top of page
BLOG
Compliance Principles, Practices, & Insights


The Three Dimensions of Strategic Alignment in Compliance
Three Dimensions of Strategic Alignment in Compliance I've spent enough years in regulated industries to see the same pattern everywhere:...


When Culture Fails
Organizations spend a lot of time talking about culture. Safety culture, quality culture, risk culture. We create frameworks, run...


Double Your Capacity to Deliver Total Value
Taiichi Ohno's Secret to Delivering Total Value To understand this approach, we need to return to the origins of LEAN manufacturing when...


When Automation Hides Waste
Applying Lean to Digital Waste The digital transformation has fundamentally changed how work gets done, but it has also created a new...


Which is Better for AI Safety: STAMP/STPA or HAZOP/PHA?
STAMP/STPA and traditional PHA methods like HAZOP represent fundamentally different safety analysis philosophies. STAMP/STPA views...


You're Not Managing Risk—You're Just Cleaning Up Messes
Imagine you're a ship captain navigating treacherous waters. Most captains rely on their damage control teams—when the hull gets...


GRC Engineering: The Need for Practice Standards
When it comes to GRC systems, there can be a significant gap between what gets implemented and what's actually needed to achieve the...


Closing the Compliance Effectiveness Gap
Compliance Effectiveness Gap Compliance has been heading in a new direction over the last decade. It's moving beyond paper and procedural...


AI Engineering: The Last Discipline Standing
The software engineering and related domains are undergoing their most dramatic transformation in decades. In discussions I have had over...


AI's Category Failure
When a technology can reshape entire industries, automate critical decisions, and potentially act autonomously in the physical world, how...


Does Your AI Strategy Pass the Ketchup Test?
A simple test to bust through the hype These days, AI providers, leaders, and evangelists claim that AI technology will transform any...


Lean Compliance: A Founder's Reflection
Lean Compliance Reflections I often think about the future of Lean Compliance, especially lately as I feel compliance is approaching a...


Understanding Operational Compliance: Key Questions Answered
Operational Compliance Organizations investing in compliance often have legitimate questions about how the Operational Compliance Model...


ERP vs GRC: Feed-Forward vs Feed-Back Systems
The distinction between Enterprise Resource Planning (ERP) and Governance, Risk, and Compliance (GRC) platforms reveals a fundamental...


Promise Architectures: The New Guardrails for Agentic AI
As AI systems evolve from simple tools into autonomous agents capable of independent decision-making and action, we face a fundamental...


Engineered Compliance: Mapping Obligations to Outcomes in Regulated Industries
By Raimund Laqua, PMP, P.Eng., Founder and Chief Compliance Engineer at Lean Compliance I've spent 30 years in the trenches of...
bottom of page
