The AI Visibility Gap — Why 87% of Organizations Can't See Their AI Tools - ZServiceDesk Blog

The AI Visibility Gap — Why 87% of Organizations Can't See Their AI Tools

Only 13% of Organizations Have Full Visibility into AI Tools — The Governance Gap Is Widening Fast The Visibility Problem Drata's 2026 research on AI in GRC reveals a stark governance gap: only 13% of IT and security professionals have full visibility into the AI tools used in their organizations . A full 87% do not have complete visibility into the AI tools active across their business . This lack of oversight is contributing directly to operational and regulatory problems. The research found that 71% of organizations said an AI tool used for GRC had contributed at least once to a failed audit or a lapse in meeting a regulatory standard . Shadow AI: The New Shadow IT The biggest AI governance challenge is employees using unmanaged AI tools for productivity-related tasks without GRC oversight . By the time governance teams discover shadow AI tools, those systems may already be shaping customer communication, influencing hiring decisions, or processing sensitive data . High-risk actions that need prevention: Sensitive data copied into public AI tools Undocumented automated decisions Unreviewed AI-generated content sent externally Inconsistent answers across teams No audit trail for how outputs were produced The Vendor AI Problem The vendors you already approved are quietly becoming AI organizations. They are embedding models into products you procured for entirely different purposes. The vendor you assessed last year for CRM functionality now processes your customer data through an AI feature that nobody on your team signed off on . Why AI Governance Is Falling Behind Intent vs. Reality 69% of CISOs have allocated dedicated budgets for AI risk management in 2026. However, only 25% rate their governance maturity as advanced, and 39% have AI usage policies that exist on paper but are not consistently enforced . The Tooling Gap 86% of teams agree that many AI products aimed at GRC are not ready for large organizations, while 83% said they were not fully prepared for the next wave of AI integration . The Buyer Shift Some 64% of respondents said they would rather use targeted agentic AI systems than broad all-in-one platforms. That share rose to 70% among buyers focused on risk . "The horizontal AI platform era in GRC is over," said Matt Hillary, CISO and SVP of Security at Drata. "Buyers aren't waiting for the next generation of tools. They've moved their money toward agents that can prove specific, repeatable, and defensible outcomes" . Conclusion Without visibility, you cannot govern AI at scale. Organizations must establish a comprehensive view of all AI assets across the enterprise—including models, datasets, and agents—as a foundational step for AI governance . Action Items for Your Organization Conduct an AI discovery exercise to identify all AI tools in use Establish a centralized AI inventory Create AI usage policies and enforcement mechanisms Implement AI governance controls Monitor for unauthorized AI usage  
Read More 18 Jun 2021
Building an Audit Culture - From Compliance to Strategic Partner - ZServiceDesk Blog

