In the interview with Marco Wehler, CEO of DextraData GRC Technologies

In an era where companies increasingly face complex regulatory requirements, the integration of AI, and the need for resilient digital transformation, one topic is gaining strategic focus: Governance, Risk, and Compliance – GRC for short. While still perceived in many organizations as a necessary evil and purely regulatory obligation, Marco Wehler, Managing Director of DextraData GRC Technologies, views it as much more: namely as an essential lever for sustainable corporate governance, digital sovereignty, and trustworthy structures in the age of artificial intelligence.
In an interview with Silicon Valley Europe, Marco Wehler explains why GRC must not be seen as an isolated discipline but must be regarded as a dynamic cross-cutting topic between management, IT, legal, and operational departments. As an economist with a solid consulting expertise, former entrepreneur, and former CPO at DextraData, he combines technological foresight with in-depth business knowledge. His key message: GRC does not belong in a mere compliance box – but at the heart of strategic corporate development.
DextraData GRC Technologies, based in Essen, is a specialized provider of modern, software-based GRC solutions. As part of the DextraData Group, the company pursues a clear mission: to not only digitize GRC but to rethink it – driven by KPIs and metrics, automated by AI... with the goal of innovatively combining regulatory requirements with calculable business benefits. At DextraData GRC Technologies, GRC is not seen as an obligation but as an active driver for efficiency, trust, and future viability. In the interview with Marco Wehler, we discuss “Beyond Compliance” – GRC as an active resource of corporate strategy, the role of GRC for trust, efficiency, and resilience – especially in the context of AI and automation – and clarify why technology alone does not create governance – and why leadership and corporate culture are decisive.
Silicon Valley Europe: Many companies still view GRC as a necessary evil. What is needed for GRC to be understood as a strategic success factor?
Marco Wehler: A pure "check the box" approach falls short in the GRC context. Those who only react will always be one step behind. It becomes strategic when senior management recognizes: GRC is not a brake block, but a navigation system. It shows where risks lurk – and where opportunities lie. That is the difference between managing and shaping. It is therefore necessary to think strategically about GRC from the very beginning.
Silicon Valley Europe: In the context of today’s ultra-fast AI development, GRC must certainly be considered separately. How can GRC help secure trust – how does that work?
Marco Wehler: AI must not be a black box. McKinsey found in their AI Trust Study (May 2025) that explainability, fairness, data privacy, and governance are the key elements for AI to be used effectively and trustworthily – it simply won’t work without them.
The latest McKinsey study (“State of AI,” March 2025) clearly shows: When the C-suite actively takes on AI governance, this is the factor with the strongest influence on economic success through AI – stronger than technical measures or pilot projects alone (Link to the study). GRC only becomes strategic when it is not sidelined but tailored and integrated by leadership.
GRC provides exactly the framework for this: who makes which decisions, how systems were trained, and who is responsible for which decision – this creates security all the way to auditability.
Silicon Valley Europe: What does “Beyond Compliance” mean in concrete terms for you – and how does this approach impact day-to-day business practices?
Marco Wehler: Beyond Compliance means: We stop just meeting the minimum requirements and instead build structures that will still hold up in three years – no matter what comes. This isn’t a luxury, it’s a survival strategy. Those who only do the bare minimum will always be playing catch-up with developments.
Silicon Valley Europe: Why, in your view, is it crucial to approach GRC not in isolation but as a cross-cutting topic spanning IT, Legal, specialist departments, and senior management?
Marco Wehler: Because problems never stay neatly tucked away in one drawer. An IT incident has legal, operational, and often communicative consequences. A compliance error can stem from a poorly documented process. When departments don’t talk to each other, dangerous blind spots emerge. GRC must connect all perspectives – otherwise, it’s just patchwork.
Moreover, senior management bears particular responsibility: they are not only morally but also legally liable for failures in governance, risk, and compliance. Those who dismiss GRC as purely the domain of a specialist department overlook this personal responsibility – and risk serious consequences for both the company and themselves.
Silicon Valley Europe: In an increasingly AI-driven economy, what demands does GRC face to ensure trust and transparency?
Marco Wehler: AI is here to stay and offers fantastic potential in every company. GRC creates trust and security precisely at this point. We often hear: AI must not be a black box. That’s too sweeping. Many of our processes aren’t business-critical. In these cases, transparency is often less important than the sheer acceleration AI provides. GRC’s task is to evaluate processes against clear requirements and categorize them accordingly. If business-critical data is used and the project outcome is vital to value creation, or if there are special regulatory requirements, then the AI systems deployed must meet particularly high standards for security, reliability, and transparency. Equally, for processes categorized differently, we can afford to loosen the reins significantly in line with risk assessment. This already happens in day-to-day business practice. AI simply forces us to systematize and institutionalize this approach. That’s exactly what GRC is for: enabling efficiency gains through technology while protecting critical processes according to their importance.
Silicon Valley Europe: What does technological sovereignty mean to you – and how can GRC help strengthen it in European companies?
Marco Wehler: It means keeping the reins in your own hands. Whoever completely outsources its key technologies not only gives up control but also independence. GRC helps make these dependencies visible – and take corrective action in time before ending up in a dead end.
Silicon Valley Europe: What role does the European location play in terms of GRC innovation and regulatory independence?
Marco Wehler: The Western tech world is shaped by the US. There’s no doubt about that. In this world, GRC innovation is lacking because the business models of tech giants are based on unrestricted collection and use of third-party data. Europe has the opportunity to set a counterpoint here and become the “Switzerland of data sovereignty and security” for the world.
The GRC philosophy in Europe is far more developed. We have the GRC thought leaders in the world. At the same time, we are strong in capital, innovative, and enjoy high prestige worldwide. The European standard has the potential to become an export hit and a home for all those seeking a secure place for their data. If we leverage this, we create real competitive advantages with GRC from Europe.
Silicon Valley Europe: How can transparency, traceability, and auditability be ensured in AI systems – and what role does a modern GRC approach play in this?
Marco Wehler: Without documented processes, any trust discussion is an illusion. We need to know: Which data was used? How was the model trained? Who approved changes? GRC provides the framework for this. Those who ignore this can already mark the next crisis meeting in their calendar.
Silicon Valley Europe: Why is it not enough to simply introduce a GRC tool? What is still missing in many companies?