


Upcoming Events . . .
Latest Pontifications & Thoughts . . .
-

Are You Headed to a Risk Management Clusterf***?
Yes, you read that correctly. Anyone that knows me knows that I am not inclined to use profanity casually. The reality is that this term, clusterf***, is a technical term. The term has its roots stemming from the Vietnam War, perhaps earlier. It defines a situation where there is a lot of top-down strategy (high-level……
-

Policy Management Maturity: Journey to an Agile Policy Management Program
Successful policy management requires the organization to provide an integrated strategy, process, information, and technology architecture to consistently govern policies across the organization. The goal is to give comprehensive, straightforward insight into policy management to identify, analyze, manage, and monitor policies in the context of operations, processes, transactions, and roles. It requires the ability to……
-

Putting $$$ to It: Can You Quantify Your Risk?
As Sir Arthur Conan Doyle stated . . . “It is a capital mistake to theorize before one has data. Insensibly one begins to twist facts to suit theories, instead of theories to suit facts.” Data is critical to risk management, and the more objective and quantitative the data is, the more value risk provides……
-

Doctor Strange: Chief Risk Officer in the Multiverse of Uncertainty
Last week I looked at James Bond 007 and Risk Situational Awareness where we explored how organizations need to be like James Bond and have full situational awareness of risk and uncertainty to objectives. This week we keep on the fictional hero theme with a look at Dr. Strange who is the representative of the……
-

James Bond 007 and Risk Situational Awareness
I am so excited about this evening! After a long wait, I am going to the new James Bond 007 movie, No Time to Die! I am making it a big deal. A group of 12 of us are going to the nice Silverspot Cinema that is amazing, with an incredible lounge area. I am……
-

The Foundation of ESG is in Policy Management
Martin Luther King Jr stated: Whatever affects one directly, affects all indirectly. I can never be what I ought to be until you are what you ought to be. This is the interrelated structure of reality. This statement is valid on a personal level, but it is also true at an organizational level. The actions……
-

Managing & Communicating Policies in the “NEW NORMAL”
Issuing well-crafted and appropriately targeted policies is a necessary first step in clearly defining and communicating the organization’s values, boundaries, practices, and expectations. Policies are the vehicle to ensure culture is defined and does not morph out of control. This enables the organization to embed culture into the action and behavior of processes, transactions, relationships,……
-

GRC 20/20’s Regulatory Change Management Maturity Model
Last week we looked at Regulatory Change RFP/Solution Capabilities this week we look at how to measure the maturity and trajectory of an regulatory change management program . . . Mature regulatory change management requires the organization to align on regulatory risk. It also involves participation across the organization at all levels to identify and……
-

Regulatory Change RFP/Solution Capabilities
Last week we looked at GRC Architecture to Manage Regulatory Change this week we get more into the specific capabilities that technology should deliver to automate and manage the regulatory change process to make it more efficient, effective, and agile . . . Regulatory change management requires a process to gather information, weed out irrelevant……
-

GRC Architecture to Manage Regulatory Change
Last week we looked at How to Define a Regulatory Change Management Strategy and Process, this week we look at how to leverage technology to automate and manage regulatory change in a dynamic business and regulatory environment . . . Effectively managing regulatory change is done with a GRC information and technology architecture to improve……
-

Defining a Regulatory Change Management Strategy & Process
Last week we looked at the broken of the Broken Process and Insufficient Resources to Manage Regulatory Change this week we look at how tp fix this with strategy and process to address regulatory change management . . . Organizations are struggling with regulatory change and seeking to integrate a regulatory change strategy and process……
-

Broken Process and Insufficient Resources to Manage Regulatory Change
Last week we looked at the challenge of the tsunami of regulatory change that organizations are flooded with, this week we look at how the internal processes and resources are insufficient to keep up with managing regulatory change in today’s dynamic, distributed, and disrupted business environment . . . The typical organization does not have……
