


Upcoming Events . . .
Latest Pontifications & Thoughts . . .
-

James Bond 007 and Risk Situational Awareness
I am so excited about this evening! After a long wait, I am going to the new James Bond 007 movie, No Time to Die! I am making it a big deal. A group of 12 of us are going to the nice Silverspot Cinema that is amazing, with an incredible lounge area. I am…
-

The Foundation of ESG is in Policy Management
Martin Luther King Jr stated: Whatever affects one directly, affects all indirectly. I can never be what I ought to be until you are what you ought to be. This is the interrelated structure of reality. This statement is valid on a personal level, but it is also true at an organizational level. The actions…
-

Managing & Communicating Policies in the “NEW NORMAL”
Issuing well-crafted and appropriately targeted policies is a necessary first step in clearly defining and communicating the organization’s values, boundaries, practices, and expectations. Policies are the vehicle to ensure culture is defined and does not morph out of control. This enables the organization to embed culture into the action and behavior of processes, transactions, relationships,…
-

GRC 20/20’s Regulatory Change Management Maturity Model
Last week we looked at Regulatory Change RFP/Solution Capabilities this week we look at how to measure the maturity and trajectory of an regulatory change management program . . . Mature regulatory change management requires the organization to align on regulatory risk. It also involves participation across the organization at all levels to identify and…
-

Regulatory Change RFP/Solution Capabilities
Last week we looked at GRC Architecture to Manage Regulatory Change this week we get more into the specific capabilities that technology should deliver to automate and manage the regulatory change process to make it more efficient, effective, and agile . . . Regulatory change management requires a process to gather information, weed out irrelevant…
-

GRC Architecture to Manage Regulatory Change
Last week we looked at How to Define a Regulatory Change Management Strategy and Process, this week we look at how to leverage technology to automate and manage regulatory change in a dynamic business and regulatory environment . . . Effectively managing regulatory change is done with a GRC information and technology architecture to improve…
-

Defining a Regulatory Change Management Strategy & Process
Last week we looked at the broken of the Broken Process and Insufficient Resources to Manage Regulatory Change this week we look at how tp fix this with strategy and process to address regulatory change management . . . Organizations are struggling with regulatory change and seeking to integrate a regulatory change strategy and process…
-

Broken Process and Insufficient Resources to Manage Regulatory Change
Last week we looked at the challenge of the tsunami of regulatory change that organizations are flooded with, this week we look at how the internal processes and resources are insufficient to keep up with managing regulatory change in today’s dynamic, distributed, and disrupted business environment . . . The typical organization does not have…
-

A Tsunami of Regulatory Change Overwhelms Organizations
Managing and keeping up with change is one of the greatest challenges for organizations in the context of governance, risk management, and compliance (GRC). Managing the dynamic and interconnected nature of change and how it impacts the organization is driving strategies to mature and improve regulatory change management as a defined process. The goal is…
-

Information & Technology Enables Third-Party GRC
After you define your Third-Party GRC Strategic Plan, and define your Third-Party GRC Processes, next comes the defining and deploying your information and architecture to enable third-party GRC/risk management . . . The primary directive of a mature third-party governance program is to deliver effectiveness, efficiency, and agility to the business in managing the breadth…
-

Shadow Policies: Increasing Legal Exposure & Liability
Are you scared of shadows? You should be, as they can cause serious legal, operational, compliance, risk, brand/reputation, and integrity liability. For the past several years organizations have been battling shadow IT. This is the use of information technology applications, devices, software, technology, and services within departments and bypassing IT and without their approval. Shadow…
-

Becoming a Policy Management Pro with a New Online Resource
Policies, and in that context the management of policies, has become critical to define and guide culture and behavior in today’s distributed, dynamic, and disrupted business environment. Today’s organization can no longer take a haphazard approach to policies and the management thereof. When an organization fails to establish strong policies, the organization quickly becomes something…
