Audit, Governance, Risk & Compliance Insights
Explore Tickbox’s audit and risk insights, including practical guidance on internal controls, governance, cyber security, data protection and technology assurance.

When AI Agents Break Their Boundaries
An AI agent does more than provide an answer. It can use connected systems, make decisions and take action. That ability creates value, but it also means that a mistake can become a real operational or security incident in seconds.

Are your controls and governance keeping pace with growth?
Growth brings opportunities, but it also changes an organisation’s risks. Arrangements that once worked well may become less effective as an organisation takes on more people, customers, systems and suppliers.

Practical controls for AI that can take action
AI is a force multiplier: it increases the value of strong controls and the impact of weak ones.

Virtualisation modernisation: look beyond the platform
Changing licensing models, rising costs, ageing infrastructure and operational complexity are prompting organisations to reconsider their virtual environments.

Cyber Security and Resilience Bill: what changes and who is affected?
The proposed Bill would widen the NIS regime, strengthen regulatory oversight and introduce new cyber incident reporting duties.

GRC Engineering: designing better controls into the way organisations work
GRC Engineering is an emerging discipline that applies engineering principles and technical capabilities to governance, risk and compliance.

ROPA and IAR: what is the difference and why do both matter?
Understanding the distinction helps organisations meet their legal obligations and maintain a clearer view of their information.

Are senior leaders seeing the full assurance picture?
Do leaders have a clear view of where they can take confidence, where concerns remain and what needs their attention?

Risk Identification: Why Good Risk Management Starts with Objectives
Good risk identification turns uncertainty into insight.

Agile and Traditional Auditing: Why a blended approach works
In fast-moving organisations, keeping assurance relevant as priorities and risks evolve is an increasing challenge for internal audit functions.

Meeting the Data Security and Protection Toolkit (DSPT) requirements
What it is, who it applies to, and how Tickbox helps.

From Trust to Assurance: Practical Supply Chain Security for Leaders
Senior leaders don’t need convincing that cyber risk is real. What’s changed is how often it comes via third parties.

Risk Management Overview: What good looks like in practice
Risk management is often seen as a document – the risk register.

Know What You Have
Good cyber risk decisions start with knowing what you have and what matters most.
