GRC Unpacked is an independent publication by Hannes Zerner about applying AI in audit, compliance, and security. It is written for GRC professionals who work with governed records, regulatory obligations, sensitive information, and accountable decisions.

Useful AI begins with the work

We examine concrete tasks: preparing audit evidence summaries, proposing obligation-to-control mappings, drafting security incident handoffs, and improving recurring GRC workflows. Each task needs clear inputs, a defined scope, permitted actions, and criteria for accepting the result.

Evidence, review, and decision ownership

Our focus is the path from source information to a work product someone can inspect and use. We distinguish observations from interpretations, candidate mappings from accepted compliance positions, and completed activities from evidence of control effectiveness.

AI can help prepare work. Its authority should be explicit. Consequential decisions require the designated organizational process, appropriate evidence, and an accountable owner.

The editorial approach

Start with the decision. Explain what the evidence supports and what remains uncertain. Include realistic examples, useful prompts, failure cases, and the strongest counterargument. Count preparation, review, and correction effort when assessing value.

Illustrative scenarios are identified as such. Recommendations are distinguished from legal requirements and verified results. A framework citation does not establish compliance. Reproducibility does not establish correctness, and human approval does not guarantee a sound decision.

Read, watch, and put it to work

Explore the journal for practical field notes on governed AI, evidence, and accountable judgment. Visit our links page for written articles, videos, and other public channels.