Overview
Richa Kaul is CEO and Founder at Complyance, a position Kaul has held since October 2022 [1][2]. Prior to founding Complyance, Kaul held multiple roles at ContractPodAi, serving as Head of Strategy from January 2020 to January 2021 [5], Chief Strategy Officer from January 2021 to July 2022 [3], and Chief Revenue Officer from April 2021 to April 2022 [4]. Kaul's earlier experience includes work as an Engagement Manager at McKinsey & Company from October 2017 to April 2018 [8] and as a Senior Business Analyst at the same firm from September 2015 to September 2017 [9]. Kaul also served as Managing Director of Technology and Corporate Services Sectors at the Virginia Economic Development Partnership from May 2018 to January 2020 [6] and worked as an Independent Consultant for The World Bank in May and June 2019 [7]. Kaul holds a Bachelor's Degree in Economics and Business Administration from Boston University [10].
Career history
- CEO & FounderOct 2022 to presentComplyance
- Chief Strategy OfficerJan 2021 to Jul 2022ContractPodAi®
- Chief Revenue OfficerApr 2021 to Apr 2022ContractPodAi®
- Head of StrategyJan 2020 to Jan 2021ContractPodAi®
- Managing Director, Technology and Corporate Services SectorsMay 2018 to Jan 2020Virginia Economic Development Partnership
- Independent ConsultantMay 2019 to Jun 2019The World Bank
- Engagement ManagerOct 2017 to Apr 2018McKinsey & Company
- Senior Business AnalystSep 2015 to Sep 2017McKinsey & Company
Education
Bachelor's Degree, Economics & Business AdministrationBoston University
Insights & ideas
The through-line
Richa Kaul's whole argument starts from a consumer, not a control framework. A close friend had their identity stolen in the Equifax breach, and the chain of reasoning that followed took her from tightening her own settings, to lecturing friends about theirs, to the conclusion that "the most efficient way to protect consumers is actually to help protect the companies who hold the world's data" [1]. Everything she says about governance, risk and compliance runs back to that: compliance is not paperwork, it is the mechanism by which strangers can safely hand over their data, and she has repeatedly framed it as the line standing between customers and the next Equifax-scale incident [1][6].
The second constant is impatience with how the work has actually been done. She describes a discipline that historically sampled ten employees out of a thousand, once a year, and called it assurance [1], and she argues that AI agents make continuous, complete coverage the default instead. What has shifted over time is the audience: what she once had to explain from first principles is now, she says, something everyone intuitively grasps because everyone is pouring personal information into chatbots [1], and GRC has moved from cost centre to strategic asset in the boardroom [7][11].
On why the company is spelled with a Y
The name is an argument. "Those who really understand the space know that compliance with an I does not equal security," she says. "Compliance should be a byproduct of good information security practices and sound internal processes to protect your customers data" [2]. The Y is the reason behind the exercise: risk reduction and protection for customers [2]. She is equally blunt that the field has an image problem it half deserves, and she pushes back on it directly, insisting that "compliance is really what enables us to trust the world around us" [1] and returning in conversation after conversation to the gap between what GRC actually is and what companies pretend it is [5][3][10]. What GRC teams do all day, in her telling, is create trust with their organisation's customers and protect the organisation: mapping to standards like SOC 2, ISO 27001 and GDPR, mitigating risks, and writing policies that keep teams aligned to controls [1][2].
On protecting consumers by protecting enterprises
She calls herself a data privacy nut and means it socially as well as professionally: she will ask friends and family whether their phone privacy configurations are up to par, and rejects cookies as a matter of routine [1][2]. Her standing party trick is a genuine piece of advice, to open the phone's settings and look at which apps have microphone access, then do the same for camera, on the grounds that it takes seconds and explains a lot about the ads people see [1]. The founding insight was that this individual diligence does not scale. Consumers would "have to be a hermit" to avoid handing data over constantly [1], the data is enormously valuable, and the breach of it lands on individuals, so the leverage sits with the enterprises holding it. She is careful not to moralise about incidents: "there's no breach shaming here," she says, because even with the right security policies in place things still happen [1].
