Skip to main content

      Governance, Risk, and Compliance (GRC) can quickly become complex as organizations face growing regulatory expectations, increasingly complex IT environments, and higher demands for transparency and accountability. What often begins with policies and controls soon raises broader questions around ownership, tooling, governance structures, and how risk and compliance can realistically be embedded into daily operations.

      In this edition, our experts explain how GRC helps organizations move from fragmented, manual approaches towards a more integrated and technology-enabled way of working. They discuss key GRC areas such as digital compliance management, control integration and testing, IT risk management, application security and GRC tooling, as well as common challenges encountered in practice, including tool selection, system integration, and business adoption.

      The discussion also explores how automation and emerging AI capabilities can support monitoring, reporting, and decision‑making, while emphasizing that tools alone are not enough. Sustainable GRC depends on clear governance, well‑designed controls and ownership by the business. Drawing on real project experience, the experts highlight what makes GRC initiatives work in practice, and why they are often more complex than initially expected.

      What is GRC and why is it important?

      Kristijan: GRC aligns business objectives, risks, and regulations. It helps organizations gain better insights, improve decision‑making, and build trust.

      Laura‑Andreea: It also helps organizations move from fragmented compliance to an integrated, technology-enabled approach, where risks are properly identified and managed.

      Kristijan Jovic, Advisor

      Kristijan Jovic, Advisor, Enterprise Risk Services

      Laura-Andreea Istrate, Advisor

      Laura-Andreea Istrate, Advisor, Enterprise Risk Services

      What services does KPMG’s GRC team provide?

      Kristijan: We work on digital compliance, control integration and testing, and IT risk management.

      Laura‑Andreea: We also support GRC tooling, from selecting the right tool to implementing and integrating it into the client’s environment.

      What are the main challenges organizations encounter in GRC projects?

      Laura‑Andreea: One key challenge is selecting and implementing the right GRC tooling, as organizations often struggle to find solutions that fit their needs and integrate well with existing systems. It is equally important to ensure that GRC is embedded in the organization, with controls effectively adopted and owned by the business. This is not always an easy task for organizations. KPMG can support this journey by providing the necessary expertise to ensure it is approached in a structured, managed, and efficient way.

      Kristijan: Another key challenge in GRC projects is the complexity of the environments in which organizations operate. Fragmented IT landscapes, numerous applications, and legacy systems make it difficult to establish a consistent control framework. A thorough understanding of the organization, combined with strong stakeholder alignment, is critical to ensure that all relevant considerations are identified upfront. This lays the foundation for a successful GRC project, minimizing unexpected issues, and helping to ensure a smooth and predictable implementation.

      What is your most memorable GRC project?

      Kristijan: One of my most memorable projects was the internal audit of an international company. What made it really interesting was the international scope, working across multiple countries. I really enjoyed the multicultural environment of the project and the opportunity to engage with individuals from a variety of cultural backgrounds.

      Laura‑Andreea: On one project, I was responsible for analyzing and comparing various GRC solutions to support the client's tool selection process. This provided valuable insights into the organization's specific requirements and priorities. It was rewarding to help the client identify the most suitable solution and guide them through the evaluation process, ensuring that the selected tool was aligned with their business objectives, governance needs, and overall organizational requirements.

      If you could choose your ideal GRC project, what would it look like?

      Laura‑Andreea: My dream project would be an end‑to‑end GRC project for an international financial organization, where we design the different controls and integrate them directly into systems, which would also involve traveling to various international locations to support regional implementations.

      Kristijan: I would love to integrate a GRC tooling project within the manufacturing sector, where we help a client select and implement a tool from start to finish. I have previously delivered GRC projects within this sector and have found its processes very interesting. These engagements provided valuable insight into their way of working. I enjoy the challenge of understanding these complex business processes and translating them into an integrated GRC solution.

      How did you end up at KPMG?

      Kristijan: During my master’s, I attended the Digital Risk Management bootcamp, where I had the opportunity to work on a GRC case, and I really enjoyed it. That’s what led me to join KPMG.

      Laura‑Andreea: It was similar for me. I joined the bootcamp and worked on a GRC case. What really stood out to me from the beginning was the culture: Everyone was welcoming, approachable, and friendly from the start, which ultimately motivated me to apply.

      Why should people join KPMG?

      Laura‑Andreea: One of the main reasons I enjoy is the combination of professional development and a strong team culture. I work with different clients and on several projects, which allows me to learn quickly and continuously expand my skills. KPMG also invests in training and development, providing great opportunities for growth.

      At the same time, the supportive and friendly atmosphere makes a real difference. The strong connections and friendships built with colleagues really make me feel appreciated.

      Kristijan: What I particularly appreciate is the level of responsibility and ownership you are given from an early stage. Being trusted to manage your work and contribute meaningfully to projects creates a strong sense of accountability and provides the motivation to continuously develop and grow. Beyond the professional aspects, the strong team spirit also makes KPMG a great place to work. Regular padel sessions with colleagues provide an excellent opportunity to connect outside of project work, fostering camaraderie, teamwork, and lasting relationships.



      Magazine on GRC

      June 2026




      Do you have questions related to GRC?

      For guidance or further information on GRC-related topics, feel free to reach out to Benny Bogaerts.

      Benny Bogaerts

      Partner, Technology | Advisory

      KPMG in Belgium



      Digital Risk Management

      KPMG Technology services.
      Technology advisory

      Stay informed

      Be the first to know about top business trends that can drive success for your company.

      stay informed