The new decade demands graduation to a new school of GRC, one which doesn’t just manage risk but constrains it. This talk will provide five steps to do just that. One, automate the detection of non-compliance as well as perform governance activities. Two, test once and comply many. Three, build chatbots to improve customer experience. Four, generate revenue. Finally, manage regulatory risk.