What does responsible AI actually look like once you move beyond the headlines and start deploying it inside highly regulated businesses?
In this episode, I speak with Richa Kaul, Founder and CEO of Complyance, about one of the biggest challenges facing enterprise AI today: building systems that people can trust. As companies race to adopt AI across every part of the business, governance, risk management, and compliance are no longer back-office functions. They are becoming central to every conversation about innovation.

Richa shares the personal experiences that inspired her to build Complyance, from her work in public sector technology and legal AI to her long-standing passion for data privacy. We discuss why trust has become one of the defining themes of enterprise AI and why businesses must think beyond their own AI initiatives to also understand the risks introduced by third-party vendors.
One of the most interesting parts of our conversation focuses on the difference between compliance and risk. Rather than viewing compliance as a box-ticking exercise or a cost center, Richa explains why AI has brought risk discussions directly into the boardroom. Business leaders are now asking deeper questions about how customer data is handled, how AI decisions are governed, and what safeguards need to exist before new technologies are deployed at scale.
We also explore how AI is changing governance itself. Traditional compliance has often relied on manual reviews and simple pass-or-fail checks, but Complyance is applying agentic AI to introduce greater context and human-like judgment into governance workflows. Richa explains how that approach is helping reduce manual effort while allowing teams to focus on higher-value risk decisions rather than repetitive administrative work.
Our conversation also covers practical advice for companies introducing AI into regulated environments. From evaluating third-party vendors and defining acceptable risk thresholds to adopting emerging AI standards and maintaining transparency throughout the process, Richa offers thoughtful guidance for leaders trying to balance innovation with accountability.
Along the way, we also discuss Complyance's recent $20 million Series A investment led by Google Ventures and what that recognition means for the company's mission to modernize governance, risk, and compliance with AI.
If your business is investing in AI while trying to strengthen trust, transparency, and responsible innovation, this episode offers a timely look at how governance is evolving alongside the technology itself.
As AI becomes embedded into more business processes, how is your company building trust while still giving teams the freedom to innovate?
Useful Links
Connect with Richa Kaul

[00:00:00] Your agents aren't producing accurate answers because they don't have a complete semantic understanding of your data. And Denodo is solving this and solving it through semantic consistency. Through semantic consistency, your agents can start making accurate predictions in real time. So see what else Denodo can do by visiting denodo.com to learn more. But now let me introduce you to today's guest.
[00:00:32] Welcome back once again to the Tech Talks Daily Podcast. And today, once again, we're going to explore how AI is reshaping the way we build, lead and make decisions inside modern organizations. And my guest today is the founder and CEO of a company called Compliance.
[00:00:52] And they are an AI-powered GRC platform that is helping some of the world's most complex enterprises automate governance, risk and compliance. All while still moving at the speed that innovation now demands. Because the reality is this. The faster AI moves, the more important trust, transparency and accountability become. And I know that's not always the most exciting of conversations. But today, we're going to change that.
[00:01:22] Because we're going to talk about responsible AI, what that looks like in practice. How compliance is shifting from a reactive cost center into a strategic function. And why third-party AI risk is a blind spot that many leaders are still underestimating. And what ethical AI actually looks like when you're building inside your organization. And we're also going to cover today some pretty big news. I don't want to reveal any spoilers there. But it's a big time at compliance this week.
[00:01:50] So, I want to talk about that and why that validation that they've recently received means so much more than a market full of noise right now. So, in a nutshell, if you're trying to balance innovation with guardrails and move fast without breaking customer trust, you're going to love this one. But enough from me. Let me introduce you to my guest right now. So, a massive warm welcome to the show.
[00:02:17] Can you tell everyone listening a little about who you are and what you do? Absolutely. Happy to. I'm Richa Call. I'm the CEO and founder of Complyance. We're an enterprise GRC platform that really helps the biggest companies in the world protect consumer data. I can't wait to talk about all things compliance. But one of the reasons I do this is I love hearing more about my guest's origin story. There's often a big story behind their success.
[00:02:44] So, can you share your personal journey into governance, risk, and compliance? And what was it that first convinced you that AI needed stronger guardrails inside regulated industries? There's very often a moment or something that pushes you in that direction, a little nod from the universe. But tell me about that origin story. Where did it all begin? Yeah. I'll tell you a little bit about the professional origins. But I actually think this origin story lives a bit outside of my career.
[00:03:11] But very quickly, I worked at McKinsey and then for the state of Virginia in both roles was focused on public sector work of basically helping governments grow their economies in the tech sector by balancing regulation with investments and incentives around innovation. And so, you know, worked in economic development. And that was an amazing journey being on the regulatory side of the house and seeing things from a government perspective. And then I worked in tech. I was chief strategy officer for a legal AI company.
