


Upcoming Events . . .
Latest Pontifications & Thoughts . . .
-
Everything I Need to Know About Risk Management I Learned In . . .
Multiple interests require multiple threads to weave into the intricate pattern of GRC. I will keep the articles coming on Effective Policy Management & Communication but also have sufficient requests to write more on risk management. So here we begin another series (which runs parallel to policy management) on Developing a Risk Assessment &……
-
What is GRC?
The Atlanta GRC bootcamp is going well! One discussion/interaction point was to define GRC – the group came up with some excellent points. They include: GRC is about how to better run a business and provides the foundation for growth based on principles. GRC is ensuring you have a well run and sustainable business. GRC……
-
Defining a Policy Management Lifecycle
Most organizations fail to manage the lifecycle of policies. This results in policies that are out of date, ineffective, and not aligned to business needs. It further opens the doors of liability as an organization may be held accountable for the policies it has in place but are not appropriate or is not compliant……
-
Policies, Done Right, Articulate Culture
We now turn our attention back to my series on Effective Policy Management & Communication. In the previous posting we looked at the disarray and chaos of how policies are managed, maintained, and communicated within organizations. Often inconsistent, poorly written, out of date, lacking consistency, developed with no style guide, and ineffectively managed and……
-
The Value of a Common Architecture for GRC Platforms
Business is complex and dynamic, and requires agility to stay competitive. Market leadership requires the organization be quick to respond to changing conditions – to pause means loss. Governance, risk, and compliance (GRC) processes often work against business agility. Requirements and initiatives managed across numerous silos, using manual or varying technology approaches, burden the business.……
-
Wanted: GRC Psychologist
When you think you have heard everything . . . One of the attendees at the San Jose GRC Fundamentals, Strategy, and Technology Bootcamp today shared an interesting conversation she had. In pursuing discussion with other organizations that have implemented GRC strategies, one told her that they actually had to get a psychologist involved. That……
-
Top GRC Questions & Issues
The San Jose GRC Fundamentals, Strategy, & Technology bootcamp is underway with terrific interaction. The bootcamp is comprised of implementers of large down to medium sized organizations, professional service firms, and a few technology providers. The top questions/issues that the attendees are trying to resolve over the course of three days are (coming directly from……
-
BPS & Resolver – Synergetic Merger
2010 is proving to be an interesting year for the reorganization of the GRC space. It kicked off with the public announcement of the EMC/RSA acquisition of Archer Technologies. Shortly thereafter you had the announcement of the merger of BPS and Resolver. The merger of BPS and Resolver is intriguing. Unlike the acquisition of……
-
CCEP – Certified Compliance & Ethics Professional
I just passed the Certified Compliance & Ethics Professional (CCEP) exam from the Society of Corporate Compliance & Ethics (SCCE). While I meant to do this years a go – I never got around to it. The certification requires so many years of professional experience and training. While many assume that you have to……
-
Corporate Policies in Disarray and Chaos
Policies are a critical component of a GRC strategy – but often the most overlooked or neglected component. It amazes me the number of companies I go into that have complete disarray and chaos in their approach to managing corporate policies and procedures. Simply put – organizations cannot ignore policy management. Consider that: Policies……
-
GRC Reference Architecture: Industry, Geographic, & Technology Views
Over the past few months we have explored together the various components of my GRC Reference Architecture. This embodies the technology end of my broader GRC EcoSystem – which to date has over 1300 technology providers, professional service firms, and content providers of GRC cataloged into the GRC market. The components of the GRC……
-
2010 GRC Research Agenda & Education
Happy New Year! I trust that 2010 will bring you success and direction in your personal and professional life. First I need to state a deep thank you to all of my subscribers that have reached out to me over the past several weeks with your sympathy and prayers for my family as my……
