<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Olusola Akanji</title><description>GRC and cybersecurity technical writer. Compliance documentation, framework guides, and governance communication for technical teams and organizational leaders.</description><link>https://akanjitechnicalwriting.com/</link><item><title>Agentic AI Risk Explained: 5 Dangerous Governance Gaps GRC Programs Must Close</title><link>https://akanjitechnicalwriting.com/blog/agentic-ai-risk/</link><guid isPermaLink="true">https://akanjitechnicalwriting.com/blog/agentic-ai-risk/</guid><description>Agentic AI systems act autonomously. Most GRC programs were not built to govern systems that decide and execute without human approval at each step. This post identifies the 5 governance gaps and what</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate></item><item><title>AI Governance Program: A Proven 5-Step Framework for GRC Professionals</title><link>https://akanjitechnicalwriting.com/blog/ai-governance-program/</link><guid isPermaLink="true">https://akanjitechnicalwriting.com/blog/ai-governance-program/</guid><description>Most organizations are running AI without a governance program to match. This guide gives GRC professionals a proven 5-step framework for building an AI governance program from inventory to evidence t</description><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate></item><item><title>AI Governance vs AI Compliance: 3 Critical Differences Every GRC Analyst Must Know</title><link>https://akanjitechnicalwriting.com/blog/ai-governance-vs-ai-compliance/</link><guid isPermaLink="true">https://akanjitechnicalwriting.com/blog/ai-governance-vs-ai-compliance/</guid><description>AI governance and AI compliance are related but not the same. Confusing them produces programs that satisfy auditors but fail to control the AI systems they were built to govern. Here are the 3 distin</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate></item><item><title>EU AI Act Compliance: 4 Critical Risk Tiers Every Organization Must Understand</title><link>https://akanjitechnicalwriting.com/blog/eu-ai-act-compliance/</link><guid isPermaLink="true">https://akanjitechnicalwriting.com/blog/eu-ai-act-compliance/</guid><description>The EU AI Act is now in force. This guide breaks down its 4 risk tiers, compliance obligations by tier, and what US organizations with EU exposure need to do before deploying AI systems.</description><pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Governance Risk and Compliance Explained: 4 Proven Reasons It Cannot Be Ignored</title><link>https://akanjitechnicalwriting.com/blog/governance-risk-and-compliance-guide/</link><guid isPermaLink="true">https://akanjitechnicalwriting.com/blog/governance-risk-and-compliance-guide/</guid><description>Governance risk and compliance (GRC) is the integrated management discipline that connects leadership decision-making to threat prioritization to verifiable accountability. Four reasons it cannot be t</description><pubDate>Mon, 05 Jan 2026 00:00:00 GMT</pubDate></item><item><title>GRC Analyst Role and Responsibilities: What the Job Actually Requires</title><link>https://akanjitechnicalwriting.com/blog/grc-analyst-roles/</link><guid isPermaLink="true">https://akanjitechnicalwriting.com/blog/grc-analyst-roles/</guid><description>A GRC analyst designs policies, manages risk registers, maps controls to frameworks, and collects audit evidence. Here is what the work actually requires day to day.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate></item><item><title>Elevate Your GRC Ethics: A Powerful 4-Virtue Governance Framework</title><link>https://akanjitechnicalwriting.com/blog/grc-ethics-framework/</link><guid isPermaLink="true">https://akanjitechnicalwriting.com/blog/grc-ethics-framework/</guid><description>How the four cardinal virtues map to GRC ethics and control families, with a virtue-to-control matrix and five-step decision protocol for governance professionals.</description><pubDate>Sat, 24 Jan 2026 00:00:00 GMT</pubDate></item><item><title>GRC Framework Overview: NIST CSF 2.0, ISO 27001:2022, and SOC 2 Type II Compared</title><link>https://akanjitechnicalwriting.com/blog/grc-framework-overview/</link><guid isPermaLink="true">https://akanjitechnicalwriting.com/blog/grc-framework-overview/</guid><description>A plain-language comparison of NIST CSF 2.0, ISO 27001:2022, and SOC 2 Type II: what each framework covers, who it is for, what it produces, and how to choose.