Your AI disruption risk report is ready!
Issue 14, August 2026
This month: AI disruption risk scoring, now live in the platform, beta testers wanted for the ISO 27001 gap analysis, consultant or technology for AASB S2, and what's new in the GRC platform.
August 2026
We showed it at the briefings. Now it's yours to try.
Hi there,
Chris here. I look after business development for Drova across APAC, and I hosted our recent briefings in Melbourne and Sydney. I'm not generally known for being the quiet one.
Plenty has come to life since those briefings. One of the things we showed is now live, another is ready for keen testers, and there are fresh releases in the GRC platform.
If you couldn't make it along, we ran the online version too. Catch up on the recording.
Let's get into it!
Chris Robilliard, APAC Business Development Director
Now live: AI disruption risk,scored against your business objectives
Last month this was a 'keep an eye out'. Now it's ready.
Drova builds your risk picture from your size, industry, location and objectives, then scores every risk from 0 to 100 for how much of it is now AI-driven.
What you end up with is a clear view of which of your strategic objectives are most exposed, by how much, and which risk to deal with first. It all lands in a report made to be shared: an executive summary, your top five AI-driven risks in detail, and how they are affecting your objectives.
Start a free trial and it's waiting for you there.
Beta testers wanted
ISO 27001 Gap Analysis: let Sheila find the gaps against your framework
This is the one we demoed at the briefings. Sheila reads your documentation, maps it against the ISO 27001 requirements, and shows you where the gaps are.
The beta release gives you three ways to point her at it: connect AWS, connect Atlassian for Confluence and Jira, or upload your documents directly.
We'd love your feedback from running it on your own policies. You'd get early access and a say in how it gets built, and we'd learn how it fits the way you already work, which is the one thing internal testing can never tell us.
If that sounds like you, get in touch with our product team.
Consultant, or technology?Buy AASB S2 expertise, not admin
A lot of organisations are weighing up whether to bring in a consultant for AASB S2. The more useful question underneath it is what you'd be paying them for.
Consultant hours aren't cheap, and a good share of them tend to go on gathering evidence, chasing people for it, and formatting the result. None of that needs their expertise. That's the work Drova takes off their plate. The framework is already embedded, the evidence collects as you go, and the reporting cycle runs.
Your consultant spends their time on the judgement you hired them for, and what they know ends up in the system rather than in their notes. Which is what makes year two cheaper than year one. You're not paying to sit through the same workshops again.
Use the decision tree to see which plan fits, or get in touch if you'd like to talk it through for your team.
Other GRC enhancements
What's new in the Drova GRC platform
Control effectiveness gets its own story. Design and Operational Effectiveness now have their own label lists in Control Inventory, separate from Overall Effectiveness. You can rate a control three ways: overall, by design, and by how it runs, each with its own labels.
Sharper reporting. The Control Overview and Risk Hierarchy templates both gained new effectiveness sections, so it now reads the whole way down the tree.
Bulk updates. Two new Apply All buttons on Obligations, so compliance process and control updates go through in one go rather than one at a time.
Look and feel. Event Types can now carry their own icons, and the Portal page has been rebuilt with clearer cards, titles and styling.
Until next month
Everything above is there whenever you want a look, and a free trial is the quickest way to see it running on your own objectives. Any questions, you know where to find me.
Chris and the Drova team
Don't take our word for it. Try it out for yourself.