Real-World GRC Convergence: Platform Considerations

Email     |     Share  
1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11
Next Real-World GRC Convergence: Platform Considerations-3 Next

Compliance Management Requirements

Compliance platforms enable companies to incorporate laws, regulations and internal policies into an enterprise risk profile. Compliance platforms should help organizations:

  • Manage policies, including documentation, review, communication and attestation.
  • Integrate policies with other enterprise content and records management systems such as Microsoft SharePoint.
  • Monitor external regulations via third-party content provider feeds, and involve business-line representatives in the impact assessment via streamlined workflows.
  • Associate regulations and risks with policies and controls so organizations can apply rationalized compliance efforts to multiple regulatory and risk management activities.
  • Utilize eLearning modules that communicate corporate brand and ideals, promote employee education, and comply with legal and regulatory training requirements.
  • Prioritize and manage compliance projects in the context of broader corporate initiatives and resource allocation, balancing profit-driving strategies with regulatory imperatives.

Integration of multiple governance, risk and compliance (GRC) disciplines on a single platform is a laudable goal, and the effort to achieve it by both vendors and their customer organizations is increasing. Notably, within the enterprise GRC (eGRC) space, integration occurs most often among the internal audit, financial controls and enterprise risk assurance functions. Conversely, the compliance function has been less inclined to integrate, due in part to the specific subject-matter expertise required for each of the compliance functions, which makes the broader risk and control sets documented by other groups less relevant to compliance teams.

Still, the Institute of Internal Auditors' (The IIA) position paper, "The Three Lines of Defense In Effective Risk Management and Control" (January 2013), offers valuable insight into why it makes sense to bring these functions together, at least on an aggregated level, even if subsets of information are contained in other source systems. According to the paper, convergence will enable the three lines (operational/business-line managers, risk and compliance functions, and internal audit) to coordinate activities, map assurance functions and perform independent validation.

But significant barriers to the comprehensive and successful integration of GRC technology across numerous groups remain. For example, many organizations continue to depend on multiple GRC technologies to fulfill different and specific departmental needs, and most organizations use different platforms for IT GRC and eGRC. Other obstacles include the lack of a unified GRC framework or a common language, the complexity of existing technologies, the lack of effective change management, and a lack of demonstrable return on investment (ROI).

Achieving convergence in the face of these obstacles requires technology capable of unifying an organization's policies, processes and infrastructure. In this slideshow, Protiviti has identified the key elements of a technology platform capable of doing so.


Related Topics : A Big Market for Big Data Jobs, Midmarket CIO, IT Management Automation, SharePoint, Technology Markets

More Slideshows

PlexxiITRoles0x IT Roles: The New Faces of Network Infrastructure

The newfound emphasis on tools and service integration is shaping a new crop of industry professionals — the actual faces behind the IT infrastructure. ...  More >>

Compliance4-190x128 GRC Programs: Building the Business Case for Value

Experience shows that organizations that manage GRC as an integrated program — involving people, processes and technologies — are more successful in delivering value to their organizations ...  More >>

IT_Man89-290x195 9 Tips for Running a 'Tween' Company

Advice and tips for entrepreneurs and companies that are no longer startups but not quite ready for an IPO, also known as "tweens." ...  More >>

Subscribe to our Newsletters

Sign up now and get the best business technology insights direct to your inbox.