[00:03:42] And so, kind of helped to shape and see that journey through. But to answer your question, Neil, the real heart of it, I am such a data privacy nut in my personal life. I mean, I can't tell you how many parties I've been to where I literally am helping people change the security configurations on their phone. Because I believe that we should be in control of our data. And I think that we trust companies with our data.
[00:04:08] And I want, you know, those companies to be trustworthy. And so, when, you know, if you think back, you know the big Equifax breach that happened years ago. One of my very best friends, his data was compromised in that breach. And I saw all of the fallout. And it just made me think about how, you know, we trust big companies with our data every day. How do we help make sure that those companies can securely handle consumer data?
[00:04:32] And there's only so far you can go with personal security configurations and privacy opt-outs and whatever else. It is at the end of the day about helping the companies themselves be, you know, the most secure that they can be to protect consumers. So, that's the quick origin. Wow. I love it. What a great story. I've got to ask that. Which do you prefer, data privacy or Boston Celtics? You've got to only choose one. What's it going to be? It's going to be really tight, but Boston Celtics on that one.
[00:05:01] And that's a big deal for me to say that, by the way. Yeah, I know. That's why I asked you that. And going back to tech here, I mean, you talk a lot about building responsible AI systems where governance and innovation meet. Incredibly cool. But what does that balance actually look like in practice for large enterprises that are trying to move quickly without exposing itself to risks? Because I think it's such a big talking point right now, especially as everyone's talking about agentic AI and hundreds and thousands of agents going out there into the wild.
[00:05:30] So, tell me more about that balance and getting it right. Absolutely. I think for enterprises, I like to split the conversation into two. One is internally building AI-led products as part of their business and their business's contributions to their customers. On the other side of it, it's their vendors, right? Because enterprises have so many vendors that they're always working with.
[00:05:54] And how do you make sure that those folks have good AI governance in place so you're not exposing the enterprise's data or the enterprise's customers' data out via the third parties that they're working with? And so, I think the answer is slightly different for each. Does that breakdown make sense now before I dive in? Yeah, yeah. 100%. I think that when it comes to the first part of that question, right? So, for folks internally, I think companies are actually doing quite a good job of this right now.
[00:06:21] I know that agentic AI and AI as a new frontier is evolving rapidly. But I have seen a lot of responsibility and a lot of clear guidelines being set internally. I think that there's a bit more nuance there that I'll come back to in a minute. On the second side with the vendors, this is where I'm seeing slightly more immaturity. And this is where compliance is really trying to help.
[00:06:45] I think a lot of enterprises have a lot of vendors that have been pre-approved or they've been working with for a while or even for new vendors that they're thinking about. They're asking quite baseline questions about AI and security and AI and governance in those vendors' practices. And I think that we've got to tighten that up very quickly in order to make sure that they're not onboarding tooling that is less than compliant, let's say.
[00:07:14] And so, that's kind of, I think, one of the harder parts to learn in. One of the big challenges, I suspect that many leaders you come across might still see compliance as a cost centre. So, there's a certain mindset shift that's needed there. So, how are you seeing AI changing compliance and risk management from a reactive function, a cost centre, into something more strategic and more forward-looking? It feels like there's a big opportunity here, but getting that message must be quite challenging sometimes. Hmm. Great question. You know what?
[00:07:44] AI has actually brought the language of risk to the boardroom in a way that no other force has that I have seen. It has made everyone so quickly understanding of what risk is. Because, I mean, just think about it. Someone who has no idea about data privacy and risk, they look at AI and they're like, okay, I'm putting a lot of data into this thing. And if that system is not treating the data as I expect it to be, then there's a lot of potential risk.
[00:08:14] And all of a sudden, everybody understands that. It's no longer in the depths of a product or in the depths of, you know, third-party risk management. It is front and centre. We are having conversations about AI every day and everyone understands that there's risk here and that there's need for compliance. So, I actually think that it's elevated it.
[00:08:34] And I think that when people talk about compliance as a cost centre, I really do think that maybe they think that about compliance, but not necessarily risk. And I think that the GRC teams that are savvy and forward-thinking are not just talking about compliance standalone. They're talking about risk.
[00:08:53] And they're coming and they're saying, look, we can invest X millions of dollars to put up, you know, guardrails and make sure we, you know, get the premium tier of every software and, you know, have all these other things built in, as well as just the, you know, the cost of hours and everything to manage this. You know, is it worth it? And, of course, I think the answer is yes. But that trade-off, you know, not just asking for the money, but explaining the risk that makes it worth it, is I think the conversations that people are starting to have.
