In short
Richa Kaul (Compliance with a Y) explains why AI-native governance, risk, and compliance (GRC) is shifting from slow, sample-based audits to continuous, agentic monitoring of internal controls and third-party vendors. She also discusses founder journey, funding strategy, and whether SaaS is “dead” or rebuilt around AI agents.
Guest backgrounds
Richa Kaul is founder and CEO of Compliance with a Y, an AI-native governance risk and compliance platform. She previously worked at McKinsey and was Chief Strategy Officer at ContractPod AI. She describes herself as highly privacy-focused.
Key claims
AI has made risk/compliance “a language of everybody” (e.g., people sharing data with ChatGPT/Claude). Agents provide full visibility vs point-in-time checks, reducing breaches. Humans remain for decisions/approvals; guardrails and determinism are used.
Notable examples
Antivirus compliance changed from checking 10/1,000 employees to continuous monitoring. Third-party vendor risk is monitored via AI agents that ask vendors questions, continuously flag issues, and help control data sharing.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VORicha's Personal Journey into Data Privacy
0:45 to 2:00
Richa shares her background and the spark that led to her business idea.
“And dare say in a few years' time, there'll be compliance people on the street asking for some spare change after her startup.”
The Birth of Complyance
2:00 to 4:20
Discussion on how Richa conceptualized Complyance after a personal experience.
“I think it's good for everyone to be a little bit safer.”
Revolutionizing Compliance with AI
4:20 to 6:30
Richa explains how AI changes the landscape of compliance and risk management.
“to trust so many companies with our data every day?”
From Point-in-Time Checks to Continuous Monitoring
6:30 to 8:30
The transition from traditional compliance methods to real-time AI monitoring.
“My point is that compliance is really what enables us to trust the world around us.”
Understanding Third-Party Risks
8:30 to 10:50
How AI can monitor third-party vendor risks effectively.
“And there was no way to do enough follow through.”
AI's Impact on Boardroom Discussions
10:50 to 13:00
AI's role in making risk and compliance more visible to executives.
“I think that before, again, unless you're involved in an audit or have worked within an organization, that's gone through a number of audits, you may not have quite understood what is risk management?”
Emerging Trends and Challenges in Compliance
13:00 to 14:00
Richa discusses the evolving landscape of compliance and the challenges companies face.
“become vulnerabilities, which is really the main goal of all this.”
The Impact of AI on GRC Teams
14:00 to 16:10
Discusses how AI is transforming the roles and perceptions of GRC teams in organizations.
“So I think GRC people often feel a bit like, oh, no, we're being annoying to our organization.”
Navigating Investments as a Founder
16:10 to 20:25
Explores Richa Kaul's unique approach to securing investor interest without traditional pitching.
“Let's get into your journey as an entrepreneur.”
Understanding Market Changes and Customer Needs
20:25 to 24:21
Analyzes how entrepreneurs should adapt to rapid changes in the market and customer needs.
“And I think that that really changes the dynamic.”
Show all 18 chapters
The Future of Workforce in an AI World
24:21 to 25:55
Discusses the challenges and necessary policy discussions surrounding the future workforce amid AI advancements.
“And you just have to make sure that your product, your solution, is actually meeting that problem.”
Building Next-Gen GRC Platforms
25:55 to 28:05
Outlines the vision for creating an advanced enterprise GRC platform using AI.
“and that's an entire conversation in itself.”
Introduction to the Discussion
28:05 to 28:20
The conversation transitions to the implications of AI on value delivery.
“And five years ago, I thought the whole thing would be solved by blockchain.”
Navigating AI and Job Security
28:20 to 29:20
Exploring the balance between AI advancements and job retention strategies.
“I would say articulation of value delivery to really senior stakeholders.”
The Evolution of SaaS in an AI Era
29:20 to 31:18
Discussion on how SaaS is transforming into systems of action and outcomes.
“Do you think that's the right intervention or what interventions would you propose?”
Human Oversight in AI Workflows
31:18 to 33:59
Examining the necessity of human involvement in AI-driven processes.
“And so I think those points together bring us to saying, SaaS is moving towards outcomes.”
Implications of the EU AI Act
33:59 to 36:28
Analyzing the potential impacts of the EU AI Act on compliance and organizations.
“Okay, we have got time for maybe one more question.”
Final Insights and Thank You
36:28 to 38:21
Richard Call discusses accountability in compliance and thanks the audience.
“There's a couple of GTM tools that I'm using, though, that I just love.”
