Upcoming Events . . .

Latest Pontifications & Thoughts . . .

  • At the Cross-roads: A Tale of Four Third Party GRC/Risk Management Roads to Travel

    At the Cross-roads: A Tale of Four Third Party GRC/Risk Management Roads to Travel

    The naturalist John Muir stated, “When one tugs at a single thing in nature, he finds it attached to the rest of the world.” This not only applies to nature but also to the reality of the Extended Enterprise in today’s complex and interconnected world. What seems to be one third-party risk cascades and interconnects…

  • Driving Efficiency into Compliance & Ethics Processes: Time Saved = Money Saved

    Driving Efficiency into Compliance & Ethics Processes: Time Saved = Money Saved

    Managing compliance and ethics has become a complex web of processes and information. The modern organization is constantly changing: new employees, shifting employees and responsibilities, evolving business processes, new and changed regulations/obligations, growing ethical concerns, and greater scrutiny from stakeholders, customers, law enforcement, and regulators. The challenge of compliance and ethics grows more confusing when…

  • Compliance & Ethics is Rapidly Evolving

    Compliance & Ethics is Rapidly Evolving

    Evolution and change happen: sometimes slowly, sometimes rapidly. In the context of compliance and ethics programs, we are seeing a significant and rapid evolution of what is expected of organizations. Organizations are required to have structured and functional compliance and ethics program that monitors compliance continuously in the context of operations, transactions, and people. A…

  • Managing Risk Creatively & Structurally

    Managing Risk Creatively & Structurally

    I think best in the abstract and imaginative. My mind is wired to be more intuitive and see relationships and images. I am more like my mother. My brother, he is like my father – wired for math and numbers. I have been competent with math, but it is not what engages me. While my…

  • Privacy, Pandemics, and Business Change…OH MY!!!

    Privacy, Pandemics, and Business Change…OH MY!!!

    The world is in turbulence all around us. What started as a health and safety issue in Asia has had a cascading impact around the world. Economic uncertainty, health and safety, work from home, IT security issues, continuity, and operational resiliency…it is like an intricate pattern of dominos falling over. In response to the pandemic,…

  • The Pandemic & the Dominos of Risk Interconnectedness

    The Pandemic & the Dominos of Risk Interconnectedness

    Risk, according to ISO 31000, is “the effect of uncertainty on objectives.” Uncertainty is all around us in 2020. Organizations go through a lot of effort to try to put a label on specific risks, but the reality is risk is too complex to put into a container and label it. An organization cannot look…

  • Effective Risk Management in Context of the Pandemic

    Effective Risk Management in Context of the Pandemic

    The COVID-19 pandemic has caught a lot of organizations by surprise. But, should it have? We have had pandemics in the past—history teaches us this over and over. The World Economic Forum has regularly reported pandemic risk on their global risk reports over the years. Political and business leaders have warned us of pandemics.  So, why has…

  • GRC Supper Club: Operational Resiliency and the Interconnectedness of Risk

    GRC Supper Club: Operational Resiliency and the Interconnectedness of Risk

    The past two months have been a crazy whirlwind of webinars, phone calls, and video meetings. Organizations the world over have been asking for calls on how to respond to the pandemic from a GRC perspective, and what the world of GRC will look like and how corporate governance, enterprise risk, and compliance and ethics…

  • Delivering 360° Contextual Awareness of Your GRC Program

    Delivering 360° Contextual Awareness of Your GRC Program

    Governance, risk management, and compliance — what we refer to collectively as GRC — is the capability to reliably achieve objectives [GOVERNANCE], address uncertainty [RISK MANAGEMENT], and act with integrity [COMPLIANCE]. Over the past twenty years, we have seen technology evolve and mature to assist organizations in achieving this definition of GRC. This evolution of…

  • Why Third-Party 360° Situational Risk Awareness is Needed Now More Than Ever

    Why Third-Party 360° Situational Risk Awareness is Needed Now More Than Ever

    I am a James Bond fan and eagerly anticipate the next James Bond film, “No Time to Die.” Unfortunately, because of the global crisis we all now face, we have to wait until November 2020 instead of seeing it on the big screen this month. While we wait for this next installment in the 007 sagas, we can still learn…

  • Centralizing Compliance and Ethics Communications in a Time of Crisis

    Centralizing Compliance and Ethics Communications in a Time of Crisis

    In a time of crisis, like what we face with the global pandemic, centralizing compliance and ethics communications and reporting is critical to streamline interactions, maintain corporate culture and integrity, improve employee morale, and communicate expectations. However, a lot of organizations are finding they are not prepared. Consider that a lot of policies are changing…

  • Being Unprepared for the Crisis Does Not Make it a Black Swan

    Being Unprepared for the Crisis Does Not Make it a Black Swan

    I may be going out on a limb and stepping on a lot of toes right now by frustrating some careers and reputations of risk managers. Simply put, this global pandemic/crisis is not a black swan event. I am finding too many GRC and specifically risk management professionals are trying to cover their behinds by…