Upcoming Events . . .

Latest Pontifications & Thoughts . . .

  • Lessons Learned in Compliance Management in 2020

    Lessons Learned in Compliance Management in 2020

    What have we learned from 2020? I think all of us have learned quite a bit in both our personal and professional lives. 2020 has stretched us as individuals and as organizations in various and unexpected ways. There certainly was a lot of tension, reaction, loss, trials, and tribulation. But there are also positive aspects…

  • GRC 20/20’s 2020 Research Year in Review

    GRC 20/20’s 2020 Research Year in Review

    2020 was certainly a year for the history books. While it has been a roller coaster that moves on into 2021 now, it certainly had a lot of impact on governance, risk management, and compliance (GRC) strategies, processes, and technology. The keywords for 2021 are integrity and resiliency. Organizations are seeking to increase organizational integrity…

  • Why Spreadsheets, Documents & Emails Fail for GRC

    Why Spreadsheets, Documents & Emails Fail for GRC

    At times I can sound like a broken record – repeating myself over, and over, and over, and over again, and again, and again.  One of my prominent soapboxes over the past two decades has been the failure of spreadsheets, documents, and emails to assess, audit, manage, and monitor governance, risk management, and compliance (GRC)…

  • Complexity of Business Demands a New Paradigm in Legal Governance, Risk Management & Compliance

    Complexity of Business Demands a New Paradigm in Legal Governance, Risk Management & Compliance

    Understanding the Interrelationship of Legal Risk and the Business In today’s global business environment, a broad spectrum of economic, political, social, legal, and regulatory changes are continually bombarding the organization. The organization continues to see exponential growth of regulatory requirements and legal obligations (often conflicting and overlapping) that must be met, which multiply as the…

  • Operationalizing GRC in Context of Legal & Privacy: the Last Mile of GRC

    Operationalizing GRC in Context of Legal & Privacy: the Last Mile of GRC

    At its core, GRC is the capability to reliably achieve objectives [GOVERNANCE], address uncertainty [RISK MANAGEMENT], and act with integrity [COMPLIANCE]. GRC is something organizations do, not something they purchase. They govern, they manage risk, and they comply with obligations. However, there is technology to enable GRC related processes, such as legal and privacy, to be…

  • Disclosure Management: Comparing Compliance Solutions

    Disclosure Management: Comparing Compliance Solutions

    Compliance disclosures are a critical element of an organization’s compliance and ethics management program. The organization requires structured approaches to managing disclosures such as conflicts of interest, and a way to address compliance related forms and processing for gifts, entertainment, and travel or facilitated payments. This requires the ability to intake information, route it for…

  • A Business Case for Integrated Third-Party GRC Across the Extended Enterprise

    A Business Case for Integrated Third-Party GRC Across the Extended Enterprise

    One of the greatest challenges to organizations today is managing the extended enterprise; the web of third-party relationships that support the business and its operations. The integrity of the organization is no longer defined by traditional brick and mortar walls and employees. The integrity of the organization requires continuous monitoring and control of the governance,…

  • Delivering on Agile Compliance in Dynamic Business

    Delivering on Agile Compliance in Dynamic Business

    Organizational exposure to compliance risk is rising while the cost of compliance soars. Organizations operate in a field of ethical, regulatory, and legal landmines. The daily headlines reveal companies that fail to comply with obligations and value. Corporate ethics is measured by what a corporation does and does not do when it thinks it can…

  • Efficiency & Agility in Accountability Compliance – SMCR, BEAR, SEAR, MIC, GIAC

    Efficiency & Agility in Accountability Compliance – SMCR, BEAR, SEAR, MIC, GIAC

    Accountability is More Than Responsibility There is a difference between accountability and responsibility. An individual or organization can outsource or delegate responsibilities, but one cannot do so with accountability. To address the breadth of compliance and ethics failures, as well as risk management, in financial services there have been a growing array of accountability regulations…

  • A New Framework for Defining and Approaching Information Governance

    A New Framework for Defining and Approaching Information Governance

    Information governance has become a critical objective for organizations. In the context of the pervasive use of information throughout the enterprise, operational reliance on information, and increased regulation and liability of information, organizations are building structured approaches to information governance. This is to ensure the proper collection, use, and control of sensitive information – intellectual property,…

  • Why Policies, and Policy Management, Matters

    Why Policies, and Policy Management, Matters

    It is finally here! For the past year, I have been working hard with OCEG on the Policy Management Illustrated eBook. I have spent countless hours behind Adobe Illustrator working hard on doing the design, layout, concepts, and process of policy management in these illustrations in collaboration with OCEG and many other firms. Below is…

  • Policy Engagement In A COVID & Post-COVID World

    Policy Engagement In A COVID & Post-COVID World

    The world has changed, business has changed. A worldwide pandemic has caused restructuring of processes, employees, and activities. It has forced organizations to look for agile ways to manage a dynamic business environment. As organizations went into lockdown and moved employees to a work from home environment they were confronted with issues, such as: Reduced…