Upcoming Events . . .

Latest Pontifications & Thoughts . . .

  • 2013 GRC Value Award: Enterprise GRC

    GRC 20/20 Research awarded MetricStream and Sterling Bank its 2013 GRC Value award in the Enterprise GRC category. MetricStream Enterprise GRC Solution Suite allowed Sterling Bank to transition from using hundreds of spreadsheets created every year to complete audits, credit reviews and risk assessments in addition to hundreds of other documents compiled to report on…

  • 2013 GRC Value Award: Risk Management

    GRC 20/20 Research awarded Modulo Risk Manager its 2013 GRC Value award in the Enterprise Risk Management category. The financial services company used Modulo Risk Manager to help it comply with HIPAA, PCI and SOX, and its consolidation of its 350 independently chartered bank branches, with 6,700 employees and a heterogeneous environment spanning a variety…

  • 2013 GRC Value Award: Insurance & Claims Management

    GRC 20/20 Research awarded Riskonnect RMIS and the State of Utah its 2013 GRC Value award in the Insurance & Claims Management category. Riskonnect RMIS’s fully automated insurance risk management software platform addresses insurance claims, litigation, exposure, and policy management. The Utah Division of Risk Management (DRM) chose Riskonnect RMIS (risk management information system) to…

  • 2013 GRC Value Award: Business Continuity Management

    GRC 20/20 Research awarded RSA® and Equifax its 2013 GRC Value award in the Business Continuity Management category. After implementing RSA Archer’s Business Continuity Management solution, U.S. consumer credit reporting agency Equifax experienced an immediate 60 percent reduction in time to create business continuity and disaster recovery plans, and a 20 percent OPEX savings for…

  • 2013 GRC Value Award: Investigations Management

    GRC 20/20 Research awarded SAI Global and HealthPlus its 2013 GRC Value award in the Investigations Management category. With the help of the SAI Global solution called Compliance 360®, HealthPlus, a Michigan health and wellness organization, reduced its average days to complete investigations cases by 56 percent. Average days to complete cases has been reduced…

  • 2013 GRC Value Award: Control Monitoring & Assurance

    GRC 20/20 Research awarded SAP its 2013 GRC Value award in the Control Monitoring & Assurance category. When SAP was implemented at a large multinational beverage corporation, during the first year, the company was able to remove more than 4,000 invalid system IDs, implement a process to remove roles from users if the role is…

  • 2013 GRC Value Award: Compliance Management

    GRC 20/20 Research awarded The Hartford its 2013 GRC Value award in the Compliance Management category. The Hartford, a leader in property and casualty insurance, group benefits and mutual funds, uses the RSA Archer GRC Platform to support over 80 GRC processes including a New York State Labor regulation instituted in 2012.  By building a…

  • GRC 20/20 Announces 2013 GRC Value Award Recipients

    GRC 20/20 today announced the launch of its inaugural GRC Value Awards program. Fifteen leaders in GRC were honored for real-world implementations of Governance, Risk Management and Compliance programs and processes that have returned significant and measurable value to an organization.  Nominations from GRC solution providers as well as internal GRC programs within organizations were…

  • The Rise of GRC Architecture in GRC 3.0

    Moving Beyond the GRC Platform to GRC Architecture Business is complex.  Gone are the years of simplicity in business operations.  Exponential growth and change in regulations, globalization, distributed operations, changing processes, competitive velocity, business relationships, disruptive technology, legacy technology, and business data encumbers organizations of all sizes. Keeping this complexity and change in sync is…

  • Where does conflict minerals fit into your broader 3rd party GRC strategy?

    The 3rd Party GRC market is the fastest growing segment of the GRC market.  The pressures are many: social accounability/international labor standards, quality, environmental, health and safety, privacy, informaiton security, credentialing, code of conduct, geo-political and operational risk.  An organization's vendors, suppliers, outsourcers, agents, service providers, contractors, consultants, temporary workers . . . it is…

  • How Do I Achieve Effective, Efficient, & Agile Conflict Mineral Compliance?

    The specific obligation of the Conflict Mineral Rule is to gather information about the use and source of 3TG in products and report to the SEC (and on the organization's website). As with other significant regulations with a far reach (e.g., Sarbanes Oxley), there is a lot of confusion out of the gates. This includes…

  • Growing Risk Exposure in Business Relationships

    This is part 1 in GRC 20/20's series of posts on Conflict Mineral Compliance and broader 3rd Party GRC . . .  No company is an island unto itself: organizations are a complex and diverse system of business relationships. Governance, risk management and compliance (GRC) challenges do not stop at traditional organizational boundaries. Organizations today…