Upcoming Events . . .

Latest Pontifications & Thoughts . . .

  • Understanding Third Party GRC Maturity: Defined Stage

    Understanding Third Party GRC Maturity: Defined Stage

    A haphazard department and document centric approach for third party GRC compounds the problem and does not solve it. It is time for organizations to step back and mature their third party GRC approaches with a cross-functional and coordinated strategy and team to define and govern third party relationships. Organizations need to mature their third…

  • Policy & Training Engagement in a Millennial Generation

    Policy & Training Engagement in a Millennial Generation

    As the only analyst covering the range of policy and training management solutions as its own segment of the Governance, Risk Management, and Compliance (GRC) market, I am asked several times a month on who is providing the next generation portal that integrated into one portal both policy communication and training related to the policy.…

  • The Rhythm of Risk: Managing Risk Throughout the Context of Business

    The Rhythm of Risk: Managing Risk Throughout the Context of Business

    Writing about risk management is like trying to have an intelligent conversation today about religion or politics. Individuals in the risk management community have polarized views and if someone does not agree with you 100% you end up in the crosshairs of an attack. It is sad. Instead of intelligent discussion where we can come…

  • Understanding Third Party GRC Maturity: Fragmented Stage

    Understanding Third Party GRC Maturity: Fragmented Stage

    A haphazard department and document centric approach for third party GRC compounds the problem and does not solve it. It is time for organizations to step back and mature their third party GRC approaches with a cross-functional and coordinated strategy and team to define and govern third party relationships. Organizations need to mature their third…

  • Policy Management Tips for Companies in Asia

    Policy Management Tips for Companies in Asia

    On 30th July, ClauseMatch hosted a Policy Management Workshop with Governance, Risk & Compliance (GRC) expert Michael Rasmussen in Singapore, the first in our global series that aim to provide a blueprint for attendees on effective policy management in today’s dynamic business, regulatory and risk environment. We caught up with Michael after the workshop to hear his summary of…

  • Understanding Third Party GRC Maturity: Ad Hoc Stage

    Understanding Third Party GRC Maturity: Ad Hoc Stage

    A haphazard department and document centric approach for third party GRC compounds the problem and does not solve it. It is time for organizations to step back and mature their third party GRC approaches with a cross-functional and coordinated strategy and team to define and govern third party relationships. Organizations need to mature their third…

  • Policy Management Technology: Separating the Simple from the Advanced

    Policy Management Technology: Separating the Simple from the Advanced

    Most organizations are waking up to find their policies in a complete disarray. Over the years policy portals have sprung up across the organization. HR has their portal, IT has one, Finance/Accounting has another, Legal/Compliance still another, and it goes on through other departments. Policies look different on each portal, sometimes they conflict with each…

  • Michael Rasmussen on GRC value & creating your GRC RFP template

    Michael Rasmussen on GRC value & creating your GRC RFP template

    What do you need to include in a GRC RFP? We asked one of the experts in this interview. Enterprise governance, risk, and compliance (GRC) strategies can help organizations across the board become more efficient and agile in navigating the ever-changing regulatory and risk environment. However, in order to maximize efficiency, effectiveness, and agility, organizations…

  • From Ad Hoc to Agile: Set Your Course for Third-Party GRC Maturity

    From Ad Hoc to Agile: Set Your Course for Third-Party GRC Maturity

    This post is an excerpt from GRC 20/20’s most recent research piece, Third Party GRC Maturity Model: A New Paradigm in Governing Third Party Relationships, and upcoming webinar From Ad Hoc to Agile: Set Your Course for Third-Party GRC Maturity. Traditional brick-and-mortar business is a thing of the past: physical buildings and conventional employees no…

  • Defining a Risk Culture: Critical Elements of an Enterprise Risk Management Policy

    Defining a Risk Culture: Critical Elements of an Enterprise Risk Management Policy

    I am amazed at the number of risk management programs I encounter that lack an organized structure and approach. So often what we know as ERM (enterprise risk management) is a hodge-podge of processes and assessments that somebody tagged the ERM label on without much thought for what they were doing. In fact, most of…

  • Challenges in Risk Management

    Challenges in Risk Management

    Providing 360° Contextual Awareness of Risk The physicist, Fritjof Capra, made an insightful observation on living organisms and ecosystems that also rings true when applied to risk management:  The more we study the major problems of our time, the more we come to realize that they cannot be understood in isolation. They are systemic problems,…

  • How Analytics is Influencing Governance, Risk Management & Compliance (GRC)

    How Analytics is Influencing Governance, Risk Management & Compliance (GRC)

    Humans excel at analytics; it is the way our brains are wired. We are constantly taking in information, processing, analyzing, and making decisions. Whether it is crossing a street, reading a book, watching a show, being a spectator or a participant at a sporting event . . . we are constantly analyzing everything around us.…