Skip to Primary Navigation

Transcript: Brian Riewerts and Michael Reyes podcast

Brian Riewerts and Michael Reyes
GRIP Montage: Pwc

Riewerts and Reyes on why siloed risk functions are breaking down — and how AI, integration, and “risk intelligence” are reshaping life sciences compliance.


The following is a transcript of the podcast episode Brian Riewerts and Michael Reyes on risk transformation in life sciences between GRIP reporter Kevin Kinsella and Brian Riewerts, partner, Pharmaceuticals and Life Sciences, and Michael Reyes, director, risk and regulatory consulting, both at PwC.

[INTRO]

Kevin Kinsella: Welcome to the Global Relay Intelligence and Practice, or GRIP, podcast. I’m Kevin Kinsella, GRIP’s reporter for Healthcare and the Life Sciences, and I’m happy to be talking to you today from our New York City offices in Midtown Manhattan, where I’m joined by our guest, Brian Riewerts, partner, Pharmaceuticals and Life Sciences, and Michael Reyes, director, risk and regulatory consulting, both with PwC.

The life sciences is one of the most complex and heavily regulated sectors due to its direct impact on public health, safety, and the economy, which frankly makes it one of the most interesting sectors as well.

PwC’s Pharmaceuticals and Life Sciences division supports this sector by providing the scientific, commercial, and operational resources companies need to compete and deliver value for patients and investors. Its team brings together deep industry insight, experience, and leading technology to help drive results, and we’re so lucky to have two of them here today.

Welcome, Brian and Michael, and thank you both for joining us this morning. In a moment, we’re going to talk about integrated risk in a Life Sciences context, but before we get into that, Brian, please introduce yourself and then you, Michael.

Brian Riewerts: Thank you, Kevin. So my name is Brian Riewerts. I’m a partner at PwC, and for the last 30 years, I’ve been working exclusively in the industry, particularly pharmaceuticals, life sciences, medical devices, and helping organizations address regulatory change, enforcement, and really, the proliferation of this industry from a risk and compliance perspective. Also helping organizations move towards providing more value in their organization.

So it’s been my life’s work really in helping the industry address regulatory change and how to do that in an effective way.

Michael Reyes: Hi, my name is Michael Reyes. I’m a senior manager, and I work really closely with Brian. I’ve spent the past 10 years working with pharma and med device clients as well on all things risk compliance. And I’m really excited to share a lot of the work that we’ve been doing in this area and some of the themes and insights that our clients have been talking about.

Kevin Kinsella: Terrific. So let’s jump right in. Despite years of investment, why is risk effectiveness still so difficult to measure?

Brian Riewerts: Yeah, and this is something that we’ve been spending a lot of time with organizations around the globe over really the past three or four years. Organizations in life sciences and healthcare have done a really good job in investing in compliance and risk in individual silos. So think about quality functions, compliance functions, internal audit, and the like. Many of those organizations have embraced technology and have moved their practices forward in many instances off the back of enforcement actions, which has caused a bit of a haphazard design structure around how risk compliance regulatory functions have been built.

What we’re finding now is that major global risks are not staying neatly within those silos anymore of quality compliance and regulatory and have become such that you need to have a more integrated view of how risks are evolving and manifesting within the organization. Because of that investment within silos, we’ve not seen the investment at the top of the house to really allow for the integration of insight and the application of AI to help drive the overall effectiveness of the function.

So it’s been a manual process in the past and now companies are really leaning more towards “how do we pull the string on this and use technology and AI to integrate what we’re doing.”

Kevin Kinsella: You talk about integrated risk transformation. What does that actually mean in practice?

Michael Reyes: Yes. So we’ve been talking to clients about this concept of integrated risk. And as we’ve talked about compliance and the different level two functions or second line functions of compliance, quality, privacy, we’ve really started to see how clients can orient themselves in different programs and start to pivot a little bit into what we are calling the life cycle of a risk. And so this is really thinking about what are the pockets of capabilities that a lot of these risk functions actually do pretty similarly.