On continuous monitoring replacing point-in-time checks
Her clearest explanation of what has changed is the antivirus example. Under the old model, you set a policy, trusted that everyone followed it, and verified by checking ten of a thousand employees: "They're checking 10 out of a thousand at one day in one month of one year. And that's how compliance used to run" [1]. There was no way to do enough follow-through. Agents replace that with "complete and continuous monitoring", always confirming that configurations are actually in place across the organisation. The payoff, she says, is that "it gives you visibility where you had none and it gives you uh risk reduction where before you were really exposed" [1]. Work that took weeks or months collapses towards real time [1], and she has argued that this makes manual GRC, with its screenshots and questionnaires, a dead end [6][7]. She frames the underlying architecture as modular AI systems rather than a single monolithic tool [8].
On third-party vendor risk
She names third-party vendors as one of the biggest risks facing enterprises right now, precisely because they sit outside the boundary you can see: "you trust your vendors to keep your enterprises data safe. Well, you can't really monitor them all the time. They're not they're not your internal environment. You have no idea what's going on over there" [1]. Agents can cover that gap by asking vendors the right questions, monitoring them continuously, and flagging any sign of risk so the customer can reconsider what data they share, how much, and whether to keep working with that vendor at all. "Before you had no coverage on that," she says, and calls this part of the product fully agentic [1]. Asked whether a vendor could spoof the agent into reporting all clear, she rejects the premise: "There's no one agent to spoof in that way," because the system is looking at hundreds, thousands, millions of data sources at once [1]. She has applied the same lens to consumer-facing incidents, using the Discord breach to show how third parties end up exposing passports and identity documents, and what companies can do to prevent that loss [9].
On AI putting risk in the boardroom
Two things changed at once, in her account. First, vocabulary: "AI has made risk and compliance a language of everybody" [1]. People feed taxes, health questions, relationship problems and venting into ChatGPT and Claude, and are upgrading to paid subscriptions specifically for stronger protections, so the risks of handing data to a company are now felt rather than explained [1]. Second, the reporting changes character. Where boards once heard the output of sample testing and whatever someone happened to escalate, full visibility as a default flips the conversation: "You're not spending your time sampling or searching for risk. You're spending your time addressing risk" [1]. Leaders arrive saying these are the problems we need to deal with rather than "I think we're okay. These are some potential issues that we might have" [1], and she is unambiguous that boards prefer that. She concedes this produces moments of shock for companies seeing their exposure for the first time, and treats that as the point: closing risks before they become vulnerabilities [1]. The market for it, she says, is huge and growing, because every company has risk and increasingly every company has compliance needs [1].
On elevating GRC teams
She is sympathetic to the people doing this work and how they are perceived. GRC departments already exist, but "those departments are often thought of as the people who nag us", forever chasing colleagues to sign a policy or finish security training, and the teams themselves often feel apologetic about it [1]. Automating the manual chase relieves both sides, the business owner and the GRC team, and lets those teams have more strategic conversations. "Now they can feel more elevated in the org," she says, "they're getting elevated in a way that they just were not before" [1], which is the same shift from cost centre to strategic asset she describes elsewhere [7][11].
On shadow AI
Asked whether all this visibility is making employees more careful, she says the opposite may be happening, and includes herself in the indictment: "I am certainly guilty of it as I'm up here on my high horse talking about this" [1]. She uses a couple of AI tools that are not part of company norms, without putting confidential information in them, and assumes most people do the same. The cause is not malice but ambition and lag: employees want efficiency and want to do a better job, and their organisation has not yet signed up for enterprise AI tools, so "you kind of create a web of shadow AI that's happening", which she calls a huge risk [1]. Mature companies have security configurations on endpoints; mid-size ones often do not. Her honest answer on visibility is that it is very hard, and the fallback is human: "That's actually where you have to rely more on training more on awareness" [1], which is only possible if agents have freed the GRC team from chasing policy signatures.
On becoming a founder she never intended to be
Up until roughly two months before starting the company, she says, she did not think she would ever be a founder [1][2]. What pulled her in was the problem and a market analysis, plus something more contrarian: "I kind of felt like I'm young and I should try to do something that I don't think I can do and it worked" [1]. She thinks foundership requires a degree of wilful blindness, since "there's some just blind conviction and you have to be a little bit blind in order to fully disrupt your life by taking the leap to become a founder" [2]. She had also told herself she would bootstrap if she ever did it, and did the opposite [2]. Her assessment of the experience is even-handed: it has exceeded expectations in places, particularly the pride she takes in the culture the team has built, and been far tougher in others, mainly the relentless volume of unexpected admin that lands late at night or on holiday. Her way of holding both is to remember she chose it: "it's a really really big game and so are you ready to play it and if not that's okay too" [2]. She credits her Chief Strategy Officer role at contract pod as the bridge from McKinsey and government ways of thinking into startup execution, and describes that title as a fancy way of saying she got to help across every function [2]. She is also clear that the unlock has been people rather than personal capability: her first priority as a non-technical founder was finding the best CTO, which she found in Hugo Naggua, who has been there from the beginning and thinks about the product from the user, scalability and enterprise perspectives at once [2].
