Opens in a new tab
vmblog logo 2024 wht (updated)

RegScale CEO: How AI-Powered GRC Automation is Revolutionizing Enterprise Compliance and Risk Management – VMblog QA

Share: 

David Marshall | Published: October 23, 2024

    interview-regscale-howerton

    In an era where regulatory compliance and risk management have become increasingly complex, organizations are seeking innovative solutions to streamline their GRC (Governance, Risk, and Compliance) processes.

    VMblog recently sat down with Travis Howerton, Co-Founder and CEO of RegScale, to discuss the launch of RegScale 6.0 – a breakthrough platform that’s transforming how enterprises approach compliance automation. Fresh off winning the CyberSecurity Breakthrough Award for Compliance Software Solution Provider of the Year, RegScale is pioneering the use of AI and continuous controls monitoring to help organizations reduce audit prep time by up to 60% and accelerate certification timelines by as much as 90%.

    In this exclusive interview, Howerton shares insights into how RegScale 6.0 is addressing the pressing challenges of modern compliance management and why automated, real-time GRC solutions are becoming essential for businesses navigating today’s complex regulatory landscape.

    VMblog:  Tell me about the new RegScale 6.0 platform and what makes it stand out in today’s security and compliance landscape.

    Travis Howerton:  The 6.0 release of RegScale’s highly scalable solution is not just an upgrade but a significant, modernizing advancement in security, risk, and compliance through Continuous Controls Monitoring (CCM) and Governance, Risk, and Compliance (GRC) tools. The RegScale platform is laser-focused on transforming GRC outcomes by bridging security, risk, and compliance. RegScale 6.0’s near real-time solution furthers that mission with a streamlined interface, smarter AI, and intelligent workflows that boost operational efficiency, provide a comprehensive view of risk, and help organizations make better decisions with less burden on staff. RegScale 6.0 further reduces costs by simplifying risk management and supporting continuous, automated audit readiness, allowing organizations to focus on growing the business, not paperwork.

    VMblog:  What key benefits can organizations expect from using RegScale 6.0?

    Howerton:  Key benefits RegScale customers can expect in 6.0 include: 

    • Simplified risk management
    • Reduction in costs for obtaining and maintaining regulatory certifications
    • Accelerated time to market
    • Enhanced staff efficiency through the use of compliance-trained AI
    • Streamlined user experience further enhancing staff effectiveness
    • Extensive questionnaire workflow automations
    • Extreme automation powering complex workflows and integrations with critical cybersecurity, IT, DevOps, and other technologies

    VMblog:  How does RegScale 6.0 leverage automation and AI to reduce staff burden and costs?

    Howerton:  RegScale’s 6.0 compliance-trained AI and automation capabilities perform onerous, meticulous, and repetitive tasks prone to errors and inconsistencies when performed manually. RegScale’s compliance-trained AI, RegML, translates written policy statements into controls mapped to regulatory requirements in minutes instead of the days to weeks it takes to do it manually. Writing a single control statement can take an experienced staff member a few hours, whereas RegML can author a best practice control statement matching a specific regulatory framework in under a minute. While passing an audit is never guaranteed, with RegML Auditor, organizations can run an AI-based pre-audit against their controls, identifying potential areas for improvement and offering suggestions to enhance them.  

    The ability to continuously keep audit documentation up to date automatically removes the need to rely on other departments to provide evidence or update incidents, removing friction and conflict when answering audit requests. 

    VMblog:  In terms of risk management, how does RegScale 6.0 help organizations stay ahead of risks and ensure real-time compliance?

    Howerton:  RegScale 6.0 now supports a “bring your own risk model” approach, allowing organizations to define and assess against multiple models based on complex enterprise needs. It also automates the Risk Control Self-Assessment (RCSA) process end to end, tracks and trends changes in risk, and ensures that controls are operating as expected by integrating with continuous monitoring.

    RegScale 6.0’s Business Impact Assessment allows teams to view the impact of risk through different lenses. It also provides a comprehensive risk score of discrete implications across multiple business areas, giving organizations confidence that controls are mitigating risks properly. By using risk and control self-assessments, organizations can systematically track residual risks and proactively address changing threats. RegScale 6.0’s risk mitigation and treatment features keep all stakeholders updated through the lifecycle of the risk, while also keeping the required audit documentation updated automatically.

    VMblog:  Can you elaborate on the integrations featured in RegScale 6.0 and why they’re essential for organizations?

    Howerton:  Staying audit-ready requires automation, and RegScale 6.0’s API integrations enable the automation of evidence collection, issue tracking, reporting, and identity management. RegScale 6.0 can open tickets, stop code promotion, send alerts, and distribute real-time event updates between security tools, ensuring information is shared where needed and keeping documentation updated throughout.  

    RegScale 6.0 operationalizes real-time compliance and security, ensuring regulations are automatically enforced throughout the development lifecycle, from code creation to deployment and beyond. Our new low-code, no-code workflow system provides out-of-the-box integrations with over 450 commercial tools, offering industry-leading coverage to simplify and automate vulnerability management, configuration management, and other security workflows.  

    Manual intervention between systems is no longer necessary-RegScale’s extreme automation shrinks the window between discovery, response, and remediation, significantly improving security and compliance. 

    VMblog:  RegScale 6.0 reflects a larger story of growth for your company. Can you share some recent achievements and the momentum driving this innovation?  

    Howerton:  We’ve experienced tremendous growth this year, including being named Compliance Software Solution Provider of the Year at the CyberSecurity Breakthrough Awards and winning the SC Media Excellence Award for Best Compliance Solution. These recognitions validate our leadership in continuous controls monitoring and automation, helping customers reduce audit prep time by up to 60% and accelerate certification timelines by as much as 90%. Our OSCAL-native platform integrates compliance directly into DevSecOps workflows, making compliance both scalable and cost-effective. We’ve also achieved FedRAMP® High In Process and SOC 2 Type 2 certifications, leveraging our platform to generate and submit compliance packages at a significantly lower prep time and cost. In addition, our recent partnership with the Unified Compliance Framework (UCF) streamlines the compliance process even further, offering customers access to one of the industry’s most comprehensive compliance libraries. This momentum reflects the broader industry shift from manual processes toward automated, dynamic solutions. 

    VMblog:  What’s next for RegScale and your team in terms of innovation and future developments?

    Howerton:  Moving forward, we’re continuing to focus on expanding automation and real-time compliance. Our goal is to keep pushing the envelope in terms of scalability and efficiency, ensuring we continue to reduce the complexity and cost of GRC for both government and private organizations. 

    ##