Diligent Logo
Diligent Logo
Products
arrow_drop_down
Solutions
arrow_drop_down
Resources
arrow_drop_down
Diligent AI

Consolidating the view, accelerating response: What state and local risk management needs today

September 14, 2026
5 min read
Katja Freeman

Katja Freeman

Solutions Sales Director

One system handles cybersecurity. That one handles loss prevention and insurance risk. Meanwhile, oversight of federal grants and constituent services lives in an entirely different system.

Does this scenario sound familiar? If the answer is yes and you’re responsible for maintaining security, compliance, business continuity and public trust in state or local government, it’s time to rethink business as usual.

Getting ahead of change and threats today means seeing the full risk picture — without blind spots, without delays and with accountability and action built in. This demands a fresh approach. Read on for why, and how the right technology can help.

Old processes fall short of rising complexity and exposure

Due to spending cuts and budget scrutiny, too many state and local agencies are continuing to manage cyber risk and IT compliance via spreadsheets, email chains, manual processes and siloed legacy systems. Problems ranging from detection lag to contradictory reporting challenge the organization as the attack surface expands and risk gets even more complicated.

Cybersecurity alone covers an ever-expanding array of threats, from phishing and social engineering to deep fakes and AI-powered malware, with frameworks like FISMA and CIS that are increasingly relevant at the state and local level.

Given the scope of what public sector organizations are responsible for, there's so much more to track. As data and requirements continue to grow and grow, manual processes keep public sector agencies in perpetual catch-up mode.

As my colleague Jason Venner, a Diligent director who spent 20 years leading and managing public sector risk and audit teams at transportation organizations and US government agencies, points out, “Whether you're talking about enterprise risk, IT risk, fraud risk, whatever the case may be, you just can’t manage it all chasing documents and spreadsheets through phone calls and email chains.” 

To compound the problem, too many agencies manage threats at the department level, through siloed systems. This compromises reporting, response and remediation.

Here’s an example to illustrate:

An agency is able to identify dozens, even hundreds, of risks. But then processes break down. There’s no defensible way of determining which issue requires attention and resources. The risk register, if one exists at all, lives in a spreadsheet that only gets updated before the yearly budget cycle or an audit committee meeting. 

Between these annual cycles, nothing is actively monitoring for emerging risk. When a risk is flagged for remediation, no tracking mechanism holds specific teams or staff accountable.

Timely oversight demands a centralized, continuous system

So, how do state and local government risk teams achieve the visibility, accountability and action they need today?

First, bring all those silos and systems together into one place: Audit findings, incident reports, vendor assessments, vulnerability scans. Leaders need centralized visibility across them all, from the most urgent cyber threats to the status of internal controls.

Risk consolidation especially matters for public sector organizations because they’re answering to so many different stakeholders: boards, legislatures, accreditors, taxpayers and the general public, all expecting a defensible, documented risk process.

Secondly, make risk management continuous. Organizations that do so catch things earlier, spending less time firefighting and more time addressing root causes.

Automation, AI and analytics save time and money

Importantly, a governance, risk and compliance (GRC) solution that automates, orchestrates and centralizes work across functions helps lean public sector teams prioritize limited resources.

Delivering status updates via one real-time platform, rather than constructing them by hand, is one example. Teams can save hours, days, even weeks' worth of work while reducing the chance of something important falling through the cracks.

IT, risk and compliance professionals can free up even more time by automating routine administrative tasks. Some examples to consider include routing assessments for review, flagging overdue remediation items and aggregating status updates.

Automation speeds up the work teams already know how to do. AI goes a step further: it surfaces risks and patterns no one knew to look for in the first place. When data that used to live in separate systems and spreadsheets is connected, AI's anomaly-finding capabilities can flag things no single team, looking only at its own silo, would catch on its own, like a vendor contract that keeps coming in above market rate, a spending pattern that repeats across departments, or a control gap that shows up in multiple business units. That shift, from reactive review to continuous pattern detection, is what turns AI from a nice-to-have into a genuine force multiplier for lean teams.

Here's a real-world example illustrating the value, from Scott Bridgen, Diligent's General Manager of Risk and Audit. One local government client, an early adopter of Diligent's ACL AI capability, used its anomaly-finding tools to catch spending leakage in petty cash and vendor contracts before it became a bigger problem.

"They used AI to look at that data — where it was coming from, the repeatable patterns, the individuals involved," Scott recalls. "In the first six months, they saved roughly $400,000."

That's the kind of return that becomes possible when automation handles the busywork and AI takes on the pattern recognition, freeing risk and compliance teams to spend their time on judgment calls instead of data gathering.

Diligent: Purpose-built for public sector cyber risk and IT compliance

Guided by insights like these, Diligent’s AI- and analytics-powered platform moves state and local IT and risk leaders into the future:

  • Delivering dashboard-powered insights to the CIO and CISO
  • Centralizing requirements, controls, documentation and assessments for heads of risk and compliance
  • Automating updates and outputs for risk management leads, with reusable common controls to reduce rework
  • Bringing compliance, analytics and remediation into one dashboard, to equip internal audit and assurance teams with continuous insight

Take the next step to better visibility, readiness, responsiveness and efficiency. Learn more about Diligent cyber risk and IT compliance solutions.

Explore More

continuous monitoring audit

Blog

· Jul 16, 2026

· 4 min read

Want to stay audit-ready? Continuous monitoring is the key

By Katja Freeman

Maintain constant audit readiness. Discover how public sector teams use automation and continuous monitoring to simplify compliance.

Auditor taking advantage of Continuous risk monitoring

Blog

· Feb 23, 2026

· 10 min read

Continuous risk monitoring: AI-powered visibility across enterprise risks

By The Diligent team

Learn how continuous risk monitoring uses AI and analytics to identify and mitigate enterprise risks in real time and remain compliant.

Professional ready to use AI to elevate her GRC ai function and encourage good governance.

Blog

· Feb 18, 2026

· 18 min read

How artificial intelligence transforms governance, risk, and compliance (GRC)

By Phil Lim

Discover how AI transforms GRC through automated compliance monitoring, continuous risk detection, and intelligent decision support.