top of page

Confide Launches Agentic GRC Platform to Govern People and AI Agents

15 minutes ago
4 min read
Confide Launches Agentic GRC Platform to Govern People and AI Agents

Confide, the governance software company founded by Wirecard whistleblower Pav Gill, has launched an agentic GRC platform that pulls governance, risk and compliance into a single system and extends the same oversight to the AI agents now working alongside compliance teams. The product replaces the patchwork of separate tools most organisations run for case management, policy, risk and audit, and logs every action, whether taken by a person or an agent, in one defensible audit trail.


The pitch is narrow and testable. When a serious concern surfaces, can a business show what happened, who made each decision, and what action followed, without piecing the story together from disconnected systems? That is the question Confide is building its software to answer, and it is the same question that has put several large firms in front of regulators and parliamentary committees over the past year.


What does Confide's agentic GRC platform actually do?


It connects case management, policy, risk and audit so a team can follow an issue from first report to final action in one live governance record. Policies, risks, cases, people, vendors and decisions sit in the same place, which removes the reconstruction work that slows internal investigations and weakens the evidence trail.


The platform governs AI agents on the same model it uses for people. Businesses set which tasks an agent may perform, where human approval is mandatory, and when a person can step in. Agents take on routine administrative work while consequential decisions stay with people, and every action by either is recorded. Confide says the system is model-agnostic, designed to work with different AI models and to slot into existing procedures rather than forcing teams to rebuild their standard operating procedures around a new tool. Workflows cover third-party risk, incident response, health and safety, law-enforcement requests and AI governance.


Why does a whistleblower founder matter here?


Because the product is built around the failure mode its founder lived through. Pav Gill was Wirecard's head of legal for Asia-Pacific, covering 11 markets, and became the whistleblower who helped expose one of the largest corporate frauds in European history. He founded Confide in 2023, initially as a whistleblowing platform, and has since broadened it into a full governance, risk and compliance suite that now also spans investigations, conflicts of interest, grievances and financial crime.


That origin shapes the design problem Confide is chasing: not how to receive a report, but what happens after one is filed. Concerns that never reach someone able to act, investigations that leave no clear record, and decisions no one can later account for are the gaps Gill argues legacy GRC tools were never built to close, least of all in an environment where AI agents help run day-to-day operations.


Why does this launch matter now?


Because the compliance burden is moving from periodic review to continuous proof. Regulators increasingly expect firms to demonstrate compliance on an ongoing basis rather than at audit time, and to show who made each decision and on what information. Confide cites roughly 61,000 new regulations introduced worldwide each year, a figure that captures the direction of travel even where the precise count is hard to pin down: buying a fresh point solution for every new rule is no longer practical.


The wider GRC market is consolidating for the same reason. Vendors across the category are converging on unified platforms that end the framework sprawl created by managing SOC 2, ISO 27001 and other standards in separate systems, and on continuous monitoring in place of questionnaire-driven snapshots. A second shift is running alongside it. Governing AI systems themselves, often described as GRC for AI, is emerging as a distinct mandate next to the longer-standing use of AI to run GRC. Confide is positioning at the intersection of both.


What does the KPMG case show about defensibility?


It shows what fragmented records and mishandled reports cost. In August 2026, KPMG Australia's handling of a whistleblower returned to the headlines after a parliamentary committee released documents indicating the firm had given external reviewers an incomplete account of the allegations. The underlying claim, first raised in parliament by Senator Deborah O'Neill in March, was that KPMG partners used confidential Lendlease board papers to help win audit tenders from rivals, including work connected to Westpac and Dexus.


The fallout has been material. KPMG Australia's chief executive and audit lead left in May, its chairman departed in August, and the firm was barred from new government contracts, with consulting revenue falling almost 17 per cent and roughly 360 staff and 27 partners facing cuts. The case is a working illustration of Confide's argument: a single, defensible record enables earlier detection and a clear account of how a concern was handled, and that account cannot be assembled retrospectively once trust has broken down.


Confide says it serves users in more than 150 countries and holds ISO 27001 certification and SOC 2 attestations, and that its backers include more than 50 GRC leaders spanning law firm managing partners, chief compliance officers at large corporates and ISACA board members. Those are company-stated credentials rather than independently audited claims, but they place Confide among the more serious entrants in a field that, for now, has no dominant platform.


Why This Matters to FinanceX Readers


For compliance leaders and investors, the signal is that defensibility is becoming the product. As AI agents take on real operational work, the regulatory question shifts from whether an action was logged to whether a firm can reconstruct, on demand, who or what did it and why. The KPMG saga shows the downside of getting that wrong: lost contracts, leadership turnover and a revenue hit that lands on the whole business.


The investment read is that GRC is consolidating from a shelf of point solutions into unified platforms that govern people and automation in one record, and that AI governance is hardening into its own budget line rather than a feature of general security spend.


Confide's differentiators, a whistleblowing and financial-crime origin and a single live governance record, are credible but not unique in a fast-crowding market. The question for any procurement shortlist is which platform can prove, not just promise, that its controls did what they claim at the moment an agent or an employee acted.

 
 
bottom of page