


Upcoming Events . . .
Latest Pontifications & Thoughts . . .
-

A New Paradigm in Risk, Resiliency & Continuity Integration
Lacking an integrated view of risk and resilience results in business processes, services, employees, and systems that behave like leaves blowing in the wind. Organizations need to develop, nurture, and mature a risk and resilience management capability aligned with strategy, performance, and objectives that operate as a risk and resilience central nervous system. Consider the…
-

Building a Mature GRC Program: The Top 5 Considerations
Shadows haunt the organization. Today’s organization is encumbered by things like shadow processes and shadow IT. These are rogue processes and technology that get implemented in the depths of the organization without thought or conformity to a top-down integrated strategy. The components of GRC – governance, risk management, and compliance – are in every organization. My…
-

360° Visibility into Risk & Resilience
Here are some thoughts on how to mature a policy management strategy from the recent GRC 20/20 research report, Risk & Resiliency Management Maturity Model: A New Paradigm on Risk, Resiliency & Continuity Integration Dynamic, Disrupted & Distributed Business is Difficult to Control The complexity of business – combined with the intricacy and interconnectedness of…
-

How to Build your GRC Strategy in an ESG Era
Looking for a path to environmental, social and governance (ESG) insights in a forest of GRC data The last two years have shone a light on GRC – governance, risk management, compliance – processes and shifted many attitudes towards risk. Yet many organizations are left with many questions: What are the best practices to identify,…
-

Ways to Enhance Your Social Accountability/Sustainability Program
ESG – Environmental, Social, Governance – is a dominant focus in organizations right now getting board-level scrutiny and attention. Organizations around the world and across industries are challenged to define, implement, and report on ESG. These pressures are coming from all directions: investors, customers, employees, regulators, and activists. The reality is that ESG has teeth,…
-

Got Risk Management? You Think You Do . . .
In GRC 20/20’s upcoming 2022 State of the GRC Market Research Briefing, one of the changes I am doing to my market models is the integration of the former Business Continuity Management segment into the Risk Management segment to become Risk & Resiliency Management. This is further referenced in the recent GRC 20/20 Research paper…
-

Policy Management Maturity: Level 2 – Fragmented
Here are some thoughts on how to mature a policy management strategy from the recent GRC 20/20 research report, Strategy Perspective: Policy Management Maturity Model. Mature policy management is a seamless part of governance and operations. It requires a top-down view of policies starting with the code of conduct and filtering down into division, department,…
-

How EHS Software Facilitates Risk Data Collection, Improves Data Accuracy & Streamlines Reporting 
We are at a critical point in history, a point that can lead to two very different outcomes. The decisions organizations make today and how they manage environmental, health and safety risks set all of us on a path for our world in the future. In my keynotes and presentations, I ask the question: What is…
-

GRC 2020’s Key Tips for ESG Reporting in 2022 
ESG – Environmental, Social, Governance – received a lot of attention in 2021. Organizations across industries and around the world have had to respond to investor, stakeholder, regulator, customer, employee, and activist demands to address ESG. The pressure is on, organizations are being held accountable and it is now time for the organization to build…
-

Providing Compliance Defensibility
Creating a defensible compliance process is not only good for risk management. It provides organisations with mitigation should unforeseen breaches occur. The Chief Ethics and Compliance Officer (CECO) role is about being the Chief Integrity Officer of the organisation. With the Environmental, Social and Governance (ESG) accountability handed to corporate compliance and ethics teams, this…
-

GRC 20/20’s 2021 Research Year in Review
2021 was a year of resiliency as we ride the waves of the pandemic with a focus on ingrity as the world turns to a focus on ESG within organizations. 2022 will continue these themes of resiliency and integrity but will bring in agility. How can organizations not only be resilient but also agile while…
-

Policy Management Maturity: Level 1 – The Ad Hoc
Here are some thoughts on how to mature a policy management strategy from the recent GRC 20/20 research report, Strategy Perspective: Policy Management Maturity Model. Mature policy management is a seamless part of governance and operations. It requires a top-down view of policies starting with the code of conduct and filtering down into division, department,…
