惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

GbyAI
GbyAI
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
P
Proofpoint News Feed
L
Lohrmann on Cybersecurity
S
Secure Thoughts
Attack and Defense Labs
Attack and Defense Labs
人人都是产品经理
人人都是产品经理
Stack Overflow Blog
Stack Overflow Blog
W
WeLiveSecurity
O
OpenAI News
SecWiki News
SecWiki News
博客园 - Franky
NISL@THU
NISL@THU
Microsoft Azure Blog
Microsoft Azure Blog
T
Tor Project blog
Microsoft Security Blog
Microsoft Security Blog
aimingoo的专栏
aimingoo的专栏
Security Latest
Security Latest
H
Hacker News: Front Page
Google Online Security Blog
Google Online Security Blog
P
Privacy & Cybersecurity Law Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
D
Darknet – Hacking Tools, Hacker News & Cyber Security
月光博客
月光博客
李成银的技术随笔
Spread Privacy
Spread Privacy
F
Full Disclosure
F
Fortinet All Blogs
T
The Exploit Database - CXSecurity.com
Vercel News
Vercel News
AWS News Blog
AWS News Blog
WordPress大学
WordPress大学
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
V
Visual Studio Blog
J
Java Code Geeks
博客园 - 三生石上(FineUI控件)
G
Google Developers Blog
云风的 BLOG
云风的 BLOG
博客园 - 司徒正美
Engineering at Meta
Engineering at Meta
Last Week in AI
Last Week in AI
P
Palo Alto Networks Blog
宝玉的分享
宝玉的分享
T
True Tiger Recordings
N
News and Events Feed by Topic
酷 壳 – CoolShell
酷 壳 – CoolShell
Cisco Talos Blog
Cisco Talos Blog
N
News | PayPal Newsroom
S
SegmentFault 最新的问题
Jina AI
Jina AI

