# Clean Reports, Flawed Systems, and the Future of GRC Page: https://stenobird.com/podcast/grc-uncensored-7039393/clean-reports-flawed-systems-and-the-future-of-grc Text version: https://stenobird.com/podcast/grc-uncensored-7039393/clean-reports-flawed-systems-and-the-future-of-grc.md Podcast: [GRC Uncensored](https://stenobird.com/podcast/grc-uncensored-7039393) Published: 2025-10-09T12:00:00+00:00 Episode link: https://shows.acast.com/grc-uncensored/episodes/68e67c6f79fd6a22445bcb20 Audio file: https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/68e67c6f79fd6a22445bcb20/media.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/grc-uncensored-7039393/episodes/clean-reports-flawed-systems-and-the-future-of-grc Duration seconds: 2789 ## Resource TJ, Kendra, and Elliot are back, and welcomed Evan Millman , GRC Manager at Abnormal Security, for what started as a casual chat and evolved into a sharp look at compliance blind spots, the role of AI in GRC, and how professionals can shape their careers in a changing field. [00:02:00] Evan shares how he used ChatGPT to analyze a risk assessment report. [00:05:00] What GRC leadership looks like at Abnormal Security (ISO 27001, 27701, 42001, SOC 2). [00:07:00] The complicated relationship between organizations and auditors — bias, incentives, and the reality of “clean” reports. [00:12:00] Why third-party attestations are table stakes, not real assurance. [00:19:00] TJ and Evan debate solutions: peer reviews, government oversight, or is the system fundamentally flawed? [00:27:00] How Abnormal approaches vendor risk: criticality ratings, renewals, and compensating controls. [00:32:00] Tools and automation in GRC — benefits and buyer’s remorse. [00:36:00] The role of AI: evidence review, documentation search, and “trust but verify.” [00:39:00] Should GRC professionals become coders, or double down on soft skills? [00:44:00] Evan’s career advice: networking, persistence, and why soft skills matter more than technical depth. Hosted on Acast. See acast.com/privacy for more information. ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/grc-uncensored-7039393/episodes/clean-reports-flawed-systems-and-the-future-of-grc/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/grc-uncensored-7039393/clean-reports-flawed-systems-and-the-future-of-grc.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.