
AI has moved from an experimental technology to a part of the infrastructure that organizations rely on to complete everyday work. ISACA notes that this shift changes the risk equation because AI systems can produce evolving outputs, experience data drift and create new dependencies throughout their lifecycles. Governance, risk and compliance (GRC) teams must now determine how to support enterprise-wide AI use without weakening the accountability, accuracy and documentation their work requires.
The pressure to make that transition is growing, but enterprise readiness remains uneven. KPMG’s Global AI Pulse found that 95% of surveyed organizations have an AI strategy, yet only 8% have established a return on investment in the technology. These findings point to a widening gap between interest in AI and the organizational conditions required to produce dependable value at scale.
Manual Work Is the Most Practical Starting Point
GRC programs depend on stable processes surrounding evidence collection, documentation, assessments, control reviews and follow-up with stakeholders. These responsibilities create the records organizations need to prove compliance and explain risk decisions, but completing them can consume time that practitioners could otherwise spend interpreting findings or advising leadership.
Research from Microsoft illustrates how this administrative burden affects the broader security function. The 2026 State of the SOC research found that 66% of security operations centers lose at least 20% of the workweek to manual data aggregation and correlation. Although security operations and GRC have different responsibilities, both functions suffer when practitioners must first gather and reconcile information before applying their expertise.
AI can provide near-term support by summarizing records, categorizing evidence, identifying missing information and directing reviewers toward items that require attention. Starting with these defined activities allows teams to compare outputs against existing documents and keep practitioners responsible for the final determination. It also creates a controlled path for testing whether AI reduces administrative effort without introducing unacceptable risk.
Fragmented Workflows Create a Readiness Gap
Many of the barriers to AI adoption originate outside the technology itself. Evidence may be stored in one system, remediation plans in another and ownership information in spreadsheets, inboxes or project management tools. Each handoff can introduce delays, duplicate effort and make it harder to determine whether the information supporting an AI-generated output is complete or current.
PYMNTS Intelligence discovered that 71% of executives identified their organization’s people, processes or data readiness as the greater constraint on AI performance, while only 11% pointed to the technology itself. That distinction is important because adding AI to one step in a disconnected process may produce an answer faster without improving the reliability of the underlying work.
GRC modernization must therefore address the workflows surrounding AI. Teams need authoritative data sources, clearly assigned owners, and consistent procedures for reviewing findings and escalating exceptions. AI is more likely to remain confined to pilots when practitioners cannot trace the information behind an output or explain how it influenced a decision.
Governance Must Reach Daily Operations
Written AI policies are becoming more common, but formal guidance cannot govern systems on its own. Practitioners need to understand how those policies apply to their work, especially when AI processes sensitive information or contributes to risk and compliance decisions.
The National Institute of Standards and Technology treats governance as the foundation for identifying, evaluating, and responding to AI risk. Rather than separating policy from execution, its AI Risk Management Framework connects accountability to how organizations assess systems and oversee their use.
ISACA also emphasizes governance throughout the AI lifecycle. That approach recognizes that risks can change after deployment as systems are updated, connected to new data, or used for different business purposes. Organizations, therefore, need recurring reviews rather than relying on a one-time approval.
Healthcare Raises the Stakes
Continuous governance carries additional weight in healthcare because AI may interact with protected health information and technology that supports patient care. A failure involving confidentiality, system integrity or availability can create regulatory exposure and disrupt essential operations.
The Health Sector Coordinating Council’s 2026 AI Cybersecurity Governance Framework recommends integrating AI oversight into existing security and risk practices. This approach helps healthcare organizations manage AI through the controls and responsibilities they already use rather than creating a separate governance structure with unclear ownership.
AI governance also requires coordination across departments. The people responsible for security, privacy, compliance and operations need a shared understanding of where AI is used, what information it can access, and how its outputs affect decisions. Clear ownership makes it easier to respond when a system changes or behaves unexpectedly.
Third-Party AI Requires Continuous Oversight
Third-party risk management provides a clear test of whether existing GRC processes are prepared for wider AI adoption. Healthcare organizations may rely on external platforms with embedded AI capabilities while having limited visibility into how those systems are trained, updated or connected to other providers.
The Health Sector Coordinating Council has warned that incomplete third-party inventories and limited supplier disclosures can obscure AI-related exposure. Its guidance calls for closer examination of how a third party uses AI may change over time, along with business associate agreements that provide sufficient transparency to identify dependencies and emerging risks.
That visibility should extend beyond the contracted provider to the downstream third parties and systems. A control failure or change at one of these parties can cascade across the supply chain, creating privacy, compliance and operational exposure even when the organization has no direct relationship with the source of the risk.
The broader threat makes that visibility more important. IBM’s 2026 threat research found that major supply chain and third-party breaches quadrupled over five years, highlighting how a single compromised provider can affect multiple organizations.
Initial questionnaires and onboarding reviews remain useful, but they cannot capture every change that follows approval. New system connections or AI capabilities can alter exposure, requiring GRC teams to maintain current vendor information and document how emerging concerns are addressed.
AI ROI Begins With Operational Results
Organizations may struggle to prove AI’s value when they begin with broad expectations of financial savings rather than a defined process problem. KPMG’s findings suggest that enterprise investment has moved ahead of measurable returns, making it important for GRC teams to establish what improvement should look like before launching a pilot.
Early value may appear through faster reviews, reduced follow-up or more timely risk reporting. Organizations can also examine whether AI reduces the effort required to validate information and improves the quality of subsequent decisions.
These indicators provide a practical basis for determining whether an initiative is ready to expand. They also help leadership evaluate AI by its impact on work rather than by adoption rates or the number of tools in use.
Moving From Pilots to Practical Use
The next stage of GRC modernization will depend less on how quickly organizations acquire AI and more on whether they can apply it within dependable processes. The strongest starting points will be workflows where teams understand the existing burden, trust the underlying information and know who is responsible for reviewing the result.
As confidence grows, organizations can expand AI based on evidence that it improves accuracy, efficiency or decision support. For healthcare information security and compliance leaders, strengthening these foundations now will create a more credible path from isolated pilots to AI-supported GRC work that is accountable and defensible.