Transcript
Automatic transcript. May contain errors.0:00Mike Butcher:So tonight we're joined by Richa Kaul, who's founder and CEO of Compliance with a Y, Compliance with a Y, not with an I, which is an AI-native governance risk and compliance platform that recently raised a$20 million Series A led by Google Ventures. Richa describes herself as a data privacy nut, perhaps the kind of person who will ask you if you have locked your phone down properly, switched on your two-factor authentication, all that kind of thing. I jest, but she actually appears to have stumbled upon her startup journey with this sort of idea about journeying from this idea. And the best way to actually protect consumer data is to help secure the enterprises that hold that world's data.
0:49Mike Butcher:And that became compliance, software that uses AI agents to help companies continuously monitor risk, compliance, and third-party vendors, etc., turning what used to take weeks or months into something much closer to real time. And dare say in a few years' time, there'll be compliance people on the street asking for some spare change after her startup. So tonight, we're going to talk to her about her founder journey, how she spotted the opportunity, why AI has suddenly pushed risk and compliance front and center into the boardroom, and the clever strategy that she used to raise funding and the big question hanging over the software industry right now is SAS dead or is it being rebuilt around AI agents Richard welcome to past founders
1:38Mike Butcher:the privacy setting at parties is it a true story it is a very true story and not just at parties I will go around and ask my friends and family if their privacy configurations on their phone are up to par all the time. Right. You definitely are that person then. I am that person. Marvelous. You must be a riot at parties. I am. I am. I think it's good for everyone to be a little bit safer. That's all. That's all. That's where this all kind of started. It's a good conversation opener, that's for sure. Yeah. I'm not sure. Some people are a little startled when I tell them to go to settings on their phone and open microphone and look at which apps they have microphone on for.
2:15but if you do it, you will be surprised. It'll only take you a couple seconds, and you'll be more secure for it.
2:21Mike Butcher:I think people are actually starting to do that. I've just seen somebody do that. I'm just saying. You want to know why you get ads about things you talk about? It's because your microphone is on for a bunch of apps that you didn't know. So are you saying that rumor about Facebook and listening to you all the time is true? Just look at your phone. You will see it. Your microphone is turned on. Why is it turned on? Mark, we love you, wherever you are. Turn that off. Turn it all off. It's literally all on. And for what? So it's actually a real tip. Do the same thing with camera. I feel I actually can just leave now because that's all that I actually wanted to do here, everybody, is let you all know that one thing.
2:57Mike Butcher:We don't want you to leave right now. We want to continue the podcast. And so what happened to you? Did you have this sort of little kind of idea about privacy? Because tell us a little bit about your personal story, you know, what you've been doing. Tell us a little more. Yeah, I'm happy to. And, you know, it's funny. I think it really was a personal start to compliance with a why. One of my very good friends was part of a really big data breach that happened. It was the Equifax breach, which happened now a number of years ago. Some of you may remember it. At that time, it was big news because, obviously, there weren't as many data breaches as there are today.
3:40Today, I feel like that type of breach may not even hit you guys, hit your newsfeeds, because there's breaches all the time. But it was the first really big breach that happened that made a lot of people kind of feel concerned that their data was not necessarily being kept as safely as they would want it to be. And there's no breach shaming here, as I like to say. It happens. If you have the right security policies in place, there's still things that can happen. but I think it was the human impact of it that really got me. One of my very close friends had their identity stolen because of that breach, and it made me kind of think about, you know, why is it that this can happen?
4:19Like, how is it that we as consumers are, you know, almost required to trust so many companies with our data every day? Just think about it. You would have to be a hermit to actually not give your data out all the time. But that data is so valuable, and, you know, The breach of it has such an impact on each of us. And I started thinking about it as the best way. Again, I began by saying, okay, I'm going to get my stuff in order. I'm going to get my configurations ready. I'm going to get about my passwords, do all of this stuff. Then I started telling my friends. You kind of get to a point where you realize that the most efficient way to protect consumers is actually to help protect the companies who hold the world's data.
5:01And that is literally how compliance with the Y was born.
5:05Mike Butcher:So also you were chief strategy officer at ContractPod AI and you worked at McKinsey. Lots of McKinsey-ites become entrepreneurs, I've noticed. And so did the problem pull you into entrepreneurship or had you always wanted to become a founder yourself anyway? I literally did not ever think I was going to be a founder. Up until two months before I started the company, I did not think I would have become a founder. It was really a pull from solving a problem. It was really an analysis of a market. And honestly, a little bit. It was something where I knew I was passionate about the problem, and it felt like something that I could never do.
5:47And that was intriguing to me. I kind of felt like I'm young, and I should try to do something that I don't think I can do. And it worked. Right.
