


Upcoming Events . . .
Latest Pontifications & Thoughts . . .
-

Is Policy Management Causing More Pain than Gain?
The Policy Management Illustrated Series Frustrated by policy management? Having trouble finding all the policies (both authorized and unauthorized) floating around in your organization? Wasting time and resources that could be well applied elsewhere to help the organization achieve its objectives and stay on track? Realizing something has to change? In our research, we have…
-

Exposing IRM for What it Really is: GRC Light
Gartner, particularly John Wheeler, is hard at work trying to convince the world that their Integrated Risk Management (IRM) is something new to replace Governance, Risk Management & Compliance. You can check out John’s latest post mischaracterizing and misleading organizations in: GRC May Keep You “Out of Trouble” ,But IRM Will Keep You “ In Business” The first…
-

Understanding Third Party GRC Maturity: Agile Stage
A haphazard department- and document-centric approach for third party GRC compounds the problem and does not solve it. It is time for organizations to step back and mature their third-party GRC approaches with a cross-functional and coordinated strategy and team to define and govern third party relationships. Organizations need to mature their third-party governance with…
-

The Intersection of GRC and Policy Management
Policies matter, and policy management matters. Period. Policies are critical governance documents for every organization. They set guardrails and parameters of acceptable and unacceptable behavior for individuals, processes, and transactions. When they are managed and enforced properly, policies guide and define corporate culture. So, why do organizations approach and manage policies so carelessly? Policies set…
-

Understanding Third Party GRC Maturity: Integrated Stage
A haphazard department and document centric approach for third party GRC compounds the problem and does not solve it. It is time for organizations to step back and mature their third party GRC approaches with a cross-functional and coordinated strategy and team to define and govern third party relationships. Organizations need to mature their third…
-

The 3 Lifecycle Stages of Vendor Security Risk Management: Offboarding
How do you say goodbye to a third party? This is the third of a three-part series on vendor risk management through the lifecycle of the relationship. Today, we focus on the offboarding monitoring process. This is the third in a three-part guest blog series looking at risk management throughout the lifecycle of a third…
-
Have You Hugged Your CECO/CCO Today?
Today is the official National Compliance Officer today! This is a very challenging role in organizations and one that is in the midst of a lot of change. Below is a link to my SWOT Analysis of the CECO role on this topic. I am presenting on this next week at Converge19 as well. Chief…
-

5 Reasons to be Happy About UK SMCR
Regulation and oversight – what a burden to business. That is the common expression financial services firms have as they respond to 220 regulatory change events around the world every business day. UK Senior Managers Certification Regime is the uber regulation that puts accountability, teeth, and enforcement to other regulations and risk management practices. But…
-

Navigating Chaos
Below is Michael Rasmussen’s article found in the Autumn 2019 issue of Enterprise Risk, published by the Institute of Risk Management (The IRM). The physicist Fritjof Capra once said, “The more we study the major problems of our time, the more we come to realize that they cannot be understood in isolation. They are systemic…
-

The 3 Lifecycle Stages of Vendor Security Risk Management: Ongoing Monitoring
This is the second of a three-part series on vendor risk management through the lifecycle of the relationship. Today, we focus on the ongoing monitoring process. Too often organizations conduct security due diligence when onboarding a third party (e.g., vendor, supplier, outsourced, service provider, consultant) and fail to monitor security throughout the lifecycle of the…
-

The 3 Lifecycle Stages of Vendor Security Risk Management: Onboarding
This is the first of a three-part series on vendor risk management through the lifecycle of the relationship. Today, we focus on steps to achieve a proper and friction-free onboarding process. The Vendor Relationship: Stages in the Lifecycle Traditional brick and mortar business is a thing of the past: physical buildings and conventional employees no…
-

Compliance Disclosure Solutions: Separating the Simple from the Advanced
GRC 20/20 is seeing a growing demand for compliance management technologies from the Corporate Compliance and Ethics department (e.g., Chief Ethics and Compliance Officer, Chief Compliance Officer). This demand spans from a broad compliance management platform to manage the range of compliance tasks and activities, to focused solutions in areas such as policy management, third…