On building the product by listening
The early method was validation before construction. She spent the months before and after starting the company talking to as many people as she could who manage information security compliance, and still returns to her notes from those calls [2]. She had run compliance for contract pod herself, which gave her one window, but she wanted to know what it meant at enterprise scale for everyone else [2]. To get closer, the company sold a relatively low-cost service helping mid-market and larger companies attain SOC 2 and other certifications, which embedded them in real business models and surfaced the pain first-hand [2]. That insight fed back to the CTO and shaped what to build first, deliberately something minimal, "the not even the bicycle like more like an axle version of this product", released even at the cost of some discomfort in order to get market feedback as fast as possible [2]. She insists the method has not changed: "that methodology of listening to the clients hearing the problem and building the solution for the problem has served us from day one and we still do it today even for the smallest features" [2]. In a crowded and hot GRC tech market, her stated basis for standing out is innovation, support and a product that delivers, including using AI privacy best practices in how the AI itself is built [2].
On raising money by controlling the aura
Both her seed and Series A were preemptive, meaning investors came to her: she has not made a pitch deck in a long time, and the $20 million Series A was led by Google Ventures [1][2]. She does not treat this as pure luck, and explains it through incentives: "whenever I'm thinking about investments, I'm often thinking about what are the incentives for the person on the other side of the table" [1]. Early-stage investors want the returns, obviously, but they also want the ins that nobody else got, access to founders and information others do not have. That, she argues, is the part founders control. Investor networks share information freely, which is good for them, so the lever is supply: "I don't share data about the company with anybody. I don't answer investor emails" [1]. You cannot control when a fund closed, how much it needs to deploy or what its thesis is, but "you can control your aura and therefore the aura that you kind of transitively pass on to the investor when they invest in you" [1].
She chose VC over bootstrapping despite her earlier intentions, because in a busy GRC market momentum and the ability to hire the best talent both cost money, and the pre-seed is what let her start working with her CTO [2]. When choosing between term sheets, including two competing ones, the decision was about individuals: "we chose based on the person, not based on the fund", even while ending up with recognised names like HV Capital and Speed Invest [2]. She also thinks the relationship works better for it, telling European investors, half jokingly, that as an American founder she cares somewhat less what her VCs think, and that this makes for partnership rather than management [2].
On raising as an American founder in the UK
She came to the UK by happenstance when her husband's job relocated them at the end of 2019, stayed for the quality of life, and started the company organically without much prior plan [2]. Jurisdiction mattered less than people assume for the product itself, since the standards Complyance covers, ISO 27001 and SOC 2 among them, are not federally regulated in either the US or the UK, and most of the client base is American [2]. Where it mattered was the company's backbone: a US-only build would have meant US-only investors, and with them different valuations and round sizes [2]. Instead the company runs three hubs in New York, London and Berlin, which she values for diversity and global perspective, for covering the global teams enterprise clients run, and for the pricing and resourcing arbitrage of operating outside the US [2][12].
She is direct about the gender dimension without claiming to have solved it. Her own round was unusually easy, and she puts much of it down to luck rather than to prior relationships, which were with later-stage VCs and did not translate directly [2]. She found herself on a 2023 list of the five female founders who had raised the most money on the strength of a pre-seed alone and thought it was plainly wrong: "there's no chance that I should be on this list" [2]. Her working theory about her own experience is posture. She says she raises "money like an American founder", carrying American expectations of valuation and round size into the room, and suspects that is what she exudes [2]. The advice she gives the female founders she coaches follows from it: "expect more from the people across the table from you. They're expecting so much of you. You should expect more of them" [2].
Takeaways
- The founding logic is leverage, not altruism: protecting consumers at scale means securing the enterprises that hold their data, an idea that came directly from a friend's identity being stolen in the Equifax breach [1].
- Compliance with an I does not equal security; compliance should be a byproduct of good information security practices and sound internal processes [2].
- Old-model assurance meant checking ten employees out of a thousand on one day of one year; agents replace it with complete and continuous monitoring [1].