5:59Mike Butcher:So for people in the room who are not GRC governance risk compliance experts, let's hear what compliance with a Y is in plain English. What does it do? Yes. First, I want to say compliance gets such a bad rep. Not compliance with a Y, compliance with an I. Everyone thinks it's boring, but I just am here to say compliance is cool. Compliance is sexy. You just have to figure out why it matters. We actually went through a period many years ago on a title I was on where we came up with Sass is Sexy. That's more believable, I think. Yes, I know. It didn't quite land, but anyway. My point is that compliance is really what enables us to trust the world around us.
6:43If you think about what GRC teams do every day, they are basically focused on creating trust with their organization's customers and protecting their organization. And that's really what it comes down to. They think about all of the different standards that they have to comply with to make sure that their customers can trust them. That can be security standards like SOC 2, like GDPR. They think about the risks that are posed to their organization and how they can mitigate those risks so that we can trust them with our data. They think about the policies they have to put into place to make sure that their teams actually stay aligned to those different rules and controls.
7:22and at the end of the day, you know, that makes us be able to trust them and it protects them.
7:28Mike Butcher:So give us a picture of how it's done at the moment and what the radical change is going on right now because of the rise of AI. Absolutely. Let me give you an example and something that I think we can all kind of relate to. I don't know how many of you all have been in an audit before, any type of audit, right? But if you, you know, we all have kind of been maybe around some type of audit before, had to be pulled in, asked for some type of evidence or something. If you think about what compliance used to be, it used to be point-in-time checks of your data to check if you're compliant. So what that means is, you might say, okay, I want to make sure that every employee has antivirus installed.
8:08Okay, well, what are you going to do about that? You're actually, in the way that it used to work, you would go around and say, I'm going to check 10 out of my 1 ,000 employees, and if they have it, that's good. That's a sample size. I'm fine with that. They're checking 10 out of 1 ,000 at one day in one month of one year. And that's how compliance used to run. You kind of set these policies. You have to trust that everyone followed them. And there was no way to do enough follow through. Just thinking of that one example, which is just one tiny part of compliance, what we do now with agents is complete and continuous monitoring.
8:44We're always making sure that, yes, you're not being exposed to risk because everyone in your organization has antivirus turned on and they have these other configurations on as well. And that's what basically automation plus AI actually enables us to do every day. It gives you visibility where you had none and it gives you risk reduction where before you were really exposed.
9:06Mike Butcher:And how is this moving into sort of the agentic era as well? Yeah, absolutely. So let's think about one more example. One of the biggest risks to enterprises right now is their third-party vendors. So again, we talked about breaches. As a company, you trust your vendors to keep your enterprise's data safe. Well, you can't really monitor them all the time. They're not your internal environment. You have no idea what's going on over there. But AI agents can do a lot of that. So we have AI agents that monitor third-party risk. So they can basically go in, they make sure to ask the vendors the right questions, they continuously monitor those vendors.
9:43any sign of risk, they flag it to you so that you can reconsider what data you're sharing with that vendor, how much you want to share with them, how you're going to interact with them if you want to work with them. And that's fully agentic before you had no coverage on that.
9:59Mike Butcher:Okay. I mean, but can these vendors spoof things in some way? Is it almost like a sort of cyber war scenario where they're trying to come back with, you know, spoof the agent into believing it's everything's fine. There's no one agent to spoof in that way. Like the agent is kind of omnipresent, I suppose, looking at hundreds of data sources, thousands, millions of sources of data at one time. So there is no one way to spoof it. You're covering all bases, basically. Now, what about this aspect about AI surfacing the kinds of risks that perhaps companies weren't previously aware of? You said that AI has brought risk and compliance to the boardroom.
10:45Mike Butcher:What is going on there? So I think the first thing I'll say is that AI has made risk and compliance a language of everybody. I think that before, again, unless you're involved in an audit or have worked within an organization, that's gone through a number of audits, you may not have quite understood what is risk management? Why do I need to care about this? But I think what's happened with AI is that we all more implicitly understand the risks of sharing our data with a company. We put in a lot of information into ChatGPT and Claude. I know I do. I'm sure you all do too. My friends tell me they use it for taxes.
11:24They use it for health. They vent. There's a lot of information. relationships relationships I mean you you give you put so much of your personal data in and I think for the first time we're all kind of realizing like oh my god this is really personal people are telling me they're upgrading to paid subscriptions so that they can have more protections like these things are becoming the language of everybody whereas before I feel like they were almost niche points so just right off the bat we've kind of all become more equipped to speak in the language of risk. The second thing I'll say is that before you have, again, sample testing that raises risks across the environment and you rely on people raising the risk or your sample testing catching the risk.
