Skip to Content

Agents of Risk: How a Former Zookeeper Is Rebuilding Compliance at McDonald’s

Agents of Risk

Agents of Risk Blog Series

Agents of Risk is LogicGate’s series spotlighting the leaders, innovators, and risk professionals building smarter, more human GRC programs. In each installment, we sit down for a candid conversation with industry talent to get the true story behind their journey, their approach to risk and compliance, and the lessons they’ve learned along the way.

Featuring: Christy Kostock, Global Compliance Analyst at McDonald’s 

How Christina Kostock’s Experience Has Helped Define Her GRC Identity

“Even if you have an unexpected path, I use everything that I’ve done in the past in my role today.”

Christy Kostock’s path to McDonald’s, where she now serves as Global Compliance Analyst, was anything but predictable. Before stepping into compliance four years ago, her career spanned an incredible range: aspiring veterinarian, Brookfield Zoo senior zookeeper, luxury brand office manager, fashion sales consultant, and executive assistant at the Dr Pepper Snapple Group. To Christy, none of those experiences were detours; they were foundational.

Specifically, Christy’s background has shaped the way she approaches her role in the following ways: 

  • Treating AI like an unsupervised junior associate: Why AI is a powerful tool for initial framing, but requires strict human oversight before anything goes out the door.
  • Connecting raw metrics through storytelling: How framing data into clear narratives drives alignment with non-technical executive leadership.
  • Designing risk analytics as both art and science: How combining a biology background with creative visual framing turns complex data into an intuitive GPS for the business.
  • Breaking out of organizational silos: Why viewing risk and compliance holistically leads to greater autonomy and better decision-making across the enterprise.

GRC Is Bigger Than the Job Description Suggests

Ask Christy what she does and the honest answer is complicated. She’s a compliance analyst on paper, but the real work takes shape as a translator between data, technology, and the people who have to act on both. “I’ve been very successful in talking about data and technology and how they connect with each other, and using those tools to further our compliance journey,” she says.

That framing matters to her. GRC, in her experience, doesn’t get treated as its own discipline so much as an offshoot of whatever function happens to own it. She’s watched people spend entire careers boxed into one narrow slice of a company’s risk or data journey without ever stepping back to see how it connects to everything else. 

Her own path across industries gave her the opposite: a habit of seeing risk and compliance holistically, which she credits for how comfortably she’s adapted to new tools, new stakeholders, and, now, AI. “I’ve been able to grow professionally while continuing to build my technical data skills. Since I use those skills every day, I’ve kept improving them, but I’ve also had opportunities to develop how I present my work, explain strategy, and work with senior leaders,” she says. “I get more autonomy, and I get to do the design work. A lot of people in my position wouldn’t get to do that. I enjoy that immensely.”

Friend, Foe, or Frenemy: Where AI Fits in GRC

Christy doesn’t see AI as a replacement for human judgment in GRC; she sees it as a multiplier, provided you know how to leverage it. Whenever colleagues or peers ask how she views the technology, her answer is always the same: “It’s great for parsing things, but I feel like it’s a junior associate. Would you give them a job and not review it? Probably not. You’re the one that’s responsible for this work. It’s not a drop and go.”

In practice, that means she’ll let AI take a first pass at structuring an idea or offer a fresh angle she hadn’t considered, then apply her own judgment before anything goes out the door. “The ideas are mine, but that first-step construction, I tend to offshore to AI a little bit,” she says. The upside has been real: less time buried in day-to-day pulls, more time in front of leadership on strategy, without working until midnight to make room for both.

For a field that runs on trust and accountability, that distinction, treating AI as a capable but unsupervised junior associate rather than a decision-maker, is the whole ballgame.

Storytelling Is What Makes the Data Land

The part of the job that truly energizes Christy is the precise moment a narrative turns raw data into a real breakthrough. Having advised doctors, attorneys, and specialized experts (professionals accustomed to dense facts), she knows that even the sharpest minds need compelling storytelling to connect complex metrics to strategic action. Data can inform, but only narratives can truly align. She says, “I love watching those aha moments where they’re like, oh, this is why we’re doing this.”

One conversation always stood out: a senior manager once remarked that Christy’s approach to data was like investigative journalism, connecting disparate facts into a clear, compelling narrative. Today, she applies that exact instinct to enterprise risk. Instead of presenting raw metrics, she empowers her team to show executive leadership why those results matter and how they drive broader business priorities. It’s a subtle shift in framing, but one that fundamentally elevates how GRC is received at the decision-making table.

Data Analytics Is as Much Art as Science

Christy’s approach to technology and reporting is shaped by two unexpected influences: a background in biology and a family of artists. While her scientific background built a habit of curiosity and hypothesis-testing, her creative side dictates how she builds dashboards. “I often think of compliance risk analysis like building a GPS for the business,” Christy explains. “Data points are simply road signs until technology brings them together into a meaningful route. Through dashboards, automation, and analytics, we transform thousands of data points into a clear story that helps leaders navigate around risks and avoid potential roadblocks.”

That artistic mindset gives her room to experiment with non-traditional visuals—once even prototyping a risk registry mapped inside the layers of a hamburger, directly connecting risk data to McDonald’s brand identity. For Christy, data design is an evolving discipline: “None of these dashboards are ever complete until they’re dead. We’ll always be growing and changing them.”

An Unexpected Path Becomes an Identity

Christy wears her unconventional career path as a point of pride. It’s the same instinct that turned a risk registry into a hamburger diagram: connect what looks unrelated until the pattern is obvious.  Today, when engaging senior leadership and board members, that instinct shows up in a single, well-honed skill: seeing the entire ecosystem instead of getting trapped in a single discipline.

It wasn’t the path she originally mapped out, but it became her defining professional identity, and McDonald’s compliance program is stronger, sharper, and far more dynamic for it.

Agents of Risk spotlights the people behind modern GRC. See how LogicGate customers put those ideas into practice.


Frequently Asked Questions

How Should GRC Teams Use AI Without Giving Up Accountability?

Treat AI like a junior associate: useful for a first pass, but never unsupervised. Christy Kostock lets AI structure an idea or suggest a fresh angle, then reviews it herself before anything goes out. As she puts it, “You’re the one that’s responsible for this work. It’s not a drop and go.”

How Can Compliance Teams Turn Raw Data Into Executive Buy-In?

Lead with a narrative, not raw metrics. Christy has advised doctors, attorneys, and other specialists, and even they need a story that connects complex data to strategic action. Her goal is the moment leaders say, “oh, this is why we’re doing this.”

How Do You Make Risk Dashboards Useful for Non-Technical Leaders?

Think of a dashboard as a GPS for the business. Christy says data points are “simply road signs until technology brings them together into a meaningful route.” Dashboards, automation, and analytics then turn thousands of data points into a clear story that helps leaders avoid roadblocks.

Does a Non-Traditional Background Help or Hurt a GRC Career?

It can help. Christy moved through roles from zookeeper to executive assistant before compliance, and she says, “I use everything that I’ve done in the past in my role today.” That path gave her a habit of seeing risk and compliance holistically instead of from one narrow lane.

AUTHORED BY

Related Posts