- Third-party vendors are among the biggest enterprise risks because you cannot see inside them, and agentic monitoring covers ground that previously had no coverage at all [1][9].
- Full visibility changes the board conversation from "I think we're okay" to a prioritised list of problems to address [1].
- Shadow AI is a serious and hard-to-see risk driven by employees wanting efficiency ahead of their employer's tooling, and the defence is training and awareness, made possible by automating the policy chasing [1].
- Fundraising leverage comes from controlling information supply: she does not share company data or answer investor emails, and both her rounds were preemptive [1][2].
- When term sheets competed, she chose the person over the fund, and she coaches founders to expect as much of investors as investors expect of them [2].
Media & appearances
- Chattinn CyberApple PodcastsAI, Risk, and the Future of Compliance: Richa Kaul on How Enterprises Can Keep UpSummary Today Marc is chattin’ with Richa Kaul, founder and CEO of an AI-based compliance automation platform. The conversation centered on how AI is reshaping enterprise governance, risk, and compliance (GRC), especially by helping organizations hand
- PathfoundersApple PodcastsPathfounders Live: With Richa Kaul, Founder & CEO of ComplyancePathfounders Live: With Richa Kaul, Founder & CEO of Complyance, in conversation with Pathfounders Editor Mike Butcher, followed by a live audience Q&A. Subjects covered during the interview and Q&A: * Why compliance is suddenly becoming a boardroom
- YouTubePathfounders Live: With Richa Kaul, Founder & CEO of ComplyanceRicha Kaul discusses founding Complyance, an AI-native governance risk and compliance platform that raised $20 million in Series A funding from Google Ventures. She explains how a friend's experience in the Equifax data breach inspired her to shift from consumer-focused privacy protection to helping enterprises secure the data they hold, which led to building AI agents that continuously monitor risk, compliance, and third-party vendors in near real-time rather than weeks or months.
- The Road to Accountable AIApple PodcastsRicha Kaul, Complyance: Asking the Right QuestionsRicha Kaul breaks down the AI risk landscape for enterprises, and argues that the key to managing all of them is resisting the urge to sensationalize. Kaul offers a candid assessment of where enterprise AI governance committees are falling short, notin
- The CTO Show with Mehmet GonulluApple Podcasts#583 Continuous Compliance Is Coming: Richa Kaul on AI Agents, Data Risk, and the End of Manual GRCIn this episode, Mehmet sits down with Richa Kaul, Founder and CEO of Complyance, to explore how AI is fundamentally reshaping governance, risk, and compliance (GRC). What was once seen as a cost center is now becoming a strategic asset. With the rise
- Legitimate Cybersecurity PodcastsApple PodcastsAI Is Rewriting Compliance (GRC)Compliance isn’t “paperwork”—it’s the last line between your customers and the next Equifax-level mess. But GRC teams are stuck chasing screenshots and questionnaires instead of reducing real risk—and AI is about to change that. In th
- That Tech PodApple PodcastsCompliance Isn’t Paperwork. It’s Power. With Richa KaulThis week on That Tech Pod, Laura and Kevin chat with Richa Kaul, founder and CEO of Complyance, for a blunt conversation about what governance, risk, and compliance actually are, and why so many companies pretend it’s something else. Richa walks us
- Cyber Security AmericaApple PodcastsSpreadsheets to AI Agents The Next Era of Enterprise GRC with Richa KaulIn episode 47 of Cybersecurity America, host Joshua Nicholson is joined by Richa Kaul, CEO and Founder of Complyance, to explore how agentic AI and intelligent automation are reshaping enterprise Governance, Risk, and Compliance (GRC). Richa breaks do
- DIY Cyber GuyApple Podcasts#90: The Discord Breach – Could it Happen to You?Complyance CEO Richa Kaul discusses how third parties can expose sensitive data (passports, IDs) and provides actionable steps to prevent loss and protect revenue.
- The Compliance GuyApple PodcastsEpisode 398 - AI Compliance - Richa KaulSummary In this episode, Sean M Weiss engages with Richa Kaul, CEO of Compliance with a Y, discussing the critical role of governance, risk, and compliance (GRC) in today's data-driven world. They explore the mission behind the organization, the importa Additional recording: The Compliance Guy.
