Upcoming Events . . .

Latest Pontifications & Thoughts . . .

  • 2019 GRC User Experience Award Nominations

    2019 GRC User Experience Award Nominations

    GRC 20/20 is accepting nominations for the 2019 GRC User Experience Awards! Governance, risk management and compliance (GRC) is a part of everyone’s job. Too often we shovel GRC into the bowels of the organization thinking it is the responsibility of the obscure and behind-the-scenes individuals in the back office of GRC in the organization.…

  • Operational Resiliency: Connected Management of Operational Risk

    Operational Resiliency: Connected Management of Operational Risk

    I am sitting in a pub in London having a pint after an intense week of interactions with organizations. My mind is laser focused on the burning issue of the day: operational resiliency. The FCA, PRA, and Bank of England have recently released a discussion paper focused on the need to build greater operational resilience in organizations. This challenge…

  • Manage Your Privacy Journey: GDPR, CCPA & Beyond

    Manage Your Privacy Journey: GDPR, CCPA & Beyond

    I love adventures! Whether in a city or out in nature, it is exciting to go out and do things. Simple adventures do not require a lot of planning, but you still need to be prepared for the day. More complex adventures require a lot of planning, coordination and execution. In organizations, complex adventures also…

  • Efficient and Effective Third-Party GRC Management

    Efficient and Effective Third-Party GRC Management

    Modern Organization: Interconnected Maze of Relationships Traditional brick and mortar business are a thing of the past. Physical buildings and conventional employees no longer define organizations. The modern organization is an interconnected maze of relationships and interactions that span traditional business boundaries. Layers of relationships go beyond traditional employees to include suppliers, vendors, outsourcers, service…

  • GDPR: Moving Forward Out of the Doldrums

    GDPR: Moving Forward Out of the Doldrums

    I love sailing. It has fascinated me since I was in high school, but only recently have I taken up learning to sail. While I have not sailed across an ocean, I have read many accounts of sailors getting stuck in the doldrums. The area in both the Atlantic and Pacific Ocean near the equator…

  • Monitoring and Managing Risk Effectively

    Monitoring and Managing Risk Effectively

    Organizations take risks all the time but fail to monitor and manage risk effectively. A cavalier approach to risk-taking is a result of a poorly defined risk culture. It results in disaster, providing case studies for future generations on how poor risk management leads to the demise of corporations — even those with strong brands.…

  • Understanding & Improving Governance, Risk Management & Compliance

    Understanding & Improving Governance, Risk Management & Compliance

    Governance, risk management & compliance (GRC) is something an organization does and not something an organization buys. GRC, done properly, is what is achieved throughout the business and its operations. By definition, GRC is “a capability to reliably achieve objectives [governance] while addressing uncertainty [risk management] and acting with integrity [compliance].” (source: OCEG GRC Capability Model that GRC 20/20 has helped define and…

  • The One Regulation to Rule Them All: UK SMR/CR & Cascading Regulations

    The One Regulation to Rule Them All: UK SMR/CR & Cascading Regulations

    For those of you on this list that know me on a personal level, I am a huge Tolkien fan. In fact, I am just a Master’s thesis away from my M.A. in Church History and the thesis is on the influence of Medieval theology, particularly Aquinas, on J.R.R. Tolkien and his works (my particular…

  • Managing Risk & Compliance in the Extended Enterprise

    Managing Risk & Compliance in the Extended Enterprise

    Modern Organization: Interconnected Maze of Relationships No man is an island, entire of itself; Every man is a piece of the continent, a part of the main.[1] Replace the word ‘man’ with ‘organization’ and the seventeenth-century English poet John Donne is describing the post-modern twenty-first century organization. In other words, “No organization is an island…

  • Enabling the 1st Line of Defense with Policy, Training & Issue Reporting

    Enabling the 1st Line of Defense with Policy, Training & Issue Reporting

    Like battling the multi-headed Hydra in Greek mythology, redundant, manual, and uncoordinated governance, risk management, and compliance (GRC) approaches are ineffective. As the Hydra grows more heads of regulation, legal matters, operational risks, and complexity, scattered departments of GRC responsibilities that do not work together become overwhelmed and exhausted and start losing the battle. This…

  • Compliance, Particularly for Privacy, Requires Data Process Mapping & Disposition

    Compliance, Particularly for Privacy, Requires Data Process Mapping & Disposition

    Compliance used to be simpler. An organization was given a set of requirements and it had to check the boxes that it met the requirements and compliance was achieved. The complex nature of business today and the focus on information in the digital economy has driven compliance requirements to a new level of intricacy and…

  • Is SMR & CR, the UK Financial Services biggest challenge for 2018?

    Is SMR & CR, the UK Financial Services biggest challenge for 2018?

    The UK Senior Manager’s Regime and Certification Regime (UK SMR/CR) is one of the most significant challenges financial services firms are facing right now. The Financial Conduct Authority (FCA) has recently announced that this regulation is going to be applied to all firms governed by the FCA: over 58,000 organizations. This is the governing regulation…