</description><pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate></item><item><title>Risk Assessment in GRC: A Practical 2026 Framework</title><link>https://akanjitechnicalwriting.com/blog/grc-risk-assessment-guide/</link><guid isPermaLink="true">https://akanjitechnicalwriting.com/blog/grc-risk-assessment-guide/</guid><description>A practitioner&apos;s guide to identifying, analyzing, and prioritizing governance, operational, and compliance risks, with a structured framework you can apply in your next risk review cycle.</description><pubDate>Wed, 07 Jan 2026 00:00:00 GMT</pubDate></item><item><title>How to Become a GRC Analyst: 5 Proven Steps Without the Traditional Path</title><link>https://akanjitechnicalwriting.com/blog/how-to-become-a-grc-analyst/</link><guid isPermaLink="true">https://akanjitechnicalwriting.com/blog/how-to-become-a-grc-analyst/</guid><description>Most GRC job postings list a degree, years of IT experience, and certifications as minimum requirements. These are real preferences, not absolute barriers. Here is the 5-step path that builds the skil</description><pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate></item><item><title>How to Prepare for a SOC 2 Audit: A Readiness Guide</title><link>https://akanjitechnicalwriting.com/blog/how-to-prepare-for-soc-2-audit/</link><guid isPermaLink="true">https://akanjitechnicalwriting.com/blog/how-to-prepare-for-soc-2-audit/</guid><description>Preparing for a SOC 2 audit means closing the gap between the controls you need and documented evidence auditors will test. Here is the sequence that works.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate></item><item><title>ISO 42001 Explained: 6 Proven Requirements for Stronger AI Governance</title><link>https://akanjitechnicalwriting.com/blog/iso-42001-explained/</link><guid isPermaLink="true">https://akanjitechnicalwriting.com/blog/iso-42001-explained/</guid><description>ISO 42001:2023 is the international standard for AI management systems. This guide explains the 6 key requirements GRC analysts need to know, how it differs from ISO 27001, and what implementation act</description><pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate></item><item><title>NIST CSF 2.0 Explained: 6 Essential Functions for Smarter Cyber Risk Management</title><link>https://akanjitechnicalwriting.com/blog/nist-csf-2-0-explained/</link><guid isPermaLink="true">https://akanjitechnicalwriting.com/blog/nist-csf-2-0-explained/</guid><description>NIST CSF 2.0 is a voluntary cybersecurity framework from NIST with 6 functions: Govern, Identify, Protect, Detect, Respond, and Recover. Here is what each one requires and how organizations use them t</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate></item><item><title>OWASP AI Top 10: A Practical GRC Guide to 10 Critical AI Security Risks</title><link>https://akanjitechnicalwriting.com/blog/owasp-ai-top-10-grc-guide/</link><guid isPermaLink="true">https://akanjitechnicalwriting.com/blog/owasp-ai-top-10-grc-guide/</guid><description>The OWASP AI Top 10 is the practitioner risk reference for AI security. This guide explains each of the 10 risks, what they mean for GRC programs, and how to map them to controls your organization alr</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate></item><item><title>What Is Risk Assessment in GRC? A Practical Framework for 2026</title><link>https://akanjitechnicalwriting.com/blog/risk-assessment-in-grc-the-foundation-that-holds-everything-together/</link><guid isPermaLink="true">https://akanjitechnicalwriting.com/blog/risk-assessment-in-grc-the-foundation-that-holds-everything-together/</guid><description>Risk assessment in GRC identifies threats before they become disasters. Learn the framework, lifecycle, and common failures that cost organizations millions.</description><pubDate>Wed, 07 Jan 2026 00:00:00 GMT</pubDate></item><item><title>Risk Management vs Compliance: What Separates Controls Intelligence from Compliance Theater</title><link>https://akanjitechnicalwriting.com/blog/risk-management-vs-compliance/</link><guid isPermaLink="true">https://akanjitechnicalwriting.com/blog/risk-management-vs-compliance/</guid><description>Risk management and compliance are not the same. Most GRC programs confuse the two. 5 signs your program is running on theater instead of real security.