EPISODE · Jun 2, 2026 · 53 MIN
Beyond Checkbox Compliance: Why GRC Must Become an Engineering Discipline ft Sheron Chakalakal, Head of GRC @ UiPath
from Security & GRC Decoded · host Raj Krishnamurthy
In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with Sheron Chakalakal, Head of GRC at UiPath, to explore why the future of GRC looks far more like systems engineering than traditional audit management.Drawing from his experience at Salesforce, Deloitte, and UiPath, Sheron explains why point-in-time audits and checkbox compliance are failing modern engineering organizations — and why risk-driven, continuously monitored GRC programs are becoming essential. The conversation dives into AI governance, continuous risk monitoring, customer assurance, GRC engineering, AIUC-1, and how security, compliance, and engineering teams must evolve together.This episode reframes GRC as a technical reliability function that helps companies reduce operational risk continuously instead of simply passing audits once a year.Key Takeaways:Modern GRC programs must evolve from audit functions into engineering-driven reliability functions.Risk—not compliance—should be the central language for communicating with leadership teams.Continuous controls monitoring is essential because point-in-time audits create “checkbox theater.”AI governance requires technical evaluations, agent testing, and continuous assurance beyond traditional frameworks.Future GRC leaders will need technical depth, business context, and the ability to bridge engineering with executive leadership.What You’ll Learn:Why Sheron believes compliance should be designed into products from day oneHow UiPath approaches continuous risk monitoring and GRC engineeringWhy AIUC-1 introduces a fundamentally different approach to AI assuranceHow GRC teams can become the “translation layer” between business and engineeringWhy future GRC practitioners must develop technical and systems-thinking skillsThis podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.comWatch more episodes: https://www.compliancecow.com/podcastConnect With Our Guest:Sheron Chakalakal | Head of GRC | UiPathConnect on LinkedIn: https://www.linkedin.com/in/sheronpaulc/Rate, review, and share if you enjoyed the show!Subscribe to Security & GRC Decoded wherever you get your podcasts:Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683Apple Podcasts: https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
Embed this episode
What this episode covers
In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with Sheron Chakalakal, Head of GRC at UiPath, to explore why the future of GRC looks far more like systems engineering than traditional audit management. Drawing from his experience at Salesforce, Deloitte, and UiPath, Sheron explains why point-in-time audits and checkbox compliance are failing modern engineering organizations — and why risk-driven, continuously monitored GRC programs are becoming essential. The conve...
NOW PLAYING
Beyond Checkbox Compliance: Why GRC Must Become an Engineering Discipline ft Sheron Chakalakal, Head of GRC @ UiPath
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.