[00:09:22] And I think that's honestly a really good thing. Yeah, me too. And for people listening that are hearing about the compliance as a company for the very first time, you position yourself as this AI-powered GRC platform that automates governance and risk management for complex organisations. But there's a big focus on all tech projects and bringing new tech organisations in around ROI.
[00:09:47] So what are you seeing as the biggest pain points in traditional governance models and how are you seeing automation meaningfully, measurably changing outcomes rather than simply speeding up paperwork? What are you seeing here? Yeah, I think there's three levers of outcomes here that we see consistently. One is, of course, time saving.
[00:10:08] Two is really tangible cost saving, both from a preventative cost perspective as well as lower fees in consulting and maybe future headcount and things like that. And the third is ability to focus on risk. And so maybe I'll touch on each of those very quickly. Currently, you know, risk compliance processes look very different based on the segment of a company. Whether they're a startup, mid-market, or enterprise, it looks very different. But one thing is, I think, very common.
[00:10:38] Everyone knows that compliance is so nuanced, so detailed, that often it requires that human touch, human judgment. And a lot of compliance tech so far has focused on red light, green light automation. Binary, Boolean, that approach. What we have done is brought nuance to compliance monitoring. And we've done that using agentic AI. And we started that in 2023, by the way. We released our first agent in 2024, January, before we even knew the word agent.
[00:11:08] And we didn't really understand what we had built. And so we've been doing this for a while. And we did it because our goal was qualitative review. And that type of nuance and qualitative element, rather than a red light, green light system, that actually brings the technology to be able to save human man hours much more than a binary operation, conditional logic type of model.
[00:11:31] That means you're replacing not only what everyone expects to replace, you're actually replacing some of the really time-consuming hours that are being spent right now, reviewing evidence, reviewing third-party responses about their AI, for example, or their security. So that's kind of that first bucket of time savings kind of brought to life.
[00:11:55] And we're recording this in 2026, where transparency and accountability are becoming board-level concerns in AI adoption. What I love about your story there is you've been on this, you're like two years ahead of the game, at least here. And to give people listening that are just getting to grips with the responsibilities and how technology can help them, I'd love to give them a valuable takeaway here.
[00:12:16] So what concrete steps should organizations be taking to create auditability and explainability in their AI systems right from day one? Where should they begin? What are those foundations? I think that they have to – this is a really tough question because I think, Neil, it's so in the weeds with every system. I don't mean to avoid the question.
[00:12:42] What I would say is that they need to have a strategy for their internal AI and their external vendors' AI. And I'm actually going to focus on the external vendors because, in my experience, people are doing better on their internal products. So they need to have a strategy for all of their team's touchpoints with other AI. Not company-built AI, but actually externally built AI. Whether that's policies around what they're putting, what employees are able to put into ChatGPT, whether that's an understanding of a much more nuanced level of review for third-party vendors,
[00:13:12] especially subprocessors who are handling their customers' data. They need to be asking the right questions, not asking surface level, but actually getting more into the weeds. And then last but not least, it's about having, I think, a really clear discussion internally about their risk thresholds as a business and then putting their money where their mouth is. If they're risk-averse and they don't want to deal with the fallouts of a third-party security breach because of AI,
[00:13:39] then they need to think about what are they doing to support third-party security. And also, when we talk about ethical AI, which is a phrase I'm hearing more and more about this year, it can feel quite abstract. So in your experience, what does ethical AI, what does that really look like in practice inside maybe a regulated enterprise environment or for somebody listening from that kind of environment? What does that actually mean? I'm going to actually bring it back to what it means for us every day. Yeah.
[00:14:08] When you're building a product, when you're building a product with AI and using AI in many ways, you make so many micro decisions. You can make decisions that are faster and that use AI in ways that may cross a line from a security or privacy perspective, but they're easier, they're faster, they're quicker. Or you can make a decision to build something in a more infrastructurally sound way. It may take a longer time. It may use more resources.
[00:14:37] It may be higher cost, which is ours, you know, internally, I mean, to build. And we deal with those trade-offs all the time. And I think ethical AI means many things to many people, of course. But I think from our level, what it means is taking the hard route to build security-first, privacy-first AI products for the market, rather than taking a shortcut, not only from a perspective of putting an AI wrapper on it, which is not useful,
[00:15:05] but also not taking shortcuts around privacy and security. Respecting our customers' data and the boundaries and the commitments that we make to them, that, to me, in our context, is ethical building with AI. And for years, even before AI came along, all tech leaders have struggled with the legacy debt, or technical debt, as it's often called. So for CISOs and CROs and compliance leaders listening today,
[00:15:31] what are those early warning signs that suggest that their AI innovation is actually outpacing their governance frameworks? And how can they course-correct without stifling momentum and without causing problems? Anything that you'd recommend here? Yes. From a risk perspective, I would say look at your risk register and make sure that, you know, you talked about technical debt. Oftentimes, the risk register really is a good example of something that is a bit stale, right?
