Newsletters Welcome, Guest Log In | Register

Governance and Risk

From regulatory compliance to corporate governance structure, everyone is involved

About this Blogger RSS

Subscribe

Sign up now and get the best business technology insights direct to your inbox.

  • Daily Edge
  • CTO Edge Update
  • Business Tools & Templates
  • Aligning IT & Business Goals
  • Maximizing IT Investments

0

Chief Ethics Officer Emerging as Strategic Position

Posted by Lora Bentley Feb 24, 2009 4:27:02 PM

In an effort to gain more insight into the growing risk/compliance officer trend, I also spoke with Paul Shulz, a managing director at Protiviti. The global company provides governance and risk consulting services in a wide variety of industries, and more recently has assembled a cross-disciplinary team of experts to help those affected by the continuing financial crisis.

 

Like Keith Darcy, Shulz agrees that the trend is a growing one. In an e-mail, he said:

Evolving legal risks, product recalls, investments that seemed solid suddenly disappearing, mounting pressures for privacy and security...all add to and compound this trend.

He referred me to the Open Compliance and Ethics Group's definition of the Chief Ethics and Compliance Officer. The group says, in part, that this role "is a strategic position vested with accountability for executing on a compliance and ethics program." Shulz notes, too, that more often than not, the CECO has direct access to corporate counsel and the authority to take control in emergencies.

 

More than that, though, he said the position must be at C-level rather than lower because it's "at the fulcrum of creating and managing the mechanisms that cut across organizational and business-unit boundaries to identify, manage, and mitigate risks" wherever they happen to arise. As for effectively communicating risk-management strategy and enforcing policies, Shulz explained:

[Protiviti has] a model we call Performance/Risk Integrated Management Model (PRIM2), which promotes the idea that strategy deployment and enterprise risk management are inseparable today and intertwine in the planning, assessment, evaluation and reporting stages.... We can see the day when line managers are surrounded with as much discipline around risk management as they are for financial and operating performance.

Add a comment Leave a comment on this blog post.

There are no comments on this post

Lowering Your IT Costs with Oracle Database 11g Release 2

This white paper identifies the key capabilities a database management solution needs to successfully deliver more information with higher quality of service, make more efficient use of IT budgets, and reduce the risk of change in data centers.

Software Forum: Information On Demand Virtual Experience

This interactive virtual forum presents leading IT experts providing the insights you need to turn your information into a strategic driver for innovation, business optimization and competitive differentiation.

Energy Efficiency

Best practices to optimize computing ability while minimizing power costs.

Laptop Security

Answers to the ongoing challenges of the mobile office: to work anywhere, securely and efficiently.

Data Deduplication

Data manipulation strategies that make data stores more manageable and reduce the need for storage capacity and its associated costs.

Security Information and Event Management

Best practices, strategies and technologies to help you use security information and event log management efficiently and effectively in order to get business value in terms of increased security, reduced risk, regulatory compliance and increased business agility.

Disaster Recovery & Business Continuity Template Pack

Prepare your company for any type of disaster you can envision and those you cannot. Immediately download this comprehensive set of templates and tools for documenting your business contingency plans.

Learn more >

The IT Service Catalog Management Toolkit

Bridge the it-business gap once and for all! A well documented IT services catalog is the conduit for IT services to the rest of the company.

Learn more >