Upcoming Events . . .

Latest Pontifications & Thoughts . . .

  • GRC 2011: Gripes & Directions

    No matter if you use the term or not – GRC (Governance, Risk Management, & Compliance) is a reality.  We are in 2011 and it has been ten years now since I first started using the term GRC in research and interactions with organizations. The truth of the matter is – GRC as an acronym…

  • Regulatory Intelligence Enabled by a GRC Technology Platform

    The core elements of a regulatory intelligence process can be delivered in a GRC software platform. The solution will allow the compliance and legal functions to profile regulations, link regulatory content aggregators, and have new developments or alerts pushed into the application and disseminated to the appropriate subject-matter expert for review and analysis. Technology tailored…

  • Approaching Regulatory Change as a Consistent Process

      The old paradigm of regulatory change management is clearly a recipe for disaster given the volume, pace of change and the broader operational impact of today’s laws and regulations. Just as the CFO needs a financial system or the sales department needs CRM, legal and compliance need regulatory intelligence. Organizations should explore how technology…

  • Manual and Ad Hoc Regulatory Change Processes

      Over the years, many organizations have matured in their view of internal risk-intelligence issues. However, monitoring external regulatory environments remains a broken process. To date, regulatory risk is managed in a very sporadic and ad hoc fashion with little accountability and oversight — if at all. Most organizations rely on manual ad hoc processes…

  • Regulatory Intelligence: Bombardment of Regulations upon Organizations

      After a brief hiatus, I turn our attention back to the issues of policy management and compliance. We will now explore (over several posts) the issue of Regulatory Intelligence and Monitoring. Hordes of regulation bear down on the organization Business is under siege by legion of laws and regulations. Compliance itself has become difficult…

  • GRC Market Developments: Reflections on IBM/OpenPages, Wolters Kluwer/FRS Global, and Thomson Reuters

      New GRC strategies, mergers, acquisitions . . . the last few weeks have been hopping for a market research analyst.Every time I sat down to blog on my thoughts someone else has come out without an announcement resulting in a whirlwind of buyer, market, and press questions.Between sessions at the OCEG GRC 360 Executive…

  • Why GRC & What Is It?

     Why GRC & What Is It? GRC, simply put, is to provide collaboration between silos of governance, risk, and compliance. It is to get different business roles to share information and work in harmony. Harmony is a good metaphor, we do not want discord where the different parts of the organization are going down different…

  • Policy Communication in a YouTube Generation

      I am a man on a mission. Make that a business on a mission – to completely refocus organizations on how they approach policy management and communication. To take business to the new frontier, to boldly go . . . You get the picture. Policies are in a complete and disappointing disarray. In my…

  • Managing Risk & Compliance Across Extended Business Relationships

      Businesses are engaged in a continuous struggle to grasp the intricacies of risk management in an interconnected environment. The focus during the past few years has been on operational risk management — managing risk to business operations and processes. However, the standard definition used for operational risk management is flawed: Operational Risk Management: “.…

  • SAI Global Acquires Integrity Interactive

    There has been a lot of consolidation and restructuring in the GRC space already in 2010 – SAI Global takes the next step by acquiring Integrity Interactive.   This is particularly intriguing as SAI Global continues to position itself as a dominant player focused on the C in GRC, that being compliance. Integrity Interactive expands…

  • SAP and CA Deliver on Comprehensive Vision of Integration of GRC

    As an industry pundit and analyst it is always fun to play match maker. For some time I have been pontificating that SAP and CA are very complimentary in their approach to the GRC market. While one focuses on business processes and applications (SAP), the other (CA) focuses on IT management and security. I was…

  • Achieve GRC Value: Efficient Business Process and Application Monitoring

      Business today requires agility and efficiency to stay competitive. Organizations must respond rapidly to changing conditions, while managing financial and human capital costs. Compliance processes often work against business agility and efficiency. Requirements and initiatives bear down on the business, and become burdensome and inflexible. When managed manually and/or across numerous siloed business units,…