[00:15:59] It hasn't been given the love and the recent updates that it needs. Make sure that those areas that you're thinking about raising to the board actually are, you know, encompassing the AI risks that exist today. Think about your third-party risk list. Think about from your third-party perspective. There's a lot of vendors that you probably have not reviewed and you don't even realize it because someone's approved it down the line.
[00:16:26] And lastly, from a controls and compliance perspective, are you tracking any AI standards? Are you thinking about, you know, looking at ISO 40-2001 or other, you know, NIST AI, RMF, other AI standards? Or are you just sticking with, you know, what you've always done for the last 10 years and not keeping up with the change? That's what I would say across those main verticals. Love it. And if we were to look further ahead, as AI systems become more autonomous and embedded into all core business processes,
[00:16:56] how do you see the role of GRC evolving in the next three to five years? And what should leaders be preparing for right now? And I understand when I say that out loud. Three to five years is a lifetime in old money. The speed of change has got so quick at the moment. But where do you see all this evolving and heading? Yeah, I think GRC is, you know, a function that is being emboldened by AI. I think that it's a function that AI is making invaluable.
[00:17:21] Because at the end of the day, so much about AI is the other side of the coin, which is trust. And how do you trust the AI? How do you trust the company that's handling your data in this, you know, newly huge, like high volume way, right? How do you trust that? And I think it comes down to the GRC function. Governance, risk, and compliance is essentially the trust function of your organization. And it helps to establish trust with your customers.
[00:17:48] And it should help to also test trust with any of the folks that you work with. And I think that at the end of the day, that's what everything is starting to be about. And as I said earlier in our conversation, when you mentioned you were building agents in 2024, it feels like you're a couple of years ahead of the game here. But it's obviously it's not just me saying this.
[00:18:10] Before you joined me today, I was reading that compliance raised $20 million of Series A led by Google Ventures to help modernize enterprises GRC with Agentic AI. Amazing recognition as well. So tell me more about that deal and what that means to you. I think, you know, when Google Ventures approached us in November, they had already done research on the GRC market. And they basically came to us and said, look, we've reviewed the whole market.
[00:18:40] We see a lot of companies that look alike. And then we see compliance leading the charge on AI and the validation as a founder to hear that for one of the biggest names in tech. It is hard to explain. It's amazing. And it also means that we raised based on who we actually are. We didn't build, you know, sand castles in the sky and make crazy promises. We doubled down on, yes, that's exactly who we are and that's exactly what we're doing.
[00:19:09] And we raised money to continue building what has made us so successful so far. And I think that as a founder is literally all that you can ask for. It really is. Congratulations to you. It's great to hear this hard work paying off. And for anyone listening wanting to explore more about how AI is transforming compliance and risk management and how you're creating transparency and accountability in enterprise AI adoption. Where would you like me to point everyone listening?
[00:19:39] Maybe to our LinkedIn or to our site, which is just compliance.com with a Y. So C-O-M-P-L-Y-A-N-C-E dot com. I, for one, have just loved chatting with you today, learning how AI is transforming compliance and risk management, creating transparency and accountability in enterprise AI adoption, and also demystifying what ethical AI looks in practice. So I'll include links to everything. I would urge people listening to go check you out. But more than anything, just thank you.
[00:20:07] It's very clear talking to you today that your passion for this industry really comes to life. And I'm just very grateful that you joined me today to do just that. So thank you. Thank you, Neil. I hope that passion comes through as, you know, the why behind compliance with the Y. This is why we do it every day.
[00:20:24] I think one of the many things I loved about our conversation today is how it reframes governance, risk and compliance from being the team that slows everything down and says no to becoming the function that makes trusted AI adoption possible in the first place. It's a massive opportunity. So if you want to learn more about compliance, you'll find links in the show notes.
[00:20:49] And please reach out to her and the team to continue the conversation there. And as always, thank you for listening. And if this episode got you thinking about how your organization is handling AI risk, vendor exposure or data responsibility, I'd love to hear your perspective too. Because in an AI first world, trust is quickly becoming the most valuable product any of us could build. So techtalksnetwork.com. Let me know your thoughts there.
[00:21:18] I'm going to sit back and relax and have a drink now. But I will return tomorrow waiting patiently in your podcast feed for you to hit play. Speak to you then. Bye for now.

