Drata’s Matt Hillary on AI’s Role in Compliance and Governance

Written By
James Maguire
James Maguire
Jan 16, 2025
1 minute read

Transcription

hi I'm James Maguire and on today's webcast we're talking about how artificial intelligence will impact governance risk and compliance programs to discuss that I'm joined by Matt Hillary vice president of security and chief information security officer at drada Matt great to have you with us today thanks for having me James great to be here I've learned a ton from the past interviews you've done with other Professionals in the space feel really lucky to be here with you great all right so I think we're in an era when companies are trying to get practical with their AI deployments it's it's not just magic pixie dust anymore they want to get in there want to make sure something really works and so part of that is heading off problems before they begin so so what are the specific problems with governance risk and compliance that AI can address you know that's a great question to start with as I think about the governance risk and compliance Spas we have a number of manual processes that we've been operating for a number of years at this point and you know with the very accessible AI capabilities that we have today I can't think of a better industry where AI can really impact the day-to-day operations that these TRC team members face uh we can go into a number of use cases where this might be the case but uh having been born in this governance risk and compliance space myself seeing the highly uh manual processes backed by spreadsheets shared folders screenshots uh emails whatever it may be to track a lot of the activities we have it's so cumbersome so painful and uh we've already totally revolutionized the space at our organization introducing a lot of automated platforms to support organizations it is so cool to see what the next step is going to look like with AI backing all of these capabilities so really you're you're saying in Ence that those automated processes are are supported by artificial intelligence not some are at this point I think we're taking that next step if we to look back they started highly manual I think we're moving we've already moved into the highly automated space when I think of automation I think of very static uh parameters that are used to detect and alert and let you know when things are there right now we have a lot of programmatic interfaces where we can pull data and run tests against those those tests again are very um uh static and specific now with AI it's amazing to be able to have well-trained models that take it beyond that to reduce a lot of the noise that we get to help facilitate a lot of analysis and response on what you might see from a a very educated human on what may come across the wire and so it's the two words that I like to use related to AI infiltrating our world in a good way is it augments and accelerates all of our activities and I think that's a very very good way to describe it here in the GRC space all right so so companies are are they're getting involved with a GRC space or using AI what's a headache that they would come across what's Difficult about this process in terms of what's a core challenge oh man um I'm not sure if you had a chance to use chat gbt or similar capabilities yourself yes it's very very cool to be able to have these prompts where you can put questions in and get answers back now when we think about you know our organization is built on uh providing the the facilitation for organizations to have trust built between those organizations and um in many ways that's done by question and answer and so when you think about these large language models where you're posing a question and getting an answer we use that same capability in our own platform and I'm seeing more and more of this in this space to help facilitate that conversation now um you know in our case uh sometimes when we go buy a SAS product from another organization we have a number of questions sometimes I've seen organizations pose over 400 questions sometimes about their security compliance privacy uh other availability practices there's a lot that goes into that due diligence I really appreciate this space because it's it's the way we we truly build trust between humans and organizations by asking questions and as transparent as we can be is where I think that's Comm with the amount of trust that we can build with those organizations and so what a great way and usage of llms now in dra or other GC tools we actually house a ton of information about their security compliance risk oh availability programs whatever it may be we are able to load that data behind a well-trained large language model and then populate many of these 400 plus question questionnaires that would usually take a human sometimes days if not you know multiple hours just to populate the question we want to make sure the answers are right we want to make sure the answers are understandable so we'll take a lot of time answering those individually sometimes we have to go back and think man this is the same question we got asked by this other customer what's the answer how do we do it well there uh now with AI and a well-backed llm we're able to populate most of those many questions posed with solid strong answers we are still in the phase I think in the industry where we have to go and validate the output we're still not at that point where we can trust it whole you know wholesale and say you know let's go and send us to the customer to answer their questions so we still have a human that goes through and verifies that but that's been taken down to the minutes instead of the hours taken to write it then review it then send it so really accelerating deal Cycles really emboldening people with knowledge now there's a receiving end of these questions too Jane so you think about their ability to review the answers to 400 plus questions now in our platform we built the ability to ingest all of the answers and really look for those call outs that might be concerning when you know you're evaluating whether or not you should purchase so that's one of oh man I we can keep going but there's that's one of many that we've already accelerated deal cycles and a trust between organizations so that's all right that's a that's a solution I mean and what else terms of a solution I I was wondering what what would be a challenge I guess the challenge I'm hearing you say is perhaps it's a it's a lot to automate it's a lot to streamline um what what ultimately do you think is is going to solve the problem if if there is such a thing no totally you know when I think about AI the backbone of AI you've got