Upcoming Events . . .

Latest Pontifications & Thoughts . . .

  • GRC Reference Architecture: Making Sense of the GRC Technology Landscape

      While GRC is ultimately about collaboration and communication between business roles and processes, technology provides the backbone that enables GRC. To describe this technology, Corproate Integrity has defined the GRC Reference Architecture (this is closely aligned to the second version of the Open Compliance & Ethics Group (OCEG) GRC Technology Blueprint). This model is…

  • Stakeholder Reputation Risk

  • Enterprise Risk Management Policy Structure

      I am amazed at the number of risk management programs I encounter that lack an organized structure and approach. So often what we know as ERM (enterprise risk management) is a hodge-podge of processes and assessments that somebody tagged the ERM label on without much thought for what they were doing. In fact, most…

  • ERM vs GRC? Response to Steven Minsky's Blog

    My response to Steven Minsky’s blog on: ERM vs GRC? SEC Says No to Myopic Approach: Costly Example from Goldman Sachs   Steve, You are struggling with understanding GRC. Everything you describe about ERM represents the R in GRC. ERM is the R in GRC if GRC processes (and supporting technologies) are done right. That…

  • GRC Professional Certification: Call to Action

      Whether you use the term or not – the fact is organizations do GRC. You will not get one organization to stand up and state they lack governance, do not manage risk, and can care less about compliance to mandated (e.g., regulatory) and voluntary (e.g., social responsibility) boundaries. The question is: are your organization’s…

  • 2010 Compliance Trends & Directions – A Corporate Integrity Research Survey

    Good research and information is the core of a successful strategy. As organizations seek to understand how their corporate compliance program stacks up against others it is necessary to get good data. Good data allows you to compare the direction of your current corporate compliance initiatives to others. To compliance officers/managers understand how their programs…

  • Providing Consistent Policies Through a Style and Language Guide

      I have stated it before and I will state it again: the typical organization is a mess when it comes to managing policies and procedures. Organization size does not matter – I have seen small to large organizations that have horrible policy management practices. Policies are scattered across the business, reside in a variety…

  • GRC Achievement Awards & Compliance Week 2010

      There are good conferences and bad conferences. Having spent seventeen professional years attending various GRC, risk, compliance, and security conferences – most are categorized in my poor to bad category with only a handful making the good. There are a few conferences that I deeply respect – some put on by vendors others by…

  • Everything I Need to Know About Risk Management I Learned In . . .

      Multiple interests require multiple threads to weave into the intricate pattern of GRC. I will keep the articles coming on Effective Policy Management & Communication but also have sufficient requests to write more on risk management. So here we begin another series (which runs parallel to policy management) on Developing a Risk Assessment &…

  • What is GRC?

    The Atlanta GRC bootcamp is going well! One discussion/interaction point was to define GRC – the group came up with some excellent points. They include: GRC is about how to better run a business and provides the foundation for growth based on principles. GRC is ensuring you have a well run and sustainable business. GRC…

  • Defining a Policy Management Lifecycle

      Most organizations fail to manage the lifecycle of policies. This results in policies that are out of date, ineffective, and not aligned to business needs. It further opens the doors of liability as an organization may be held accountable for the policies it has in place but are not appropriate or is not compliant…

  • Policies, Done Right, Articulate Culture

      We now turn our attention back to my series on Effective Policy Management & Communication. In the previous posting we looked at the disarray and chaos of how policies are managed, maintained, and communicated within organizations. Often inconsistent, poorly written, out of date, lacking consistency, developed with no style guide, and ineffectively managed and…