People

Richa Kaul

Richa Kaul is the founder and chief executive of Complyance, a New York-based governance, risk and compliance platform built around artificial intelligence agents that continuously monitor enterprise data security, regulatory compliance and third-party vendor risk [1][2]. The company's name is deliberately spelled with a "y" rather than an "i," a distinction Kaul uses to argue that compliance should be a byproduct of sound information-security practice rather than a paperwork exercise pursued for its own sake [3]. Complyance has raised a $20 million Series A round led by Google Ventures, funding that supports its shift away from the periodic, sample-based audits that have long characterized the compliance industry toward continuous, real-time monitoring [2].

Kaul has described her path to founding the company as unplanned; she has said that even a month before starting Complyance she would not have identified herself as a future founder [2][3]. She traces the company's origins to two converging influences: a long-standing personal preoccupation with data privacy, including a habit of checking her own and others' phone privacy settings, and a professional observation that enterprise compliance software had not kept pace with modern technology [3]. She has said the more immediate catalyst was watching a close friend suffer identity theft as a result of the Equifax data breach, an experience that pushed her to conclude that protecting consumers was best achieved indirectly, by helping the companies that hold consumer data secure it more effectively [2]. Kaul relocated to the United Kingdom in 2019 after her husband's job required the move, and she has said Complyance grew "organically" out of that period rather than from a deliberate plan to start a company [3].

Before founding Complyance, Kaul held strategy roles including chief strategy officer at ContractPodAi and earlier experience at McKinsey and in government, a background she has credited with teaching her how to translate high-level strategic thinking into hands-on startup execution [2][3]. As a self-described non-technical founder, she has said her first priority in building the company was recruiting a chief technology officer, and she brought on Hugo Naggua, who has remained in that role from the company's earliest days [3]. In validating the product, Kaul has said the team deliberately avoided over-building before testing the market, instead conducting extensive interviews with people managing enterprise information security and compliance and offering low-cost services, such as support attaining SOC 2 certification, to mid-market and larger companies in order to embed directly in customer workflows and learn about their pain points firsthand [3].

Kaul frames the current shift in the compliance industry as a move from point-in-time checks, in which auditors historically sampled a small fraction of an organization's systems or employees at a single moment, to continuous monitoring enabled by AI agents that can track compliance status across an entire organization on an ongoing basis [2]. She argues that this shift has pushed risk and compliance considerations further into the boardroom as AI adoption accelerates, and she has taken the broader position that governance, risk and compliance teams function to create trust between organizations and their customers rather than simply to satisfy bureaucratic requirements [2].

Insights & ideas

Richa Kaul argues that consumer data protection is best achieved indirectly, by helping the enterprises that hold that data secure it properly, a conviction that grew out of a friend's identity theft following the Equifax breach [1][2]. She positions Complyance as an AI-native governance, risk and compliance platform whose agents continuously monitor risk, compliance and third-party vendors, compressing processes that once took weeks or months into near real time [1]. A recurring theme in her thinking is that compliance has an image problem: she insists "compliance is cool" and reframes GRC teams as the people who create trust between an organization and its customers [1]. She also stresses the distinction encoded in her company's name, that compliance with an "I" does not equal security, and that true compliance should be a byproduct of sound information security practices and internal processes rather than an end in itself [2]. On her own path, she describes becoming a founder as driven by "blind conviction" after spotting an unmodernized enterprise tech gap, not by any prior ambition to start a company [1][2].

Experience

  1. CEO & Founder
    ComplyanceOct 2022 to Present
  2. Chief Strategy Officer
    ContractPodAi®Jan 2021 to Jul 2022
  3. Chief Revenue Officer
    ContractPodAi®Apr 2021 to Apr 2022
  4. Head of Strategy
    ContractPodAi®Jan 2020 to Jan 2021
  5. Managing Director, Technology and Corporate Services Sectors
    Virginia Economic Development PartnershipMay 2018 to Jan 2020
  6. Independent Consultant
    The World BankMay 2019 to Jun 2019
  7. Engagement Manager
    McKinsey & CompanyOct 2017 to Apr 2018
  8. Senior Business Analyst
    McKinsey & CompanySep 2015 to Sep 2017

Education

Media & appearances

This page shows public professional information only, each fact cited. Is this you? Corrections or removal within 24 hours, no questions asked.