Upcoming Events . . .

Latest Pontifications & Thoughts . . .

  • The GRC Mystery House

    Governance, Risk Management, and Compliance – every organization does it.  There are variations in the opinion of what we call GRC.  Some like it and some do not.  Some use the term ERM in much the same way I use the term GRC, others may call it something else or not even have a name……

  • The Titanic: An Analogy of Enterprise Risk

    As we close out 2012 let us roll the years back from 2012 to 1912.  One hundred years a go was the disaster of the Titanic.  What can we learn from it today? I have been told that Captain E.J. Smith stated before the Titanic set sail, “Never in all history have we harnessed such……

  • Improving Policies Through Metrics

    Thank you for joining me on this journey through Effective Policy Management. Today we come full circle and bring the effective policy management process to closure. Let’s review where we have been. The first illustration and roundtable introduced the topic of why policies matter and my Effective Policy Management Lifecycle. Each illustration after that took……

  • Get Your GRC House in Order: Fundamental Steps Before Buying GRC Technology

    Your organization could be at risk because of the scattered and disconnected approaches of past compliance information and processes. To prevent unanticipated risk exposure, your organization may require a governance, risk management and compliance (GRC) that takes into account a thorough understanding of the state of your environment. So how do you get your GRC……

  • What is risk management?

    Risk management is maturing, but as a result needs to be understood correctly and reminded that it does not rule the roost. I have three teenage boys (19, 18, and 16).  At times my boys get to big for their britches and need to be reminded what the pecking order is.  It does not mean……

  • Concluding the GRC Analyst Rant

    If you have been following my posts, you will know that I created a firestorm of discussion on: Rethinking GRC, Analyst Rant, Gartner’s 2012 EGRC Magic Quadrant.  If you go to this link you will see the range of comments – many anonymous – from on the topic. French Caldwell, who continues to be a gracious……

  • Accepting Nominations for the 2013 GRC Technology Innovation Awards

    ANNOUNCEMENT: GRC 20/20 is accepting nominations for the 2013 GRC Technology Innovation Awards. To nominate a technology solution – please download the form. The GRC Technology Innovation Awards are to recognize technologies that are revolutionizing Governance, Risk Management, and Compliance (GRC).  Please understand what it is NOT: The purpose of these awards is NOT to……

  • Effective Policy Enforcement Involves Technology

    I find that ineffective and unenforced policies are rampant within organizations, and are a thorn in the side of compliance and policy managers.   Mismanagement of policy has grown exponentially with the proliferation of documents, collaboration software, file shares, and Websites. Organizations end up with policies scattered on dozens of sites with no defined understanding……

  • Policy Communication in a YouTube Generation

    So you wrote a policy—now what? Policies are only effective if you can show that they have been communicated and understood. Having a written policy that nobody knows about is just like having no policy at all. You cannot hold people accountable to a policy until you have made them aware of the policy. Unfortunately,……

  • Maintaining Policies and Keeping Them Relevant

    The webinar on policy management addresses a common flaw – the failure to properly maintain policies once issued.  Every policy should go into a periodic review to ensure it remains accurate and necessary.  And given the number of policies in most organizations, and the numerous factors that may give rise to a need for change, this……

  • Measuring Policy Compliance and Metrics

    This webinar looks at the critical issue of ensuring policy adherence, compliance, and metrics for managing polices.  Attendees will learn the challenges, best practices, and benefits of a measurable and trackable system for policy enforcement. Learning Objectives: Understand monitoring and validation of compliance to policies Define methods for compliance metrics and assessments Determine how to manage……

  • Increasing Compliance Effectiveness, Efficiency, and Agility with Technology

    Compliance obligations and risk to the business is like the hydra in mythology — organizations combat risk, only to find more risk springing up to threaten the organization. Managing GRC activities in disconnected silos leads the organization to inevitable failure. Reactive, document-centric, siloed applications, and manual processes for GRC fail to actively manage compliance in……