Building an Audit Culture - From Compliance to Strategic Partner

Audits Are Not Just About Compliance — Build a Culture of Collaboration and Improvement The Audit Culture Shift Internal audit's mission remains the same—but the tools, capabilities, and expectations surrounding the function are changing faster than ever . Organizations are moving from viewing audit as a compliance obligation to seeing it as a strategic partner. Characteristics of a Strong Audit Culture 1. Risk-Aligned Assurance Audit plans adjust as risks evolve across the organization, providing assurance on what matters most . 2. Continuous Improvement The CAE must ensure and continuously improve the quality and performance of the internal audit function . Methodologies must be evaluated and updated as necessary . 3. Stakeholder Engagement The CAE should maintain regular, ongoing communication with the board, senior management, and other stakeholders to contribute to a common understanding of the organization's risks and objectives . 4. Collaboration The CAE must coordinate with internal and external providers of assurance services to minimize duplication of efforts . Building the Audit Culture 1. Communicate Value Demonstrate how audit contributes to organizational success. 2. Partner with Stakeholders Engage stakeholders throughout the audit lifecycle. 3. Focus on Solutions Offer recommendations that address root causes and improve operations. 4. Embrace Technology Use technology to provide better insights, faster. 5. Invest in People Develop auditors with the skills needed for the future. The Audit Manager's Role The audit manager role is critical to building audit culture. Responsibilities include : Planning, supervising, reviewing, reporting, and closing audits Managing stakeholder relationships Ensuring quality assurance and continuous improvement Leading engagement teams Navigating emerging issues and trends The Future Audit Team "The future audit team will likely consist of human expertise supported by AI-enabled analytics, automation, and intelligent workflows" . Key roles in the future audit team: Human auditors with domain expertise AI-enabled analytics specialists Automation and workflow experts Stakeholder relationship managers Conclusion Building an audit culture means moving beyond compliance to strategic partnership. Organizations that embrace this shift will achieve greater value from audit and stronger stakeholder relationships. Action Items for Your Organization Assess your audit culture Communicate audit value to stakeholders Partner with stakeholders throughout the lifecycle Invest in technology and people Measure stakeholder satisfaction Continuously improve
Read More 10 Jun 2021
Trend Analysis for Proactive Request Management - ZServiceDesk Blog

Trend Analysis for Proactive Request Management

Stop Reacting to Requests — Use Trend Analysis to Identify Problems Before They Explode The Power of Trend Analysis Trend analysis enables teams to clearly identify which types of service requests and inquiries are trending, enabling proactive resolution of broader issues . What to Look For Trend What It Means Action Spike in access requests New hires, role changes, or security issues Review onboarding process Increase in software requests New tools being adopted Review license management Rise in password resets Policy issues or system problems Review authentication Hardware requests increasing Growth or equipment lifecycle Review procurement How to Do Trend Analysis 1. Collect Data Gather request data over time — type, volume, patterns. 2. Identify Patterns Look for patterns: time of year, day of week, related events. 3. Investigate Causes When you see a pattern, investigate why it's happening. 4. Take Proactive Action Fix the root cause, not just the individual requests. 5. Monitor Impact Track whether your proactive action reduced the trend. Example: Trend Analysis in Action Observation: Password reset requests spike every Monday morning. Analysis: Employees forget passwords over the weekend and need resets Monday. Proactive Action: Implement MFA or passwordless authentication. Result: Password reset requests drop by 50%. Tools for Trend Analysis Tool Type Capability ESM platforms Built-in analytics and dashboards BI tools Advanced visualization and analysis AI/ML Automated pattern detection Conclusion Trend analysis transforms service request management from reactive to proactive. Instead of handling the same problems repeatedly, organizations can identify and fix root causes — reducing volume and improving service. Action Items for Your Organization Review your data — what patterns do you see? Investigate root causes of trends Take proactive action Monitor the impact Share findings with stakeholders
Read More 04 Jun 2021
The Future of Controls Management - Trends for 2027 and Beyond - ZServiceDesk Blog

