Upcoming Events . . .

Latest Pontifications & Thoughts . . .

  • Where Third-Party Risk Strategy & Technology Fail . . .

    Where Third-Party Risk Strategy & Technology Fail . . .

    The modern organization is not defined by brick-and-mortar walls and traditional employees. The modern organization is the Extended Enterprise of third-party and nth-party relationships. The suppliers, vendors, outsourcers, service providers, contractors, consultants, temporary workers, brokers, agents, dealers, partners, and more . . . they are part of your organization. There is no black-and-white border to…

  • Measuring Value: Making GRC Processes Efficient, Effective, and Agile

    Measuring Value: Making GRC Processes Efficient, Effective, and Agile

    Have you ever heard of the Winchester Mystery House in San Jose, California? It’s a sprawling mansion that was built in the 1800s at the cost of $5.5 million (calculate inflation, and that is one very expensive house today). It had 147 builders that built it over 38 years with no blueprint, no design, and no…

  • Practically Understanding and Delivering ESG in Today’s Organization

    Practically Understanding and Delivering ESG in Today’s Organization

    ESG – Environmental, Social, and Governance – has been creating a barrage of pressure upon organizations across industries and around the world in recent years. Corporate investors are making capital investment decisions in companies based on ESG commitments, metrics, and ratings. Legislatures and regulators around the world are ensuring the regulations are focused on the…

  • Rasmussen’s Strategic Pillars of GRC: Agility, Resiliency, Integrity

    Rasmussen’s Strategic Pillars of GRC: Agility, Resiliency, Integrity

    The physicist Fritjof Capra stated: “The more we study the major problems of our time, the more we come to realize that they cannot be understood in isolation. They are systemic problems, which means that they are interconnected and interdependent.” Capra was making the point that ecosystems are complex, interdependent, and require a holistic, contextual awareness…

  • GRC Done Right Starts With the Business: Objectives, Performance, Processes

    GRC Done Right Starts With the Business: Objectives, Performance, Processes

    Too often GRC – governance, risk management, compliance – is approached backwards. Using the acronym, one would think it is CRG, or even Cr (lower case intentional). Too many organizations start with compliance, and even risk management is done in a compliance context, and governance, performance, and objectives are not even in view. The official…

  • The Exposure of Compliance at the Frontlines of the Organization

    The Exposure of Compliance at the Frontlines of the Organization

    Compliance and ethics do not happen in the back office but at all levels of the organization. From the top down to the front-line employees. Compliance and ethics done right are a part of everyone’s job.  Too often we shovel compliance into the bowels of the organization, thinking it is the responsibility of the obscure…

  • COGNITIVE GRC: Enabling Regulatory Change Management

    COGNITIVE GRC: Enabling Regulatory Change Management

    Keeping up with regulatory content can be a challenge. The constant changes in today’s regulatory environments translate to a growing burden on organizations in terms of the number of regulations they face and their scope. Many organizations do not possess the necessary regulatory change management infrastructure and processes to address these changes and, consequently, find…

  • Cognitive GRC (GRC 5.0): Enabling Enterprise Risk Agility & Resilience

    Cognitive GRC (GRC 5.0): Enabling Enterprise Risk Agility & Resilience

    Organizations need to be agile, not just resilient. Agility is the ability to see what is coming at the organization and allow the organization to adjust and navigate to use the environment to its advantage to seize opportunities while avoid or mitigate hazards and harms. Resiliency is the ability to spring back and recover from…

  • ESG: The Foundation is Built on Policies

    ESG: The Foundation is Built on Policies

    I have been advising organizations on strategy, process, and technology related to ESG for over fifteen years. Of course, it has not been called ESG for that long. It was CSR (corporate social responsibility), social accountability, sustainability . . . now it is ESG. ESG has a lot more focus and momentum than its previous…

  • Checklist to Measure & Improve Risk & Resilience Maturity

    Checklist to Measure & Improve Risk & Resilience Maturity

    The mature risk and resilience program can be measured against critical elements across governance and oversight, people and engagement, process and execution, and information and technology. Risk & Resilience Governance & Oversight The governance model is agreed upon at the board level and effectively communicated and supported across the organization  Policies and procedures for risk…

  • Advancing Your Organization’s Risk and Resilience Maturity

    Advancing Your Organization’s Risk and Resilience Maturity

    Getting to the Head of the Risk & Resiliency Class Organizations with risk and resilience processes siloed within departments operate at the Ad Hoc, Fragmented, or Defined stage. At these stages, risk and resilience management programs manage risk and continuity at the departmental level, and lack an integrated view, with no gain in efficiencies from…

  • Five Stages of Risk and Resilience Maturity

    Five Stages of Risk and Resilience Maturity

    Mature risk and resilience management is a seamless part of risk governance and operations. It requires a top-down view of risk and resilience, led by the executives and the board, where risk and resilience management are part of the fabric of business operations and processes – not an unattached layer of oversight. It also means…