC Professional), CCEP (Certified Compliance and Ethic Professional), and a CISSP (Certified Information Systems Security Professional). OCEG has recognized him as an OCEG Fellow for his contributions and advancement of GRC practices around the world.
Malaysian enterprises are navigating one of the most demanding regulatory environments in Southeast Asia. Bank Negara Malaysia's Risk Management in Technology (RMiT) framework and its sharpening expectations on AI governance, the Securities Commission's evolving digital asset and capital markets oversight, the long-anticipated modernization of the PDPA, NACSA's National Cybersecurity Policy, and the accelerating pace of the Madani Economy's digital agenda are all in motion simultaneously. Manual GRC cannot keep pace — and organizations that treat this as a technology upgrade problem will keep falling behind.
This session is centered on shifting perception from GRC as a tool to a business enabler, while addressing front-line resistance and underutilization, and showcasing how AI can be layered in to enhance usability, adoption, and decision-making without adding complexity.
Why manual GRC breaks under compounding pressure: the fragmentation trap — disconnected tools, siloed risk, compliance, audit, cyber data, and periodic point-in-time assessments that leave organizations exposed between cycles
The adoption gap and its cost: why most GRC programs are technically deployed but organizationally stranded — avoided by the business, invisible to the board, and unable to demonstrate value until something goes wrong
Shifts in GRC: from periodic to continuous sensing and assessments; from reactive to predictive intelligence; from assurance-speak to business decision language; and from bolted-on to embedded AI
GRC as competitive advantage: how leading enterprises in the region are using AI-enabled GRC programs to accelerate business, reduce audit friction, lower regulatory capital requirements, and build board confidence
Please complete the registration form to secure your spot. Confirmation will be shared shortly. Availability is limited.
Panel Discussion
© 2026 MetricStream Inc. All Rights Reserved. Privacy Policy | Sitemap