12:10What's happening now is that you have full visibility as a default. So you're not spending your time sampling or searching for risk. You're spending your time addressing risk. And that risk visibility is surfacing the things and you decide what to raise to your board but before you had no no visibility and now all of a sudden you can see and you're spending your time being like look we need to deal with these problems. Not spending your time saying I think we're okay these are some potential issues that we might have and boards prefer that.
12:40Mike Butcher:Is that leading to some kind of heads being blown off moments with some of the companies you speak to going, oh my god, we had no idea what was going on? I do think so in some cases, yes. I think there are a lot of companies out there who can kind of, I think, benefit a lot from the risk that they can see now and they can close them before they become vulnerabilities, which is really the main goal of all this. I mean, is the size of the market must be running into billions, I guess? Billions and billions and billions, yes. The market is huge and it's growing. Every company, every company in the world has risk.
13:18And they're now getting to a point where every company has compliance needs as well. And so, yes, it's a huge market. It's a good space to be in.
13:26Mike Butcher:And I think, is it changing companies in how they deal with it in terms of governance? Are they forming special kind of departments now as a result of this? Or what's going on? They have had departments already for it. Sure, but I mean, different things? Yeah, those departments are often thought of as the people who nag us. It's almost like GRC people always feel very, like they owe the rest of the company because they feel bad because they're always chasing you for something, signing your policy, doing your security training. And so I'm sure you've all been on the receiving end of it. So I think GRC people often feel a bit like, oh, no, we're being annoying to our organization.
14:06But now with AI, they're spending less time doing that because the agents are doing so much of that manual work, which relieves the work for the business owners as well as the GRC team. And now they can feel more elevated in the org. They're having more strategic conversations. So I think they're getting elevated in a way that they just were not before.
14:23Mike Butcher:And is it changing the companies themselves in how employees behave? Is it, I don't know, heightening awareness in some way? So interesting you bring that up because I think we may be seeing the opposite a bit. A lot of companies are using shadow AI right now. It's a very big problem. What that means is employees, I am certainly guilty of it as I'm up here on my high horse talking about this. I'm so guilty of this. I use a couple of AI tools that I know are not necessarily going through the company's norm. I don't put confidential information in them, but I'm using them. I'm sure we're all using tools as well.
15:02And you kind of create a web of shadow AI that's happening. Because your employees, especially at large orgs, you can't control everything that they're doing in terms of their software.
15:13Mike Butcher:You mean they're putting stuff that's going on inside the company into their personal Claude account? To do a better job, right? They're doing it for efficiency. And they want to get a raise. They're doing it, maybe, yes, exactly. But they're doing it because sometimes their organization hasn't caught up yet. They haven't yet signed up for enterprise AI tools or something like that. And so they're feeling hungry. They want the benefit. And so they're kind of setting up accounts and they're doing some of these things. And at more mature companies, there's kind of security configurations on the endpoints.
15:42But, you know, at a mid-sized company, maybe not. And so you're getting kind of the shadow AI network that's happening, which is a huge risk, by the way.
15:51Mike Butcher:Is that something you probably, how can you have visibility into that? It's really, really hard. That's actually where you have to rely more on training, more on awareness. And as I like to say, you know, REI agents allow GRC teams to do some of that stuff because they no longer have to chase everybody for policy signing. So, yeah. Let's get into your journey as an entrepreneur. Now, you didn't just raise a Series A led by Google Ventures out of the box. Tell us a bit about how you got there first. Yes. Very luckily, I would say. So I think one thing is we've been very lucky to have a preemptive seed round and a preemptive series A round, which means that the investors came to us and we didn't have to pitch.
16:35So I haven't made a pitch deck in a long time, which is a really nice thing.
16:39Mike Butcher:A lot of entrepreneurs have been quite flabbergasted at that. I know, I know. And it's a very different model. Absolutely. It's a very, very different model. And I'm happy to talk about a little bit more. But that's the that's the quick story of it. Well, no, I think you're going to have to tell us now because this is a secret a lot of people would like to understand. Yeah. Okay. I think some of my friends asked me this, so I'm going to try to break it down the way that I like to share it with my friends. I think it goes back to whenever I'm thinking about the business, whenever I'm thinking about investments, I'm often thinking about what are the incentives for the person on the other side of the table.
