GRC Articles & Analysis
Practical advice, regulatory analysis and expert guides for Canadian GRC professionals.
Recent articles
Security incident management under Law 25: obligations and best practices
Since September 2023, Law 25 has imposed strict obligations on Quebec organizations regarding privacy incident notification. An unreported or poorly managed incident can result in
ISO 27001 vs SOC 2: which certification should your Canadian organization choose?
Facing increasing security requirements, many Canadian organizations must choose between ISO 27001 and SOC 2. Both certifications address similar objectives but target different ma
How to map your information assets in compliance with Law 25
Information asset mapping is the foundation of any effective GRC program and a Law 25 requirement to demonstrate that you know what personal information you hold.
All articles
(13)DORA: how Canadian companies with European operations must prepare
The European DORA regulation came fully into force on January 17, 2025. Canadian financial institutions offering services in Europe or collaborating with European entities are dire
The 10 essential risk indicators for your CISO dashboard
An effective GRC dashboard is not measured by the number of indicators displayed, but by their relevance to decision-making. Here are the 10 KRIs that every CISO should monitor as
NIS2 and the Canadian public sector: anticipating new digital resilience requirements
The European NIS2 directive came into application in October 2024. Its implications affect Canadian organizations partnering with European entities in critical sectors.
Artificial intelligence and GRC internal audit: opportunities and risks for Canadian organizations
Artificial intelligence is profoundly transforming internal audit practices. AI tools enable analysis of massive data volumes and anomaly detection, but also introduce new risks.
Complete Guide to Law 25: Obligations and Compliance
Everything you need to know about Quebec's Law 25: obligations, timelines and practical steps to bring your organization into compliance.
How to Conduct a Risk Assessment for an SME
Practical method to identify, assess and treat security risks in a small or medium-sized enterprise.
DPIA: Practical Guide for Privacy Officers
How to conduct a Privacy Impact Assessment compliant with Law 25, step by step.
5 Common Mistakes in GRC Internal Auditing
The most frequent pitfalls in internal audit programs and how to avoid them to gain efficiency.
Managing Multiple GRC Frameworks Simultaneously
Strategies to align ISO 27001, Law 25 and PCI-DSS in a unified GRC program without duplicating efforts.
ISO 27001 Certification in 6 Months: Lessons Learned
How a Quebec SME obtained its ISO 27001 certification in 6 months with CapGRC.
PCI-DSS v4.0: What You Need to Know
Analysis of the major changes in PCI-DSS version 4.0 and their impact on Canadian organizations.
Understanding DORA: The European Digital Resilience Regulation
Complete guide to the Digital Operational Resilience Act (DORA): scope, obligations and impact on Canadian financial institutions.
Understanding PIPEDA: Canada's Federal Privacy Law
Complete guide to the Personal Information Protection and Electronic Documents Act (PIPEDA) in Canada.
Go further with CapGRC
Discover all our guides, templates and webinars to structure your GRC program.