Forbes - Innovation

Google Confirms 2 Critical New Flaws—How To Jump The Update Queue Google Splits Its Agent Strategy For Two Developer Audiences ‘The Boys’ Series Finale Review Scores Are Way Under ‘Stranger Things’ Autonomous Data Stewardship: How AI Agents Are Redefining Master Data Management In Financial Services A Small Business Guide To Understanding Multistate Tax Obligations Why Performance Has Become The New Currency In Advertising The Plan For FEMA Reform, Less People In D.C.,More Responsibility For States There’s A Way ‘Gen V’ May Now Live On After ‘The Boys’ Finale Garmin Cirqa Price May Be Far Higher Than Expected Securing AI Cloud Systems: Intelligent Testing For Intelligent Systems 2 New Microsoft Defender Zero-Days Exploited—Patch Now Rolling Out 2 Tell-Tale Signs Of ‘Fake Love’ In A Relationship, By A Psychologist California Lets Cops Give Tickets To Robocars, Which Is Ridiculous Why Do Humans Have Unique Voices? An Evolutionary Biologist Explains The Anatomy That Makes You Unmistakable Of All The Professions AI Is Disrupting, Accounting Has The Worst Math How Connected Reporting And Dynamic Waterfalls Reshape Fund Services Humanoid’s New Deal: Bosch Will Build Its Robots With Schaeffler Parts The New Resilience Part 2: Evolving Best Practices In AI And IIoT ​How AI Is Changing The Economics Of Integration ​Why The Cheapest AI Stack Becomes The Most Expensive At Scale The New Surgeon General Advisory On The Harms Of Screen Use— Here’s What The Science Says About Risks And Benefits Developing An Executive Cybersecurity Strategy For Directors Stop Measuring AI Spend, Start Measuring Impact AI Agents Belong In Your Identity Program How SMEs Unlock Greater Value From AI Why Small, Elite Teams Outperform Big Ones If You Value Online Security Stop Using Public Wi-Fi Hotspots Demystifying Success: A Practical Approach To Guiding Your Business Are Financial Institutions Failing To Back The Low-Carbon Economy? Airbnb CEO Brian Chesky Called Chinese AI Fast And Cheap. Now, Congress Wants Answers The Neurotech CRO: Kordata Launches To Power Next-Gen Clinical Trials Latest AI Behaves More Like Humans By Rudely Interrupting You During Conversational Chats And We Might Relish It Google I/O 2026 Turned Gemini Into An Agent Platform Advanced Packaging Leads The Way To Intel Foundry Success From AI Policies To AI Literacy In Education Today’s Wordle #1797 Hints And Answer For Thursday, May 21 NYT ‘Pips’ Hints, Answers And Walkthrough For Thursday, May 21 Meta Expands Its Creator Ecosystem With Instagram’s New Instants App 4 Factors That Strongly Influence First Impressions, By A Psychologist ‘The Boys’ Series Finale Is A Crushing Disappointment ‘Escape From Tarkov’ Icebreaker Delayed As Current Event Extended Class Of 2026 Faces A Hard Truth: AI Isn’t The Threat—Ignoring It Is What Google’s Universal Cart Launch Means For AI-Led Shopping The $150 Trillion Question—What Is AI’s Value In Asset Management A Third-Wave Philanthropy Unlocked By AI Could Supercharge Federal R&D Top Frontier AI Models Top Out At C+ ... Barely Better Than Old Models Google Wants Search To Stop Answering And Start Acting Quordle Hints Today: Thursday, May 21 Clues And Answers NYT Strands Hint Today: Thursday, May 21 Clues And Answers (In A Material World) NYT Connections Hints Today: Thursday, May 21 Clues And Answers (#1,075) NYT Connections Answers Explained For Thursday, May 21 (#1,075) Why Infrastructure Modernization Is The Real Enabler Of AI The ‘Concord’ Curse Returns With Quantic Dream’s PvP Game Axed In 3 Months ‘Obsession,’ Now Going Viral, Just Set A 17-Year Box Office Record ‘The Boys’ Series Finale Review: Last Second Salvation Inside Incyte’s $120 Million AI For Drug Development Deal Samsung Galaxy Z Fold 8: Bad Crease News, No Display Upgrade The Robot Revolution Has Officially Begun When Insurance Disappears, Economies Follow. The G7 Has A Unique Opportunity To Act Solving The Identity Crisis: Putting Today’s Fragmented Consumer Back Together Private Equity-Owned Retinal Practices Perform Fewer Retinal Detachment Procedures Some Private Equity Firms Would Rather Let People Go Blind Than Reduce Their Profits How To Mitigate The Microsoft Windows BitLocker ‘Angry Hacker’ 0-Day ‘Off Campus’ Has Set A Rotten Tomatoes Score Record For The Past Year E-Cigarettes Can Help You Quit Smoking Says New Study Netflix’s Best New No. 1 Show Lands A 90% Rotten Tomatoes Score 2 Stubborn Habits That Predict Long-Term Success, By A Psychologist The AI-Native Human: What You Must Become To Stay Relevant GitHub Says 3,800 Repositories Breached—TeamPCP Hackers Demand $50,000 Vibe Hunting: A New Way Of Threat Hunting With AI Your AI Is Getting Smarter. But Whose Intelligence Is It Building? How 24/7 Renewables Are Ending Fossil Fuel Reliability ​Behind Vertical AI: What AI Is Already Demanding Of Energy And Utilities How The ARISE Network Is Rethinking Clinical AI Meet The Star-Nosed Mole — The Fastest Hunter On The Planet It’s Time To Rethink Data Retention In Healthcare The Intelligence Infrastructure Behind AI Agents The Next Phase Of Enterprise AI: Why LLM Consolidation Is Inevitable ​The Software Coordination Tax: Why Your 40-Engineer Team Is Shipping Like 25 Beyond The ‘Build Versus Buy’ Trap: Agentic Orchestration​'s Role In The Future Of GTM Demystifying Success: A Practical Approach To Guiding Your Business The Identity Crisis Your Security Team Didn't See Coming The End Of The Server Room: What Happens When Your Cameras Start Modernizing Legacy Industries And Multi-Partner Coordination Why Pharma Boards Confuse Scenario Models With Risk Measurements Your Company Is Measuring AI Adoption Wrong. Track This Instead. China Has Outspent The U.S. On Research For The First Time. 3,375 American Scientists Are Telling Congress To Pay Attention Why Americans Are Turning Against Data Centers Climate Advisers Call For Maximum Workplace Temperature Rules In U.K. People Are Really Angry At AI Content Even If It Turns Out That AI Didn’t Produce It And The Content Was Actually Human Made Volvo EX60 Road Tested: Is This The Best Electric SUV Yet? Ugreen Packs A Punch With Its Latest Nexode And MagFlow Air Chargers Why AI Literacy Has Become A Boardroom And Investor Priority 007 First Light Early Access: How To Play Before The Release Date Ronda Rousey’s 17-Second Win Drew Staggering Netflix Viewership Ronda Rousey Fallout: UFC Veteran Rips MVP MMA 1 As 'Cringe' When Is the Next UFC? Date, Times and Full Schedule Ebola Outbreak Update: An American Doctor, A WHO Emergency, And What The New Numbers Mean Microsoft Work Trend Index 2026 Shows AI Productivity Is Not Enough Today’s Wordle #1796 Hints And Answer For Wednesday, May 20
Rethinking GRC In The Tokenized Economy
Ramachander · 2026-05-21 · via Forbes - Innovation

Ramachander Rao Thallada is a Governance, Risk, and Compliance (GRC) Executive for Manulife, a modern North American financial institution.

getty

Governance, risk and compliance (GRC) have long been viewed as a purely operational cost rather than a strategic opportunity. Significant investment has been made in building compliance systems to meet regulatory requirements, yet inefficiencies persist due to fragmented processes, legacy systems and rising risk exposure. Drawing on experience in financial systems and compliance, the core issue is often not the absence of controls, but how those controls are designed and implemented.​

Traditional GRC models have historically been reactive, focusing on identifying and managing risks after they emerge rather than designing systems that prevent or reduce risk at the source. In digital payment environments, for example, considerable progress has been made in securing transactions at the point of entry. However, downstream processes such as refunds, dispute resolution and charge-back evidence collection often still rely on outdated, data-intensive workflows.

