
MITRE ATT&CK: A Practical Guide to Understanding Adversary Behavior
August 12, 2026From Check-the-Box to Continuous Assurance: TrustCloud’s Vision for AI-Powered GRC and TPRM

Governance, risk and compliance (GRC) and Third Party Risk Management (TPRM) may not be the first areas that come to mind when people think about transformation with AI. But at the FRC Erie Summit on July 29, 2026, TrustCloud founder and CEO Sravish Sridhar made the case that these are exactly the kinds of disciplines where meaningful transformation is needed—and where AI can have a very practical impact.
Sravish’s session, GRC Transformation for the Public Sector: ACT with AI, challenged public-sector technology and security leaders to reconsider an operating model that is still too often built around spreadsheets, manual evidence collection, point-in-time audits, questionnaires and sampling. His larger question was simple: If GRC and TPRM are supposed to help us understand whether an organization – and the third parties it depends on – can be trusted, why are we relying on processes that only give us a partial picture a few times a year?
For decades, modern digital security has relied on mathematical problems that are practically impossible for classical computers to solve. When you log into a secure government portal, send an encrypted message, or verify a digital signature, your data is shielded by public-key cryptography. A standard computer trying to brute-force these mathematical shields would take thousands of years.
Moving beyond “check-the-box” GRC and TPRM
For Sravish, the problem begins with the gap between what organizations say about their security and compliance posture and what they can continuously prove. He described trust through an idea that runs throughout his presentation: “promises made, promises kept.” Making the promise is one thing. Demonstrating that the organization—and its extended ecosystem—is living up to it is another.
Traditional GRC and TPRM processes can make that difficult.
Security, compliance and risk professionals spend significant time gathering evidence, completing and reviewing questionnaires, preparing for audits and assessing vendors. Assessments frequently rely on samples rather than the entire population of activity. Meanwhile, the scope continues to grow as organizations contend with more frameworks, contractual requirements, third-party relationships, security risks and emerging areas such as AI governance. Sravish’s presentation captures that challenge succinctly: more requirements, but often the “same team, same headcount, same spreadsheet.”
That challenge is especially familiar in the public sector, where expectations continue to rise while teams and budgets do not necessarily rise with them.
For FRC customers across state and local government and higher education, that tension should sound familiar: How do you increase assurance and resilience across your own environment and your third-party ecosystem without simply asking already-stretched teams to do more manual work? Sravish believes the answer starts with three letters: ACT.
ACT: Automation, Continuous Monitoring and Transparency
Sravish’s ACT framework outlines three changes he sees as essential to modern GRC and risk management: Automation, Continuous Monitoring and Transparency.
Automation is about taking repetitive work away from skilled professionals so they can spend more time on analysis, decision-making and risk reduction. Sravish’s framing is straightforward: machines can handle the daily grunt work, while people focus on strategic review and decisions.

Continuous Monitoring replaces the point-in-time mindset with an ongoing view of controls and risk. Rather than assessing internal controls or third parties only periodically, organizations can work toward a more current understanding of where risk is changing and where attention is needed.

And Transparency means making that information useful beyond the GRC or TPRM team. Instead of risk living in a spreadsheet understood by a small group of specialists, organizations can use accurate, current information to have better conversations with CIOs, CISOs, executives, control owners, vendor managers and other stakeholders.

That shift changes GRC and TPRM from exercises in proving that a box was checked into tools for making better decisions.
Making the business case for AI
One of the more important parts of Sravish’s talk was what he didn’t recommend: adopting AI simply because it is AI.
With organizations being presented with AI use cases from every direction, Sravish offered another way to frame the business case: AI as Assurance + Impact.
Assurance means having confidence in the result—testing more of the environment, more accurately and more frequently instead of relying exclusively on periodic sampling. Importantly, Sravish extends that idea across both the organization’s first-party and third-party landscape, with an emphasis on broad control-testing coverage and quantifying exposure in meaningful terms.

Impact is about connecting that assurance to outcomes the organization cares about. Are you giving employees time back? Reducing operational costs? Identifying internal or third-party risk sooner? Helping leaders understand which control failures actually matter? Connecting cybersecurity work to the mission the organization exists to deliver?

Sravish frames that impact in terms of unlocking productivity, saving money and connecting actions to the mission being protected—whether that means benefits paid, licenses issued or students enrolled. That last point is particularly important in the public sector. The goal is not compliance for compliance’s sake. It is protecting the systems, partners and services behind the many functions citizens, students and communities depend on.
TrustCloud and FRC: Helping customers put the model into practice
As an FRC OEM partner, TrustCloud brings technology to this challenge that is designed around automated IT and third-party risk assurance, continuous control monitoring and a more current view of an organization’s risk and compliance posture.
For FRC, that makes TrustCloud particularly relevant as we work with public-sector customers looking to modernize GRC and TPRM without simply adding more work to their teams.
The opportunity is bigger than automating an audit or speeding up a vendor questionnaire. It is about moving toward a model in which organizations can measure their posture continuously, gain greater visibility into third-party risk, surface meaningful issues sooner and give leaders better information for deciding where to act.
Sravish closes his Erie Summit session with practical ideas for getting started—without suggesting organizations need to transform everything at once. His recommendations include selecting important controls to automate, moving a control from an annual sample to continuous testing, and proactively publishing accurate risk or audit assurance information.
He also brings plenty of humor to a subject not traditionally known for it, including a memorable take on security questionnaires that is worth hearing directly from him.
Most importantly, his talk poses a question public-sector leaders increasingly need to answer: Can you prove that your organization-and the third parties you rely on-are as secure, compliant and resilient as you believe them to be, not just at audit or assessment time, but every day?

Watch the Full Session
Watch the full session to hear Sravish Sridhar’s complete presentation from the FRC Erie Summit and see how TrustCloud is approaching the next generation of GRC and Third Party Risk Management.
To learn more about TrustCloud and how FRC can help your organization evaluate modern approaches to governance, risk, compliance and third-party risk, contact your FRC representative.