</description><pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate></item><item><title>SOC 2 Compliance Explained: What It Is and Who Needs It</title><link>https://akanjitechnicalwriting.com/blog/soc-2-compliance-explained/</link><guid isPermaLink="true">https://akanjitechnicalwriting.com/blog/soc-2-compliance-explained/</guid><description>SOC 2 compliance explained: what it is, the five Trust Services Categories, how Type I and Type II differ, who needs it, and what auditors actually test.</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate></item><item><title>SOC 2 Documentation Checklist: What Auditors Request and Why</title><link>https://akanjitechnicalwriting.com/blog/soc-2-documentation-checklist/</link><guid isPermaLink="true">https://akanjitechnicalwriting.com/blog/soc-2-documentation-checklist/</guid><description>A complete SOC 2 documentation checklist organized by control area: policies, access records, change management, incident logs, and vendor evidence auditors test.</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate></item><item><title>SOC 2 for SaaS Companies: What It Requires and When to Start</title><link>https://akanjitechnicalwriting.com/blog/soc-2-for-saas-companies/</link><guid isPermaLink="true">https://akanjitechnicalwriting.com/blog/soc-2-for-saas-companies/</guid><description>SOC 2 for SaaS companies explained: which Trust Services Categories apply, common SaaS control challenges, and when to start before enterprise deals require it.</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate></item><item><title>SOC 2 Trust Services Criteria Explained: What Each Category Covers</title><link>https://akanjitechnicalwriting.com/blog/soc-2-trust-services-criteria/</link><guid isPermaLink="true">https://akanjitechnicalwriting.com/blog/soc-2-trust-services-criteria/</guid><description>The SOC 2 Trust Services Criteria cover five categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Here is what each one requires.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate></item><item><title>The Four Cardinal Virtues: An Ethics Framework for GRC Professionals</title><link>https://akanjitechnicalwriting.com/blog/the-four-cardinal-virtues-an-ethics-framework-for-grc-professionals/</link><guid isPermaLink="true">https://akanjitechnicalwriting.com/blog/the-four-cardinal-virtues-an-ethics-framework-for-grc-professionals/</guid><description>Maps prudence, justice, fortitude, and temperance to GRC control families in NIST SP 800-30, ISO 27001, and ISO 22301, giving practitioners a character-based framework for high-pressure governance decisions.</description><pubDate>Sat, 24 Jan 2026 00:00:00 GMT</pubDate></item><item><title>What Is AI Governance: 3 Critical Frameworks Every GRC Analyst Must Know</title><link>https://akanjitechnicalwriting.com/blog/what-is-ai-governance/</link><guid isPermaLink="true">https://akanjitechnicalwriting.com/blog/what-is-ai-governance/</guid><description>AI governance is the set of policies, controls, and accountability structures that ensure AI systems operate within defined boundaries, perform as intended, and meet applicable regulatory requirements</description><pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate></item><item><title>What is Governance, Risk, and Compliance (GRC) and Why It Matters More Than Ever</title><link>https://akanjitechnicalwriting.com/blog/what-is-governance-risk-and-compliance-grc-and-why-it-matters-more-than-ever/</link><guid isPermaLink="true">https://akanjitechnicalwriting.com/blog/what-is-governance-risk-and-compliance-grc-and-why-it-matters-more-than-ever/</guid><description>A plain-language introduction to GRC: what governance, risk, and compliance mean individually, how they work together, and why the integrated approach matters for modern organizations.</description><pubDate>Mon, 05 Jan 2026 00:00:00 GMT</pubDate></item><item><title>What Is GRC in Cybersecurity? A Plain-Language Guide</title><link>https://akanjitechnicalwriting.com/blog/what-is-grc-in-cybersecurity/</link><guid isPermaLink="true">https://akanjitechnicalwriting.com/blog/what-is-grc-in-cybersecurity/</guid><description>GRC stands for Governance, Risk, and Compliance. Learn what each component requires, how they connect, and which frameworks GRC analysts use to build secure organizations.</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate></item></channel></rss>