They are the risk assessments, the identification of the risks, the prioritization, and what we put in terms of mitigation plans and monitoring and even issues management. And so what we started to see is we can actually pull those different capabilities together and start to see a little bit more value in terms of the connectedness across these different programs and these different offices, essentially, that clients have started to build over the past several years.

So when we think about integrated risk transformation, it’s a little bit of a pivot and paradigm shift of really thinking about what is the risk and how do we put the right process controls and framework around those risks rather than setting up individual offices, different programs for every risk just because we’ve seen tons of risk come up in the past. And even now the velocity, the change, and everything is just becoming so much greater. And so we need to think about how we can address those in a more agile fashion and really keep up with the speed of change.

Kevin Kinsella: That’s very interesting. What’s fundamentally broken in how organizations manage risks today?

Michael Reyes: I would say that maybe not necessarily broken, but there’s just a ton of opportunity to do and leverage a lot of the investments that clients have already started to invest in over the past several years. And so when we think about all the different operating efficiencies that a compliance program has invested in, in quality, in privacy, in third party risk management, there’s been a lot of great work. And now we see an opportunity to really connect those capabilities and actually drive more value.

So whether it’s connecting how you do risk assessments a little bit more efficiently or how we look at our third parties, instead of seeing them in individual pockets of the potential risks, we can now see a different picture when we actually take a step back, look at all the different second line functions that provide the risk oversight and really start to see a little bit of a different picture.

And so ultimately, when we look at the models, we can pivot a little bit more on what are the risks, what are we doing about them, and is it enough rather than keeping all this information segmented and siloed in the different programs and the different offices?

Kevin Kinsella: Terrific. Why haven’t GRC and ERM investments solved the problem?

Michael Reyes: From a tools capability, I’ll talk about that first. A lot of clients have done a great job in investing in GRC capabilities and technologies that are really point solutions. And so what we’ve seen at clients is they have great technologies and tools stood up across the risk function landscape. So when we think about GRCs, there’s policy capabilities, there’s assessment capabilities, there’s issue tracking. And so when we times that by the number of different programs and offices, we actually see that everyone has a different version of some of these tools in place. And they do a lot of great work and a really important work for each of these functions.

And so now we’re trying to say, hey, across this ecosystem of all these different technologies, all these different data sets, is there something that we can really step back, look at the broader picture of what data is being captured in each of these different programs that ultimately tell a little bit of a different story?

I think there’s such a big opportunity with the risk management profession, where we can now say we have done a great job in our different pockets of compliance, of quality, of enterprise risk of third party. And now we can take a step back and say we can have a way better picture. We can look at problems differently and we can help solution what some of the mitigation plans are for some of our top, more impactful risks, and especially helping our business partners as we think about what are the steps that might be duplicative, have overlap, or even just make it easier from a user experience for how they navigate risk and interact with the different offices.

Kevin Kinsella: Absolutely. What is the integrated risk dividend?

Brian Riewerts: This is my favorite thing to talk about. So when we sit as compliance professionals and consulting leaders going into engagements, our clients are usually coming at this concept of integrated risk from one of two perspectives. One, we’ve spent too much. To Michael’s point, we’ve built a federated model with redundant or duplicate, and sometimes underinvested capabilities across these different risk groups, and they need to figure out from a cost reduction perspective, we have to be able to do better. Others come at this from a position of strength and saying we’re doing very well, we’re growing rapidly, we need to be faster, we need to be more agile in how we’re looking at risks, and we have the resources right now to invest into that curve to really take advantage of AI and other emerging solutions.

So when we stepped back and we were looking at these sort of two different dichotomies of how global life sciences companies are addressing this topic, you need both. And we came up with this concept of the integrated risk dividend to say there is measurable return from integration, and it’s not just the cost savings from duplicate investments, but it’s also the productivity gains that you have within the organization. It’s the value of early risk identification within the enterprise and being able to share that early detection capability across everywhere.

But also it is the value of better decision making within the organization in understanding the velocity and change of risk globally and to be able to anticipate that and really move from a reactive environment to a proactive environment. So we tried to figure out a concept to bring that all together to say if you’re going to invest into this environment, either because of cost reduction obligations or desire to just be better, what does that really mean? And that was really where the idea of the integrated risk dividend came from.

