


Upcoming Events . . .
Latest Pontifications & Thoughts . . .
-

State of GRC: A Future of Agility, Resiliency & Integrity
Below is an abstract and the video of my keynote from the Konnect 2022 conference. My next keynote will be at #RISK in London on November 16th and 17th where I will also be the chair/host of the conference, and doing a special executive breakout session on ESG. The keynote video details the challenges organizations……
-

Where Risk Management Strategy & Technology Fail . . .
Last week we explored where third-party risk management strategy and technology fail, this week we turn our attention to where enterprise/operational/integrated risk management strategies and technologies fail. Yes, that world of ERM, ORM, IRM which is fraught with misconceptions, complexities, and too often solutions that create blind spots on risk. The modern organization demands that……
-

Strengthen Your Cybersecurity Management Policy With the Human Firewall
The need for cybersecurity is growing with the dynamic, distributed, disrupted, and particularly digital nature of business. Digital transformation is making cybersecurity even more critical to protect the organization, maintain resilience, and compete in today’s chaotic and digital business environment. The threats to business come from all angles and include the malicious, but also the……
-

ESG and the Geopolitical Complexities of Supplier Risk
How do you define the modern organization? There is no binary boundary to the organization anymore, no more black and white. It is impossible to clearly state that this is where the organization ends. The organization is NO LONGER defined by brick-and-mortar walls and traditional employees. There are shades of grey as the modern organization……
-

Where Third-Party Risk Strategy & Technology Fail . . .
The modern organization is not defined by brick-and-mortar walls and traditional employees. The modern organization is the Extended Enterprise of third-party and nth-party relationships. The suppliers, vendors, outsourcers, service providers, contractors, consultants, temporary workers, brokers, agents, dealers, partners, and more . . . they are part of your organization. There is no black-and-white border to……
-

Measuring Value: Making GRC Processes Efficient, Effective, and Agile
Have you ever heard of the Winchester Mystery House in San Jose, California? It’s a sprawling mansion that was built in the 1800s at the cost of $5.5 million (calculate inflation, and that is one very expensive house today). It had 147 builders that built it over 38 years with no blueprint, no design, and no……
-

Practically Understanding and Delivering ESG in Today’s Organization
ESG – Environmental, Social, and Governance – has been creating a barrage of pressure upon organizations across industries and around the world in recent years. Corporate investors are making capital investment decisions in companies based on ESG commitments, metrics, and ratings. Legislatures and regulators around the world are ensuring the regulations are focused on the……
-

Rasmussen’s Strategic Pillars of GRC: Agility, Resiliency, Integrity
The physicist Fritjof Capra stated: “The more we study the major problems of our time, the more we come to realize that they cannot be understood in isolation. They are systemic problems, which means that they are interconnected and interdependent.” Capra was making the point that ecosystems are complex, interdependent, and require a holistic, contextual awareness……
-

GRC Done Right Starts With the Business: Objectives, Performance, Processes
Too often GRC – governance, risk management, compliance – is approached backwards. Using the acronym, one would think it is CRG, or even Cr (lower case intentional). Too many organizations start with compliance, and even risk management is done in a compliance context, and governance, performance, and objectives are not even in view. The official……
-

The Exposure of Compliance at the Frontlines of the Organization
Compliance and ethics do not happen in the back office but at all levels of the organization. From the top down to the front-line employees. Compliance and ethics done right are a part of everyone’s job. Too often we shovel compliance into the bowels of the organization, thinking it is the responsibility of the obscure……
-

COGNITIVE GRC: Enabling Regulatory Change Management
Keeping up with regulatory content can be a challenge. The constant changes in today’s regulatory environments translate to a growing burden on organizations in terms of the number of regulations they face and their scope. Many organizations do not possess the necessary regulatory change management infrastructure and processes to address these changes and, consequently, find……
-

Cognitive GRC (GRC 5.0): Enabling Enterprise Risk Agility & Resilience
Organizations need to be agile, not just resilient. Agility is the ability to see what is coming at the organization and allow the organization to adjust and navigate to use the environment to its advantage to seize opportunities while avoid or mitigate hazards and harms. Resiliency is the ability to spring back and recover from……