17:19And a lot of it is based on that. And so if you think about earlier stage investors, of course, of course, of course, their incentive is to invest in a company that skyrockets and does great. Don't get me wrong, we all are aware of that. But there's also something at earlier stage where it's about the vibe, right? I'm gonna use a Gen Z phrase that I learned recently. It's like aura. It's like, you know, it's your aura. So if you're an investor, and I know there's some in the room, so maybe you can tell me if I'm right or wrong. as an investor, you also want to get the ins to the companies that no one else got the ins into, right?
17:55You want to have access to the founders and to the information that no one else got. Okay. Well, that's something that's in our control as founders. We can control that. We can control the supply of information out into the investor market and make sure that we can win on some of those incentives. So the investors kind of network out there is a grapevine. You tell someone something, I feel like everyone kind of knows it. And it's good. You know, they're sharing information. That's great for them. But we are founders and we need to protect ourselves and our businesses. So the way I see it is that there's a lot out there that you can't control.
18:32You can't control when an investor has just raised a fund, how much they want to deploy, what their theses are. You just you can't control that as much as we want to. But you can control some things. You can control your aura and therefore the aura that you kind of transitively pass on to the investor when they invest in you. So let's make it really practical. I don't share data about the company with anybody. I don't answer investor emails. When I do, I say, hey, and I'll give you guys the exact word I use. I always say, you know, I'm really underwater right now or I'm really heads down right now and I'll message you when I'm coming up for air.
19:07That's just what I say. I don't give any other information. I don't take any meetings. And what that does is that no one really knows any of the specifics about us out there. They just kind of know that we're not talking to anyone. And then when someone really interesting comes knocking, that person gets the information after a period of relationship building, which I'll get into in a minute. But when they get the information, they know that no one else knows it because the VC community is like so intertwined. Because now you're a black box. Now you're a black box. And they're the ones who got access.
19:38And that's already a win now for you, right? Now that's something that you've controlled in the dynamic between you and this VC. You've not given your information to anyone. When you start speaking with them, don't, I mean, this is one person's opinion. I won't say it, but I would say don't go in with the data room prepped and ready for them. That's not how you win on relationship. Go in and understand, you know, they owe you as much is you owe them. Why did you come to me? Why are you interested? What's your thesis? Why do you think that we're going to win? Ask them the questions. It's an even playing field.
20:13And by doing that, there is just more buy-in that gets developed. You build a relationship. Then you share your numbers and your data once you have also gained the trust and they have gained your trust. And I think that that really changes the dynamic. Way too many founders I know are doing, it's an entire job to just do VC meetings. And they have their data room ready to go. They have their pitch deck ready to go. Why? Why? You have a business to build. Focus on that. I feel very privileged saying all of this, by the way, but it's my personal advice and it's worked for me now for two funding rounds.
Read the full transcript
20:50Mike Butcher:Would you say that's more of a Silicon Valley playbook than a lot of European founders kind of get that a little bit wrong? Very interesting question. I definitely think that it is more of an American playbook. But I don't, I actually know, you know, my American founder friends, I don't think are doing this to this extreme. I think it is a bit risky. But it is what it is. And it is also a function of how European VCs tend to go, give me your kind of two-year predictions, blah, blah, blah. Yes, but that's not been my experience, right? I think that once you, I think a lot of European founders just go in with so much information that then that becomes the conversation.
21:32Like, make the conversation about your vision. Make the conversation about you. Make the conversation about them, by the way, also. And then share your data. And keep in control of that. Like, don't overshare first. You know, it's your business.
21:46Mike Butcher:AI is flooding the market. You know, there's a new update. Last week ago, everyone said, said use poor code everyone said now move to chad gpt i was like what's going on um and you know so that's that's at the sort of the consumer end but also at the business end we've also got the issue that um creation costs are collapsing you've got big tech they release a feature i mean there's the whole stuff about uh the anthropic mythos uh which is almost like a marketing play if you ask me but the you know whether or not a new feature update in fact a few weeks ago Anthropic released a feature to do with law and all of a sudden a bunch of laws a floated law companies collapsed they did something around design and Figma's share price collapsed and that's all going on at one end and at the other end you've got some teenager in a in a spare bedroom coding on lovable and and vibe coding, and because he or she is 17, the VCs think they're the next big thing.
22:52Mike Butcher:So what are we going to do? How do you think entrepreneurs should sort of approach this right now, because it's almost like we're in a different kind of era right now? It's a really tough question, and I think you almost have to go back to the basics in a time of such change, and it really is a time of such change. I used to, at ContractPod, do strategy, and I did GTM. And even just removing myself from company building for a minute. I used to know enterprise B2B SaaS, GTM playbook like the back of my hand. I could do the math out of my head. I knew exactly how to hire and exactly what to do. That's totally upended as well.
