TL;DR: ISACA conference sessions showed GRC leaders shifting from checkbox compliance to continuous risk reduction, with AI governance, MCP risk, and audit evidence generation emerging as the clearest pressure points, according to Clarity Security. The industry’s control model is out of step with systems that can make decisions, expand access, and outpace point-in-time review cycles.
NHIMG editorial — based on content published by Clarity Security: the ISACA GRC conference themes on AI governance, compliance, and evidence generation
By the numbers:
- 1, ver 1,500 compliance, audit, technology, and security leaders gathered in San Diego for four days of sessions and workshops.
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, sharing sensitive data, and revealing access credentials.
- 96% of technology professionals identify AI agents as a growing security threat, and 66% believe this risk is immediate.
Questions worth separating out
Q: What breaks when GRC programmes rely on point-in-time compliance reviews?
A: Point-in-time reviews miss the changes that happen between audit snapshots, which means access can be approved on paper while remaining risky in practice.
Q: Why do local AI agents complicate identity and access management?
A: They can retain legitimate permissions while changing timing, prioritisation, and action sequence outside human presence.
Q: How should security teams turn access reviews into real risk reduction?
A: Security teams should use access reviews to remove dormant access, orphaned accounts, and privileges that no longer match the work being performed.
Practitioner guidance
- Build continuous evidence pipelines Connect entitlement changes, access usage, and revocation events so auditors can verify control operation continuously rather than at a single review point.
- Model AI agents as governed identities Assign explicit scopes to MCP-connected and other agentic workflows, including tool permissions, logging, and revocation paths before they reach production.
- Unify human, NHI, and agentic access telemetry Correlate identity, privilege, and activity data across all three identity classes so evidence generation does not depend on manual reconciliation.
What's in the full article
Clarity Security's full article covers the operational detail this post intentionally leaves for the source:
- Session-level examples of how GRC teams are reworking access review and continuous compliance workflows.
- Practical discussion of MCP security and how audit programs should account for agentic access paths.
- Details from Clarity Security's continuous risk assessment framing, including the Identify, Classify, Triage, Remediate model.
- Conference-specific context from the sessions and conversations that shaped the article's conclusions.
👉 Read Clarity Security's conference analysis on AI governance, MCP risk, and continuous compliance →
AI governance, evidence gaps, and what GRC teams must change now?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
AI governance has become an identity governance problem, not just a model-risk problem. The conference’s strongest signal was that AI is now embedded in access decisions, tool use, and evidence trails. That means GRC teams can no longer treat AI as a separate policy domain. IAM, PAM, and NHI controls must extend into AI delegation, tool permissions, and runtime authorisation if governance is going to reflect reality.
A question worth separating out:
Q: Who is accountable when AI-related access outpaces governance?
A: Accountability sits with the owners of identity, data, and platform controls together, because AI-related access problems cross programme boundaries. IAM, IGA, PAM, and security leadership must share responsibility for visibility, revocation, and ownership. If one team can create access but no team can remove it quickly, the control model is incomplete.
👉 Read our full editorial: AI governance and continuous compliance are reshaping GRC priorities