GRC was "box-ticking." Now it's strategic risk management.
A few years ago, GRC professionals were known for writing policies nobody read and running audits nobody cared about. Compliance was a cost centre, not a strategic function.
That era is ending — rapidly.
Malaysia's DPDPA amendment, BNM's Risk Management in Technology (RMiT) requirements, SEC cybersecurity disclosure rules, and the EU's NIS2 and DORA directives have made risk and compliance a board-level issue. Boards are now asking direct questions about cyber risk exposure. Organisations without credible GRC functions are failing audits, losing enterprise clients, and facing regulatory fines.
GRC professionals who can navigate this complexity are being pulled into strategic roles.
What Changed, and Why
Regulatory complexity increased dramatically. A Malaysian financial institution now manages compliance across: BNM RMiT, BNM JIS (Joint IT Standards), PDPA/DPDPA, Bank Negara's CPS (Cyber Policy Standards), potentially MAS Technology Risk Management Guidelines if they operate in Singapore, and ISO 27001 if they pursue certification. Each has different requirements, timelines, and evidence standards.
Boards got serious about cyber risk. Post-pandemic breaches, ransomware waves, and regulatory enforcement actions made cybersecurity a board agenda item, not just an IT problem. GRC professionals who can translate technical risk into business language are now presenting to audit committees.
Third-party risk became unmanageable at scale. Supply chain attacks (SolarWinds, MOVEit) demonstrated that organisations' risk extends to every vendor, supplier, and cloud provider. Vendor risk management is a growing GRC subspecialty.
What GRC Actually Looks Like Day-to-Day
The reality of GRC work varies significantly by sector:
In a bank or financial institution (most common in Malaysia):
Managing ISO 27001 and BNM RMiT compliance programmes takes the majority of your time. This involves maintaining evidence libraries, coordinating control assessments across IT teams, preparing for regulatory examinations, and running quarterly risk committee meetings. Vendor risk reviews for significant outsourcing arrangements are a constant.
In a tech company:
SOC 2 Type II audit coordination, PDPA privacy impact assessments for new product features, and security review of new vendor onboarding. The pace is faster and the scope is broader than in banking.
In a consultancy:
Client-facing work — gap assessments against frameworks, policy drafting, framework implementation support, awareness training. You see a wider variety of industries and maturity levels.
The Skills That Actually Matter
GRC is the cybersecurity domain where soft skills matter as much as technical ones. This isn't a weakness — it's a differentiation.
You need: strong analytical writing, the ability to translate technical concepts for non-technical audiences, structured thinking for complex regulatory requirements, and attention to detail that a controls evidence file demands.
You don't need: penetration testing skills, advanced coding ability, or deep protocol-level networking knowledge (though a working understanding helps).
The AI Governance Opportunity
AI governance is creating an entirely new GRC subspecialty. As organisations deploy AI systems, they need professionals who can assess AI risk, design AI governance frameworks, manage AI model inventories, and comply with emerging AI regulations (EU AI Act, Malaysia's proposed AI governance framework).
Almost no one has this experience yet. Getting in early is valuable.
If You Have a Non-IT Background
Finance and accounting professionals: your risk assessment and audit skills map directly to GRC. You understand control testing, evidence standards, and how to present risk in business terms.
Legal and compliance professionals: regulatory interpretation, policy drafting, and compliance programme management are core GRC competencies. Your skills transfer.
IT operations and helpdesk professionals: you understand the operational technology environment. Building on that with GRC framework knowledge (ISO 27001, NIST) is a clear path into security GRC.
Our GRC Coaching Track is designed specifically for those entering or advancing in GRC roles in Malaysia and the region. Coached by Lavanyah Prabu, who has hands-on GRC experience across financial services.
Ready to Apply This in Your Career?
LumaShift helps you turn insights like these into tangible career progress. Let's talk about where you are and where you want to be.