infrastructure you got data and then you've got a model that's well trained and so applying th those fundamental principles in the GRC space we load the data so that's the solution is we load the data about the organization the models what we train to basically take that information and and communicate it in such a way that the receiving organization can then make a decision on it and so the problem there is man the amount of hours the pain the human effort that goes into it the time spent uh to answer these questions we are that's the problem and then that's you know something sometimes organizations you especially at the end of the quar the last few days and answering these questionnaires can really compact uh the amount of hours a human spends on that is notable and material so that's the problem the solution is accelerating that to the point where we can use humans where humans are most are used best which is reviewing these outputs and being able to send that off instead of having to craft the raw underlying answer so that's the solution here that exists yeah we think with with governance and compliance AI can play a key role but it feels to this day that humans are still probably playing the larger role and and and will be for some time agree or disagree I 100% agree and and the way I usually communicate this is we still need the humans to her the Bots and I think that's the case with automation uh when a problem is presented to me or my peers we have two choices we can throw a number of you know capable humans at the problem or we can throw both with a significant augmentation of automation or tools or capabilities now in that tool chest we have that powerful AI capability to then further augment but the humans are still going to need to be there to direct to validate to um you know use to hone to train all of these are creative nature our ability to see things at a bigger larger perspective I don't think that's ever going to be replaceable in a material way in our foreseeable future so 100% agree with you that we will still need very capable and amazing humans to monitor the capabilities that AI is providing but also with the purpose of uh you know continue to accelerate our ability to do more and more individually and collectively that makes perfect sense definitely well you I'd like to look at the the future of artificial intelligence at GRC I think it's a it's a key area because is companies want to be getting ready now for the future so if you look ahead say oh you know 1 to three years or so what do you see for the future for artificial intelligence and and and GRC oh man uh I think the future is bright I think we're only at the beginning what the capabilities exist to us now I was talking with some peers last night uh just uh thinking of different ways AI can continue to augment various areas of the security space not even just the DRC space but security the Privacy space the trust space uh our day-to-day I think many of us are still the beginning of thinking through how we reroute our own brains instead of going straight to a search engine to ask for answers we're starting to go straight to a very capable llm and so uh with that I think the future is bright I think this first year is going to be the the year of where does AI make the most sense and they almost are looking at a point solution approach when I look at GRC I was actually summarizing I actually used AI to do this like give me a simple boled list of all the simple responsibilities that you know are supporting a GRC that the GRC member does does some of these may go into 20 to 30 uh different items now as a ceso I probably have a 100 different items I think if there's a list out there to say what is a c so responsible for it is overwhelming and I think about all these individual items that are there uh so this first year is identifying some of the most painful aspects there where we can then augment with a capable large language model or other AI backed capability to accelerate security questionnaire automation is one of literally uh a number of other items that we can look at I was looking at the list here I was like oh man uh one that comes to mind is we have a number of new control Frameworks that come out and continue to iterate and so a human usually has to go read that and say what are the Deltas between today and what this new standard wants us to do uh no better solution than using uh cable LM to summarize that tell you where your gaps are make a list to go through that even suggest ways to augment and fix those things uh is kind of what we're seeing now so again a number of those things so I think the first year is finding which are the most painful areas to then uh apply these capabilities I think in 3 years time we're going to have uh more and more what uh I think what large organizations are coming out with now an entire assistant to really support us when you think about an assistant uh you know supporting us in our day-to-day activities they need to know everything about us they need know everything about our tools and our state to really provide that suggestions that level of suggestion we need to to further there so when I think about um three years time I think we're going to have a full-on capable uh assistant level capability with not just the point Solutions but a holistic approach to helping accelerate all of our day-to-day activities Beyond just this space so um really really bright and excited future there for for AI supporting us that is fascinating Matt that's really neat the the idea of agentic AI basically doing GRC that makes seems like it would be a natural natural direction for the industry uh thank you so much for sharing your expertise today it was great I learned a lot and uh please come back and talk with us again some on thatt of course James thanks for having me I always love what you do thanks for what you're doing please continue so we can all learn together thanks again for having me thank you all right

This transcript was generated automatically from the video's captions and may contain errors.

eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Matt Hillary, VP of Security and CISO at Drata, details problems and solutions as AI plays an expanding role in governance, risk, and compliance (GRC).

Watch the video:

James Maguire

James Maguire has been reporting on emerging technology for more than 15 years. He has won two ASBPE Awards of Excellence for in-depth feature articles about cloud computing and artificial intelligence. He has covered the gamut of enterprise and consumer technology, and regularly communicates with leading IT newsmakers, vendors and analysts.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.