These gaps often result in unnecessary exposure of sensitive information and increased operational complexity and ultimately weaken the effectiveness of compliance itself.​​

From Reactive Controls To Embedded Governance​​​

​To address this problem, businesses need to shift from compliance by control to compliance by architecture, where governance is embedded directly into system design. Instead of relying on layers of oversight and manual controls, systems should be designed to inherently reduce risk while still maintaining transparency and accountability.

One area where this shift is increasingly relevant is payment tokenization. While tokenization has been widely adopted to protect cardholder data during transaction authorization, its use has typically been limited to the front end of the payment process. Downstream processes, however, often still rely on legacy approaches that depend heavily on sensitive data.

​​This issue was highlighted in a study conducted by Vimal Teja Manne, a business analyst with expertise in payment processing and privacy-focused financial infrastructure. According to the study, many tokenization solutions still rely on PAN-associated data when managing refunds and processing charge-backs. Manne’s work closely examines the end-to-end workflow and proposes a new architecture that connects the payment, refund and dispute processes without relying on sensitive identifiers.

​Under the GRC framework, this represents a significant paradigm shift. Rather than relying on continuous access to sensitive information, the approach uses a secure token-based relationship model, enabling full traceability without compromising confidentiality. These ideas are also aligned with privacy by design and data minimization, which are two principles that are becoming increasingly important in today’s regulatory environment.

The proposed system could reduce privacy exposure from a score of 1.48 to 0.31 (approximately 79%)​, while also improving the accuracy and reliability of audit evidence. This reinforces that effective compliance is not about adding more controls, but about designing systems that are inherently risk-aware and resilient.​

One key aspect of the Manne framework is the concept of selective disclosure. In traditional compliance processes, transaction data is often shared broadly across multiple parties, which increases both risk and inefficiency. By contrast, the framework introduces role-based disclosure of evidence, ensuring that only the minimum amount of data required for a specific function is shared.

This design improves security while also increasing efficiency by reducing unnecessary data handling and processing. It effectively introduces a structured analytical approach that helps bridge the gap between compliance requirements and practical system implementation.​​

Designing systems that effectively balance operational needs with compliance requirements demands more than technology alone, and business analysis is what helps make that alignment possible.​

In order to make this transition, companies will need to initially examine their end-to-end compliance processes and see where sensitive data is accessed, stored or replicated more than is necessary for purposes of regulation and compliance management. In most instances, risk does not come from a lack of controls, but from an outdated set of dependencies inherent in the processes that were established before modern technology came into play.

Organizations should focus on reducing unnecessary dependencies on sensitive data through approaches such as tokenization, abstraction and privacy-centric system design. Where appropriate, these methods can limit direct exposure to regulated information while still preserving traceability, operational continuity and compliance effectiveness.​

Another critical step is utilizing a role-based strategy for sharing data, whereby access is granted on a need-to-know basis. For instance, firms can start by reviewing their approaches to creating audit evidence and distribute it in such a way that every party gets the necessary data to perform their duties. Firms can benefit from developing robust internal capabilities, especially when it comes to business analysis and process redesign, which help make it easier to integrate compliance regulations into systemwide solutions.​​

The Rise Of Architecture-Driven Compliance

​This reflects a broader shift in the GRC landscape. As data volumes and digitization continue to grow, the role of the business analyst is evolving from that of a traditional analyst to a more enabling, strategic function. The ability to align regulatory requirements with an organization’s system architecture is becoming increasingly critical for both innovation and compliance.

Organizations that continue to treat compliance as a back-office function risk facing escalating challenges in managing risk and adapting to regulatory change. In contrast, those that adopt an architecture-based approach to GRC—supported by strong analytical capabilities—will be better positioned to manage risk, build customer trust and improve operational efficiency. In this context, compliance should not be seen as an obstacle to success, but as a potential source of competitive advantage.

In a token-based economy, trust is no longer defined primarily by policies and controls, but by system design itself—where governance is embedded, risk is reduced by default and compliance evolves alongside technology. Organizations that recognize this shift in paradigm will be the ones that shape the future of GRC.​


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?