Kevin Kinsella: But is the dividend real or still theoretical?

Brian Riewerts: So and that’s I think where most of our clients are at the pilot stage of this. I think that the dividend is real in concept, but the challenge really isn’t identifying where the productivity gains are or the value of risk identification. It’s identifying the stranded cost across the organization. And that is people, process, technology and controls. Where do we have those embedded within our organization? And it’s been 30 years of these functional risk organizations building policies and processes and technologies and the like.

So from a change program perspective, it’s difficult for some of our clients to identify and pull out those stranded costs. But the onset of AI and how that’s disrupting the practice of risk management and compliance in the life sciences industry, it’s providing an accelerator to really identify and quantifying and pulling those costs out. So it’s it is real. It’s just a question of how rapidly are our clients going to move down that path to look for what their new North Star is going to be for this.

Kevin Kinsella: How does integration change decision making?

Michael Reyes: So I love this question because I think there’s such a value unlock for so many of the risk functions today. Historically, I think compliance, other risk functions audit have generally been consumers of data. Right. We pull data to analyze. We look at different documents. We look in terms of trying to assess or audit things or monitor them. And it’s all data that’s being captured other places in the business. Like I was saying earlier, there’s so much data now being created in these systems that are in the risk management organizations, through their GRC capabilities, through any of the stuff that they’ve stood up to advance their programs, especially with compliance programs doing a lot more with analytics today.

There’s just so much more data that’s available and also so much more data that’s being created by the actual risk organizations themselves. And so when I think about where companies are going or in some of the capabilities in terms of better decision making at the end of the day, I think we’ve been calling it risk intelligence. If you think about what a brain does is it sources information to try to make the best decisions it can. When we think about that in the context of risk management and your business value, I think it’s seeing and unlocking all the different pockets of information that are now being created, looked at across the whole organization to really make a more holistic picture for business leaders, for risk management leaders to ultimately make better decisions.

And so when I think about a picture that has historically been in place, right? Compliance looks at compliance risk, quality looks at quality risks, privacy looks at privacy risks, cyber looks at all things cyber. But now you have the opportunity to really say, what are the different areas where some of these data sets overlap? What are some of the capabilities that we have in place to really say, if we put two or three of these together, does it actually change how we look?

And we’ve seen a couple of different examples of this play out with clients, whether it’s looking at HR data, investigations data, compliance data to say who could potentially be someone that we need to have a little bit more targeted training or even just potentially watch out for in terms of marketing or sales tactics. But now we can have the opportunity to really do that across all the different organizations and second line functions to really say, here are things that are actually starting to bubble up in certain markets and what should we do about it? Is it enough for us to take action? Is it something that we really should prioritize as a leadership team to really say this could actually materially impact our business in this either geography or in this specific physical location.

And so when we think about that, I think there’s such a big opportunity for risk organizations to take a step back and take inventory, because I think this is actually one of the hardest things that people have in terms of time, energy and effort is to really actually take a step back and inventory all the things that are out there for you to even look at and then start to build a picture both from a top down what impacts our strategy. But then what are all the micro decisions that are being made day to day that ultimately rise up and could actually have a bigger impact to our organization than we even know.

Kevin Kinsella: How is AI changing expectations for risk and compliance?

Brian Riewerts: What we’re seeing from an AI perspective is organizations are running to innovate. They’re running to look at how we can apply AI, again, in discrete areas like transactions monitoring or in identifying issues within the enterprise. But what we’re not seeing yet is that holistic view of how AI can support risk management from inception to close. And Michael talked about the lifecycle of a risk. We’re seeing, finally, the opportunity for AI to help us be more predictive on the front end to understand the nature of regulatory change management from a global perspective, to understand how to compile that information with other risk events that are happening around the world, to really create a more real time ingestion of risk and regulatory change events and have AI help you understand if this risk event or this regulatory change has occurred.

What does that mean downstream to me from a policy perspective within my control environment? What do I need to change or add? How do I adapt training around this? And then how do I think on the back end around internal audit planning and execution, how do I really treat this as an overall end to end process? And where does AI fit in that story?