23:32I mean, you have to learn everything new. It's not just the company you're building. It's every function within the company you're building. It's how the customers are thinking. Everything is changing. It's really exciting and really difficult time to be an entrepreneur right now because of that. But my advice is really, you got to go back to basics in a time of such change. And the basics are, you got to know your customer, and you've got to understand the problem that they're facing. If AI is solving part of the problem, understand the version of the problem that they're going to still face.
24:02You have to know it, and you have to make sure that your product is addressing whatever version of that problem is left. And it may be a slightly new problem. Maybe it's a slightly adjacent problem. Maybe it's 80%, 60 % of the first problem. I don't know. That depends on you. But there's still something that you need to solve for. And you just have to make sure that your product, your solution, is actually meeting that problem. And honestly, the basics of PMF, I think, are going to be what carries us through.
24:30Mike Butcher:And another aspect of this is that AI native startups, which is what you are, also seem to be different to a previous generation of companies. You're doing everything AI natively, you know, internally as well as externally. What's your perspective on that and what that's done to being a founder? You know, it's actually really interesting. It keeps us efficient. I just had a board meeting shortly before this, and I was looking at our efficiency numbers like, wow, you know, it's crazy what you can do now these days. You can really focus on hiring high talent density individuals who can really leverage AI to continue to expand the work that they're doing and make more and more impact.
25:15It's actually amazing. You know, our sales team looks different. Our engineering team looks different. Our implementation team looks different. Every function has been transformed based on these tools that we now have. and it's actually crazy. It's crazy how fast it happened.
25:30Mike Butcher:You're going to have a similar problem to all those corporates who are no longer hiring junior developers or is that going to be an AI native startup problem as well? So I, before, at McKinsey and afterwards, I worked in economic development, which is the creation of jobs and I worked actually for a state in the US doing that. So this topic hits me really hard. It's a really complex one and I actually think there needs to be a lot of policy discussions around how we support newer generations of the workforce in this world, and that's an entire conversation in itself. I don't think we're doing a good job right now.
26:06Mike Butcher:Well, it seems like we're just crawling out of the ocean on this whole subject, and, you know, it's maybe even a year ago that this subject wasn't even that front and center, but it just gets more and more, doesn't it? It didn't even exist. No, absolutely. But let me draw this to the point where you've raised this$20 million led by Google Ventures and you're now planning to expand. Give us a picture of where you're going next. Yeah, what an exciting time, honestly. We are really focused on building the next generation enterprise GRC platform that is actually really end-to-end agentic run. I mean, that sounds a little crazy to say out loud, but we are talking agents who can do all of your audit prep for you, agents who can write your policies, get them out there, agents who can monitor your third parties, agents that can surface risk.
27:04And we want to elevate the GRC team to really be focused on the whys behind compliance instead of being focused on all of the manual busy work. We got a long road ahead, but it's
27:17Mike Butcher:Is that going to change the nature of business in a way that we're not quite predicting? All of a sudden, maybe heavy lifting, perhaps the EU suddenly gets easier to operate in, for instance. Yes, very true. I mean, I suppose that's a Shangri-La, right? That's exactly right. And it's actually going to go beyond that. I mean, that to me is almost a stepping stone on the way to really understanding businesses' risk profiles and being able to meaningfully reduce the number of breaches that we read about every day. Because if you're spending all of your time currently doing manual busy work on compliance, you can shift all of that attention to actually dealing with the risks that have been teed up for you.
27:59You are now completely transforming your ability to protect your organization and your consumers. And that is the Shangri-La.
28:08Mike Butcher:Well, there you go. And five years ago, I thought the whole thing would be solved by blockchain. and many other people did as well. Richard Call, thank you very much for being on PathFounders. Absolutely. Thanks for having me. Hi, my name's Ed. What doesn't scale with AI? You've got 40 people. What isn't scaling? What isn't scaling? I would say articulation of value delivery to really senior stakeholders. And I think that's becoming increasingly important in a world of AI because obviously, as we just discussed, they have a lot of optionality now. Clients have a lot of optionality now to use different tools.
28:46They can use CoPilot instead of your tool. Obviously, you should build a tool that's good enough that that doesn't happen. But you always need to be articulating the value that you're delivering to the most senior people who are in the room when making those types of choices. And that doesn't scale. It's really human. In fact, kind of what I've told the team is like, look. Hi, Risha. I'm Fiona.