The Future of Controls Management - Trends for 2027 and Beyond

AI-First, Continuous, Connected — The Future of Controls Management Is Here The Controls Transformation The future of controls management is AI-first, continuous, and connected. Organizations are moving from manual, periodic controls to autonomous, real-time controls. Key Trends 1. Agentic AI for Controls Agentic AI is reshaping controls management by enabling systems that can independently monitor, assess, and remediate controls . What this means: Self-healing controls that automatically correct themselves Autonomous control assessments Real-time anomaly detection Automated remediation workflows The implication: Organizations that adopt agentic AI for controls will achieve continuous compliance with minimal manual effort. 2. Continuous Monitoring Continuous monitoring is becoming the new standard. Organizations are moving from point-in-time assessments to real-time control monitoring . What this means: Always-on control visibility Immediate detection of control failures Real-time risk insights Automated alerting The implication: Organizations that implement continuous monitoring will be audit-ready at all times and detect gaps immediately. 3. Common Controls Frameworks Common Controls Frameworks are becoming mainstream. Organizations are rationalizing overlapping standards by mapping a single control to multiple requirements simultaneously . What this means: One control satisfies multiple requirements Consistent evidence across audits Reduced manual effort The implication: Organizations that implement CCFs will reduce manual administrative burdens by up to 33% . 4. Controls as Data Controls are becoming data-driven. Organizations are converting controls into measurable operational data (KPIs, KRIs, logs) . What this means: Controls are measurable Controls are testable Controls are auditable Controls are improvable The implication: Data-driven controls enable better decision-making and continuous improvement. 5. Integrated Controls Controls are becoming integrated with ITSM, security, and QA. Organizations are collapsing fragmented controls into a single data fabric . What this means: Risk-aware ITSM decisions Integrated risk management Connected controls Unified reporting The implication: Integrated controls reduce duplication and enable better decision-making. 6. Controls Rationalization Controls rationalization is becoming essential. Organizations are eliminating duplication and consolidating overlapping controls . What this means: Leaner control environments Reduced costs Improved assurance Stronger accountability The implication: Organizations that rationalize controls will reduce costs and improve effectiveness. The 2027 Controls Roadmap Timeframe Actions Now Assess current controls, identify gaps, define strategy Q3-Q4 2026 Rationalize controls, automate manual controls, implement continuous monitoring 2027 Implement agentic AI for controls, achieve integrated controls, continuous improvement Conclusion The future of controls management is AI-first, continuous, and connected. Organizations that embrace these trends will achieve more effective controls, reduced costs, and continuous compliance. Action Items for Your Organization Assess your current controls capabilities against future trends Build a roadmap for AI-first controls Plan for continuous monitoring Implement Common Controls Frameworks Convert controls to measurable data Integrate controls with ITSM, security, and QA Rationalize controls
Read More 22 May 2021
The Risk Register — Centralizing and Tracking IT Risks - ZServiceDesk Blog

The Risk Register — Centralizing and Tracking IT Risks

Garbage In, Garbage Out — How to Build a Risk Register That Actually Works What Is a Risk Register? A risk register is a formal, centralized repository that records and tracks identified risks. It serves as the single source of truth for risk information across the organization. Essential Risk Register Fields Field Description Risk ID Unique identifier for each risk Risk Description What is the risk? Information Asset What asset is affected? Threat What threat is the source? Vulnerability What vulnerability enables the threat? Impact What is the potential impact? Likelihood How likely is the risk? Inherent Risk Risk before controls Existing Controls What controls are in place? Residual Risk Risk after controls Risk Owner Who is accountable? Control Owner Who implements controls? Risk Treatment How will the risk be treated? Status Current status Review Date When was it last reviewed? Risk Register Best Practices 1. Keep It Current The IT risk register should be regularly updated . Outdated risk registers are worse than none at all. 2. Assign Clear Ownership Every risk should have a risk owner and a control owner . Without ownership, risks won't be managed. 3. Document Risks Clearly Include information asset description and classification, potential threats, impact and likelihood, existing controls, risk owner, implementation owner, and inherent as well as residual risks . 4. Link to Business Impact Every risk should be connected to business impact. Without business context, risk priorities are unclear. 5. Review Regularly Mission-critical and critical information assets should be assessed at least once a year . Common Risk Register Mistakes Mistake Consequence Outdated information Decisions based on obsolete data Missing risks Risks are not managed No ownership No one is accountable No links to business impact Unclear priorities No review schedule Register becomes outdated Risk Register and Audit The risk register should be: Documented and periodically updated in a formal centralized risk register  Regularly updated  Endorsed by the risk committee  Conclusion A well-maintained risk register is the foundation of effective risk management. Organizations that keep their risk registers current, assign clear ownership, and link risks to business impact will make better risk decisions. Action Items for Your Organization Build or update your risk register Assign clear ownership for each risk Link risks to business impact Establish a review cadence Use the risk register to guide risk decisions  
Read More 04 May 2021
IT Control Frameworks — COSO, COBIT, NIST, ISO 27001 - ZServiceDesk Blog