Going back to the risk dividend point for a second for organizations that are looking at spans and layers of risk functions across the globe and saying we just simply can’t afford this anymore. The exam question is where can AI take work out of the process so that I can skinny down my human capital investments or technology investments?

Others are saying, as I had alluded to, those that are kind of from a position of growth, we still want to drive an efficiency quotient within the organization, but we need to improve our agility, our speed, our really our resilience to risk and regulatory how can AI help to drive that for us? So we’re seeing that as organizations that we’re looking to employ AI, it really amplifies the difference between integrated and federated organizations when you try to apply AI technology against federated data and federated systems and federated process.

So for organizations that are looking to shift from reactive oversight to proactive risk intelligence, part of the challenge is really figuring out again, that foundational data layer data fabric challenge that many organizations have found themselves in in 2026.

Kevin Kinsella: Now, within an organization, who should own integrated risk transformation?

Michael Reyes: Yeah, I love this question. So, you know, talking to one of my clients, when we talk about integrated risk, who owns risk, everyone owns risk at a company. And I think that’s just like a really fun, you know, colloquial concept. And at the end of the day, you know, everyone has a role to play in terms of the actual transformation and how to operationalize the different processes with integrated risk. We’ve actually seen a little bit of a trend. And so the trend is really seeing that across organizations, our second line functions are already starting to converge a little bit, whether it’s through their committees, or through some of the shared capabilities that they have, different risk organizations are starting to reorient themselves a little bit in terms of where they sit.

But overall, when we think about some of those examples, like risk committees or other types of committees that either have reporting functions or, you know, decision making authority, it really is starting to show that just like information, everything starts to converge a little bit more in the stories, the insights start to change a little bit. And so when we think about, you know, even some of the areas that we see starting to, you know, have better collaboration, we’ve seen over the past several years, compliance and audit have started to, you know, share insights, quality, even privacy and third party risk management organizations have all started to share information.

But as we think about who owns those transformation elements, really, there are many have taken the orientation to either have a few leaders that really drive some of those capabilities or even think about some of the areas that have shared capabilities under a like Center of Excellence type model as well.

Kevin Kinsella: Where should an organization begin to get started with this?

Michael Reyes: As I think about all the different areas where risk management plays, there’s just a ton of opportunities for people to think differently. And so we’ve been calling them “no-regrets moves,” right? I think for most of our clients, finding different ways to either streamline, make things clear or have better communication and therefore decision making is usually how we think about what these no regrets moves are. For example, with most of my clients, I normally joke about saying everyone’s probably tired of how many committees there are within an organization. And so committee fatigue is a real thing. And so, you know, working with one of my clients, I had the opportunity to interview a couple of their business stakeholders and their reaction was like, oh, yeah, there’s a committee for that. There’s a committee for that. There’s a committee for that.

And then I go talk to the committee and they say, that’s not what we do. We don’t do that. We don’t have a decision making authority. So even just thinking about, you know, how information is being disseminated across teams, what is the actual decision making model? Who are the people that need to be pulled together to have a meaningful conversation to manage risk? I think is some of the fundamentals that I think we need to go back to in terms of understanding what are these no regrets moves and they’ll be different for each company, right? Maybe your organization doesn’t have a ton of committees, but, you know, finding out who the right person to phone a friend is, is still a challenge for some of their business partners.

So when I think about no regrets moves, it’s do we even know who some of the decision makers are for some of these big hairy items? Do we know who should be in the room if we need to start thinking about a risk that has, you know, never shown itself to us before or something that could be impactful to either our new strategy or even a new way or adjacent industry that we should even be thinking about? Because we have no idea if that’s going to start to bleed over into how we operate.

So I think it’s answering a couple of these more fundamental questions that helps to orient ourselves around, you know, where we should start. The other examples that I can point to are really thinking about where we see integrated risk happening organically.

So when we think about third-party risk management, right? Third-party risk is very hairy and, you know, for a lot of clients, pretty difficult just because of how many different risk functions can be pulled in to help figure out what are the best mitigation strategies, what are the types of controls we want the third party to have, whether it’s security, whether it’s, you know, compliance, anti-bribery, anti-corruption, know your customer, all these different areas for a third party tend to be, you know, really complex.