29:06Mike Butcher:China, Chinese court has ruled that firms can't lay off workers on the grounds of AI and replace them with agents. You mentioned that you thought we needed to support people, future generations who are coming into an AI environment. Do you think that's the right intervention or what interventions would you propose? It's a really tough question. It is an interesting intervention, I think. I think that right now trying is better than sitting on our hands. I think that we have a lot more to learn. AI is changing every day. And I think we have a lot more to learn before we are even going to be in a steady enough state to make the right policy.
29:46So to me, an intervention is still trying. And I think it sends a signal that, look, we're not trying to end up in economic development disaster here. We're trying to keep people in jobs. And I think that's really good. I think that companies can focus a lot more on how do we reallocate the efforts of people to things that are more strategic if we have these agents to do things that are more manual. So I think it's a good step.
30:13Mike Butcher:Over here. So my name's Chloe. I work in product marketing. So I'm a typical SaaS product marketer. So that's why I'm here. And I don't think you quite answer the question. How are we seeing the end of software as a service as we know it today? I mean, I don't want to say we're seeing the end of it. I can talk about this all day. Let me try to summarize two quick points. The first point is that I think we're moving from software being a system of record into software being a system of action. And I think if people are not making that switch, then they're going to be left behind. But I don't think that's the end of SaaS.
30:49I think that's just a new iteration of it. My second point is that in a world, this is kind of how I say it to my team, we used to sell a software in which the clients did their work. Now we sell a software that does work itself. And so at that point, you start to converge with selling outcomes instead of selling software. And that reminds us all more of a services company. You buy a service, you buy an outcome. And that's okay. That's completely okay. And so I think those points together bring us to saying, SaaS is moving towards outcomes. I actually think we're going to kind of be better for it because it's a higher bar and you have to deliver it with trust.
31:29Mike Butcher:So you said that your pipeline, this compliance pipeline, is fully run by agentic AI. Where's the human in this? Where are the agents getting audited? You mean from the perspective of when we deploy? Yes. Yes. Great question. There's a few things. Humans are always in there to make the decisions, right? So when we think about that, you said example about risk. The humans were previously spending time basically hoping to catch risk. What I mean by that is, you know, hoping to catch moments of, I should say, risk exposure is what I should actually say it. And now they're instead flipping to being able to address the risks that get raised by AI.
32:07That's work that AI can't do. Going back to, like, what does not scale, AI can't then solve the problem unless it's a quick, you know, configuration on or off. But it's usually not. It's a multifaceted, difficult human problem to solve. And only humans can do that. So that's one. Love your question about who audits the AI. It's very meta for me to say this, but compliance audits the AI. As in not compliance with a Y, compliance with an I. That's the point. You go through these audits to actually, that's what we all do. All tech companies go through audits to make sure that your product is actually safe and secure and acting on certain principles.
32:41There's been new standards that have come out, like ISO 42001 or AIUC1, which are actually built to test your AI and how good it's doing.
32:49Mike Butcher:Rishina, thank you for sharing your knowledge. and dear Dan Key Founder at Alchemy Machines. Just to follow on from that question, in addition to the human in the loop, are you mixing a deterministic approach for mapping out workflows with the agentic layer? Or are you sort of, beyond the human in the loop, are you using some other hybrid approach or is it purely agentic? Great question. So especially when you're working with enterprises and especially when you're working in such a nuanced topic as GRC and compliance, you need to make sure that your client can trust the output. And that means that a fully agentic workflow is always going to be non-deterministic and therefore can't be trusted to 100.000%, right?
33:33It might be 99.999, but it's not 100.00. And so we have to retain elements of determinism in that workflow through guardrails on the AI, reduced context that basically assures certain outputs, as well as just using automation in certain places, not agentic features, to make sure that they're getting very clear point A to point B. Even if the route might look different based on the agent, they're still getting to point B. But that's a really good question. Thank you.
34:02Mike Butcher:Okay, we have got time for maybe one more question. Go. Hi there. So it feels like a conversation I have at home because my wife also works in compliance. Yes, sometimes we have a chat about these things. So what we were chatting about, and I'm really curious to hear your take on this, July 6th or 16th, I'm not aware of the date, but there's an EU AI Act that's coming into force. So I guess two subtopics to this question. Do you think organizations are going to have their AI compliance departments as they have for privacy or for other areas in the future? Because I know it doesn't exist today in 99 % of the companies.
34:41Mike Butcher:And the other one is, how do you think, how serious is this EU AI Act is going to be taken? And what opportunities do you think it rises for other companies out there? Oftentimes when compliance changes come via regulation, like through the EU AI Act, they go to the legal department instead of the compliance department, which is just an interesting thing that happens. Legal almost becomes the translator. They take the regulation code or text and they kind of translate it into things that the company needs to do. And that's the point where the compliance team almost picks up the baton. And that's interesting.