- Cyber SentriesApple PodcastsAI Compliance Security: How Modular Systems Transform Enterprise Risk Management with Richa KaulAI Insight to Cloud Security: AI-Powered Compliance: Transforming Enterprise Security In this episode of Cyber Sentries, John Richards speaks with Richa Kaul, CEO and founder of Complyance. Richa shares insights on using modular AI systems for enterprise security compliance and disc
- Software Development, Finance and AIApple PodcastsThe New Normal: Data Breaches and Business Resilience (feat. Richa Kaul)Listen to and watch The New Normal: Data Breaches and Business Resilience (feat. Richa Kaul) from Software Development, Finance and AI on Apple Podcasts. November 6, 2025. Duration: 1h 1m.
- Tech Startup StoriesApple PodcastsThe Reluctant FounderRicha Kaul, CEO of Complyance, shares her unexpected journey from strategy consultant to startup founder building across three continents. She reveals how she raised funding with an American founder mindset in the UK, the importance of validating your i
- Venture EverywhereApple PodcastsComplyance with a Why: Richa Kaul and Scott HartleyIn episode 64 of Venture Everywhere, Scott Hartley, Managing Partner of Everywhere Ventures chats with Richa Kaul, CEO and founder of Complyance, a GRC (Governance, Risk, and Compliance) platform designed for mid-market enterprises. Richa shares how Complyance helps businesses strengthen their security compliance through customized automation, enabling a proactive approach to cybersecurity. Scott and Richa also explore the evolving compliance landscape, shifting from a check-the-box mentality to building adaptive, strategic, and trust-driven security frameworks. In this episode, you will hear: Balancing automation with customization in security policies.Federal regulations vs. trust-based compliance standards.Need for incident response planning, as well as prevention.Uses AI for additional custom checks with varying threshold levels. Learn more about Richa Kaul | Complyance LinkedIn: https://www.linkedin.com/in/richa-kaul/ Website: https://complyance.com/ Learn more about Scott Hartley | Everywhere VC Linkedin: https://www.linkedin.com/in/scotthartley/ Website: https://everywhere.vc/
- PaperbackApple PodcastsEp. 66: Laxmi KrishnanWelcome to Paperback by the Open Library Project Ep. 66. We have as our guest today Laxmi Krishnan. She is the host of the "Lit Nama" Podcast on IVM Podcasts. In the first half, we discuss When We Dead Awaken by Adrienne Rich. In the second half, we discuss Cyber Sexy by Richa Kaul Padte and Many Ramayanas by Paula Richman. To know more about the books we discussed, listen in to the podcast. You can follow Laxmi Krishnan on her instagram handle: @literarychills(https://www.instagram.com/literarychills/?igshid=14c6tsq7jyhjb) You can find more details about The Open Library Project on www.openlibrary.in You can listen to this show and other awesome shows on the IVM Podcasts app on Android: https://ivm.today/android or iOS: https://ivm.today/ios, or any other podcast app. You can check out our website at http://www.ivmpodcasts.com/ See omnystudio.com/listener for privacy information.
- New Books in CommunicationsApple PodcastsRicha Kaul Padte, "Cyber Sexy: Rethinking Pornography" (Penguin Viking, 2018)Social Sciences Podcast · Updated Daily · This podcast is a channel on the New Books Network. The New Books Network is an academic audio library dedicated to public education. In each episode you will hear scholars discuss their recently publ…
- New Books in LawApple PodcastsRicha Kaul Padte, "Cyber Sexy: Rethinking Pornography" (Penguin Viking, 2018)Social Sciences Podcast · Updated Weekly · This podcast is a channel on the New Books Network. The New Books Network is an academic audio library dedicated to public education. In each episode you will hear scholars discuss their recently publ…
- New Books in South Asian StudiesApple PodcastsRicha Kaul Padte, "Cyber Sexy: Rethinking Pornography" (Penguin Viking, 2018)Society & Culture Podcast · Updated Daily · This podcast is a channel on the New Books Network. The New Books Network is an academic audio library dedicated to public education. In each episode you will hear scholars discuss their recently publ…
- New Books in Public PolicyApple PodcastsRicha Kaul Padte, "Cyber Sexy: Rethinking Pornography" (Penguin Viking, 2018)Social Sciences Podcast · Updated Daily · This podcast is a channel on the New Books Network. The New Books Network is an academic audio library dedicated to public education. In each episode you will hear scholars discuss their recently publ…
This page shows public professional information only, each fact cited. Is this you? send a correction, or ask for removal within 24 hours, no questions asked.