And so having a way to then say, here’s a version of integrated risk, what are the ways that we can really test and pilot, you know, a better way to connect data across teams, have better handoffs, and then really see a little bit of the value of streamlining the process and ultimately getting better outcomes with the third party. Instead of having business stakeholders or even the third party go to five different questionnaires or 10 different offices asking different questions. Is there a way that we can really think through what are the risks? What are we doing about them? And is it enough for that across all the different restomies that they touch?

Kevin Kinsella: But what signals show that integration is working within an organization?

Brian Riewerts: So I think there’s a lot of different sort of KPIs that you could look at in terms of reduced duplication, faster remediation, things like that. But when you distill it down, I think one of the most valuable indicators of value is the nature of conversations within the organization to simplify it.

To build on what Michael was saying, as organizations are looking to invest in AI to identify regulatory change, every function within the organization is looking to do it in their own way. Is there an opportunity through an integrated risk transformation exercise to pull the string on that and say: “This is an enterprise capability that we all need to participate in. Let’s look at requirements. Let’s look at where we’re going to derive insights. What is our risk appetite tolerance within the organization as this content flows through?”

Having a combined conversation around that, as simple as it sounds, doesn’t happen very often. When you then talk about enabling technology, GRC platforms and other investments, third-party risk management platforms, is there an opportunity to really look at risks from multiple perspectives instead of just that siloed piece?

We were with a client two weeks ago and talking about how they’re all looking at the elephant from different angles, but they don’t see the whole elephant. They’re applying bandages on the elephant based on what they’re looking at. What we heard from one of our other clients who’s been on this journey now for two years is one of the most impactful early value propositions was.

We had better conversations as a leadership team around this to really look at how these risks intersect and how we want to really step back and look at broader investments to mitigate the risk, not just to protect value downstream, but to accelerate growth from the upstream perspective. That comes when you bring everyone together into one room to talk about, as you said, big hairy risks and the multi-dimensional nature of what they mean to an organization.

Michael Reyes: Maybe to just bring another example onto that, we were working with a client and they stood up a forum to be able to talk about some of these more complicated risks. There are topics that they bring in, different speakers.

The conversation got so good that the C-suite has actually asked to start to join those meetings just to hear how and what people are talking about. When I think about what are early indications of value, I think a good indicator of value would be when people actually want to go to the meeting. They want to have the discussion, they want to learn, and I think that’s a huge value prop for some of the stuff that we’re talking about because it is important and it does impact a lot of people. When you frame up those insights, your fancy word of risk intelligence, when people feel invested into the conversation, I think it will always lead to better outcomes.

Kevin Kinsella: It brings it into the culture of the organization. Finally, in the next five years, what will separate the risk leaders from the laggards?

Brian Riewerts: I think you will see that the winners in this market won’t be the organizations with the most tech, the most AI in general. I think the winners will have that connected system of risk intelligence where every signal, every issue, every event ultimately makes the enterprise smarter. The technology is here now to enable that. AI is breaking down historical silos like I’ve never seen in my 30 years of doing this work. It is now at the precipice of a significant change event for the industry, not just health care, but all industries in this space.

The challenge is, will organizations have the courage and the forward-looking vision to make the move and break down these historical silos and move into, admittedly, a new era of risk management and risk excellence, really? I think that will ultimately show who the winners and losers are in this space. Do you have the courage to adapt into this new environment?

Kevin Kinsella: Thank you, Brian and Michael. You’ve given us a lot to think about.

Listen to the audio.


Get full access, free for a month

This is a free article. Try Premium free for 28 days to get every article on GRIP and more – no payment details required.

What’s included:

  • Every new article, plus our 5,000+ archive
  • Daily regulatory insight and guidance
  • Exclusive interviews and in-depth analysis
  • Coverage of industry-leading events and conferences
  • All podcasts and videos, featuring industry experts
  • The full set of Rules Navigator tools
  • An ad-free experience