35:18I don't know that that's how it should be, but that's just sort of how it has been. And what's interesting is that in that process, you often kind of, I'm going to use the word, lose a little bit of the compliance side of things. And you end up being kind of following the letter of the law, which is good, of course, and we need to. But there's a lot more behind it. I'm going to use GDPR as an example. If you read the GDPR text, which I have done, it's actually quite vague, right? Because it's about the spirit of each of those controls. And a GRC person interprets that very differently than a legal person.
35:52A legal person interprets it in a way that actually creates more, I think, weight and almost baggage for the organization versus like a more pragmatic kind of practical compliance view on it. Not to say that either is bad. of this is different. And so I think that that's kind of what's going to happen with the EU AI Act. I feel like it's going to feel very heavy when I think it's meant to be more guiding. And I do think that, honestly, there are a lot of things that will still need to be improved in it. I've read it. And I think that, yeah, I just think that the pace of AI is changing so fast that, as I said before, like policies are almost right now a good stepping stone, but we've not become steady state enough to understand everything that's required okay last two questions we'll
36:39Mike Butcher:keep them brief and the answers okay what's um your favorite ai tool that you're using at the moment that people might not have heard of and that is really having an impact oh that's such a good question i there's a couple of niche ones but i need to look them up more to be able to openly endorse them. So I won't. There's a couple of GTM tools that I'm using, though, that I just love. So I'm going to be a little bit lame and default to saying that, you know, Claude is just my favorite LLM and I use it every single day. Last one. Where are your negative feedback loops? What happens if you get it wrong?
37:18And who's accountable? Yeah, from an AI perspective? No, from a compliance perspective.
37:23Mike Butcher:If the policy that you create, Oh, you know, if things slip through the net, whose fault was it? That's interesting because we don't really see it that way, like in the sense that the way that we've built our agents, the infrastructure that we've built and the prompts that we've used and sort of the guardrails that we've built. It's almost like we have near zero, I would say, chance of it being, quote unquote, wrong from a compliance perspective. I think that what's important is that there's approvals built in. So what we've done with our AI agents is that they can't even finalize something unless they get a human approval.
37:57And we communicate to our clients that it's more than human in the loop. It's like judgment required, right? Like human judgment required, must have. And so you kind of put the responsibility on the client because it needs to apply to them in the right way. And that's versus like the AI won't be wrong from a compliance perspective. At least we haven't seen anything like that.
38:19Mike Butcher:Amazing. Right. right thank you so much everyone thank you so much to Richard Call for coming to Pathfounds thank you very much to our sponsors Nebius and Halkin and we'll hope you join us for another Pathfounds podcast soon
From the publisher
Pathfounders Live: With Richa Kaul, Founder & CEO of Complyance, in conversation with Pathfounders Editor Mike Butcher, followed by a live audience Q&A.
Subjects covered during the interview and Q&A:
* Why compliance is suddenly becoming a boardroom issue
* How AI is changing governance, risk and compliance
* The hidden danger of employees using “Shadow AI” via their personal accounts
* Why third-party vendors are now one of the biggest enterprise risks
* How AI agents can monitor company risk in real time
* What the Equifax breach taught Richa Kaul about consumer data
* Why protecting consumers means protecting the companies that hold their data
* How Complyance raised a $20M Series A led by GV
* Richa’s unusual fundraising strategy, informed by a Silicon Valley playbook
* Why founders may be oversharing with VCs too early
* Whether SaaS is dead, or simply being rebuilt around AI agents
* The shift from software as a “system of record” to a “system of action”
* Why AI-native startups operate differently from traditional SaaS
* How AI is reshaping sales, engineering and implementation teams
* The future of junior jobs in an AI-powered workforce
* Why compliance teams may actually become more strategic, not less relevant
* How the EU AI Act could reshape enterprise compliance
* Why legal and compliance teams interpret regulation differently
* Why fully agentic systems still need guardrails and human judgment
* Who audits the AI — and why AI governance standards matter
* Why the future of software may be about selling outcomes, not tools
* What still does not scale in an AI-native company
* Which AI tool Richa Kaul uses personally
Thanks to our partners for supporting this event:
Halkin Offices: For a prime address, exceptional workplace design, and award-winning customer service - all under one roof. Just contact Oliver Kingshott on oliver@halkin.com
Nebius: Nebius is building the ultimate cloud for AI, with a single platform that spans the entire AI journey — from data and model training and tuning to production runtime and deployment. To find out more please contact their team.