IT Control Frameworks — COSO, COBIT, NIST, ISO 27001

Headline: Which Framework Is Right for Your Organization? — A Complete Guide to Control Frameworks What Is a Control Framework? A control framework is a structured set of practices, principles, and guidelines that helps organizations design, implement, and assess controls. Frameworks provide a common language for controls management and ensure comprehensive coverage. A framework helps you: Identify what controls are needed Design controls effectively Assess control effectiveness Demonstrate compliance Benchmark against peers Major Control Frameworks Framework Primary Focus Best For COSO Internal control, enterprise governance Financial reporting, enterprise risk management COBIT IT governance and management IT processes, alignment with business goals NIST CSF Cybersecurity Cybersecurity risk management NIST SP 800-53 Security and privacy controls Federal systems, government contractors ISO 27001 Information security management Information security management systems COSO Internal Control Framework Overview: The Committee of Sponsoring Organizations (COSO) framework provides a comprehensive model for designing, implementing, and assessing internal controls. It is widely used for financial reporting controls and Sarbanes-Oxley (SOX) compliance. Five Components: Control Environment Risk Assessment Control Activities Information and Communication Monitoring Activities Key Principle for IT Controls: Principle 11 of the COSO framework states: The organization selects and develops general control activities over technology to support the achievement of objectives . Points of Focus: Determines dependency between the use of technology in business processes and technology general controls  Establishes relevant technology infrastructure control activities  Establishes relevant security management process control activities  Establishes relevant technology acquisition, development, and maintenance process control activities  COBIT (Control Objectives for Information and Related Technologies) Overview: COBIT is a comprehensive framework designed to assist organizations in managing their IT systems effectively . Developed by ISACA in 1996, it provides a structured set of best practices that enable managers and IT professionals to evaluate their current IT capabilities and develop strategies for enhancement . Key Features: Aligns IT goals with broader organizational objectives  Optimizes resource use and mitigates risks associated with unregulated IT operations  Organized into four main domains: Planning and Organizing (PO), Acquiring and Implementing (AI), Delivering and Supporting (DS), and Monitoring and Evaluating (ME)  Purpose: COBIT consolidates and harmonizes standards from diverse sources into a critical resource for management, users, and IT auditors . After two decades, COBIT's value is clear as a comprehensive business framework for the governance of enterprise IT . NIST Cybersecurity Framework (CSF) Overview: The NIST CSF provides a policy framework of computer security guidance for how private sector organizations in the United States can assess and improve their ability to prevent, detect, and respond to cyber attacks. Five Functions: Identify Protect Detect Respond Recover ISO 27001 Overview: ISO 27001 specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS). Annex A Controls: Provides a reference set of security controls (114 in the 2013 version) that organizations can select and implement. How to Choose a Framework If Your Organization… Start With Consider Adding Is a government contractor or federal agency NIST SP 800-53 NIST CSF for cybersecurity Needs financial reporting controls COSO COBIT for IT processes Needs ISO 27001 certification ISO 27001 NIST CSF for maturity benchmarking Manages IT governance COBIT COSO for enterprise governance Is a mid-market company starting from scratch NIST CSF 2.0 COBIT or ISO 27001 as you mature Many mature organizations layer frameworks rather than choosing just one. A common approach is COSO for enterprise governance, COBIT for IT management, and NIST CSF for cybersecurity operations. Conclusion Frameworks provide a structured approach to controls management. They offer common language, comprehensive coverage, and benchmarks for maturity. Organizations should select frameworks based on their regulatory requirements, industry, and maturity. Action Items for Your Organization Assess your regulatory and industry requirements Evaluate which frameworks are relevant to your organization Select a primary framework Consider layering frameworks for different purposes Map existing controls to the chosen framework  
Read More 11 Apr 2021