High Signal Podcasts Evidence ledger
Method
Browse
← Back to evidence

Evidence receipt / evaluation

Published · transcript-backed

John Collison: evaluation

31 Mar 2026 Cheeky Pint Compliance at scale and why TAM is a distraction with Christina Cacioppo of Vanta

“Yeah, I think what you're saying is there's a strategy component to how should we be doing things, and then there's an hourly labor component to compliance, which is like, "Oh, we did 10 times as many sales.”

— John Collison

Source trail

Everything needed to verify it.

Speaker
John Collison
Attribution
Verified speaker
Claim type
evaluation
Recorded
31 Mar 2026
Publisher
Cheeky Pint

Transcript context

…Exactly. If you can give them good tools, they can do that. Okay, fine. Then again, pre-AI, but then over time, that team starts to grow, and then you have a GRC team, and you have CISO, and all this. What we're talking about now, and we haven't seen yet, but if I had to future cast and guess, is we're going to see those GRC teams collapse a bit more into these single-threaded owners. Because you think of a GRC team today, there's maybe one person answering questionnaires, one person just reviewing new software vendors. You look at those, and you're like, "Okay, I think you can agent the work and then have someone oversee it with 20% of your time." But like, okay, great, you've collapsed two into 40%. You have some person who's responsible for bothering the engineers to get evidence for them for the audit or to get the control in place because they don't own the control, but they own the program, so they have to go to the engineer and be like, "Hello, I noticed you have a new database that is not encrypted. Will you please encrypt it?" You're like, you can just have software go nag that person. Anyway, it collapses. I do think we will seek smaller GRC teams managing agents, but actually in the future. Then they are doing more. I'm not doing the security reviews. I'm thinking about the findings and overall managing this risk portfolio, this vendor risk portfolio, versus being like, "Oh, this vendor doesn't have this thing, and I need to go get it from them." Yeah, I think what you're saying is there's a strategy component to how should we be doing things, and then there's an hourly labor component to compliance, which is like, "Oh, we did 10 times as many sales. We need 10 times as many bodies on the security reviews." You're saying that AI will eat up a lot of the hourly labor part of compliance and leave people doing the strategy work. Yes, I do think that.…

Stored transcript either side of the excerpt. The highlighted words are the published quote; the surrounding text is unedited source, never generated.

Search evidence