GRC Journal - (Page 60) The Ins and Outs of GRC to owners. Leading GRC technology solutions include advanced, configurable workflow capabilities that notify process owners of pending work, facilitate the signoff on work activities and provide an audit trail that tracks the details of the transactions. 4. Transparency and visibility within and across the enterprise are critical to keeping GRC managers aligned. Integrated GRC solutions provide a holistic view of GRC data through dashboards, reports and proactive notifications. Continuous controls monitoring (CCM) can sometimes be implemented as a qualified GRC approach. What should Corporate America know about CCMs? Do CCM platforms serve as a cure-all, or are GRC systems still the standard? Corporate America should know that CCM solutions provide a great compliment to core GRC systems but do not serve as a direct replacement. CCM systems do an excellent job at monitoring detailed transactional systems, filtering large volumes of data and providing notifications of potential transactional issues. CCM software enables organizations to detect weaknesses in control structure, flaws with existing processes or transactions that stray beyond a specified risk tolerance. CCM products remove some of the heavy lifting and can enable efficiencies in completing auditing tasks. Effective GRC requires the documentation, management, reporting and oversight of processes, risks and controls. CCM solutions provide capabilities to streamline the testing of specific process and controls and provide transactional transparency for information that exceeds specified tolerance. However, CCM solutions do not offer the capabilities to manage the core GRC disciplines of financial controls management operational risk management, enterprise risk management, IT governance and compliance. With an increased focus on GRC standards, what are some of the transitions that corporations are making in order to ensure compliance? Are there any trends that are altering the focus of GRC from a technology standpoint? Convergence is the single most significant trend that is driving changes in GRC technology. We are seeing many of our clients bring together the multiple disciplines of GRC, including internal audit, risk and compliance groups. These changes involve not only new organizational structures, but also new and more united business processes. As a result, organizations are now demanding GRC solutions that address the multiple facets of GRC, all contained in one unified solution. Another common trend for both large and small organizations is the transition away from task-oriented, project-based GRC programs to process-oriented, holistic GRC programs. As organizations bring together the various disciplines of GRC, they have quickly realized that the most efficient and sustainable way to manage these GRC initiatives is to take a long-term, program-based approach to GRC. Many corporations are now managing compliance responsibilities as an ongoing business, technology compliance and risk management program – not as a series of one-off projects. The final trend is the elevation of the internal audit function. As corporations invest and mature in their GRC processes, they quickly realize the importance of having a solid discipline of oversight and assurance over the GRC initiatives. Internal audit provides the required discipline, skill set and expertise to play this oversight and assurance role. As a result of this increased focus on internal audit, corporations are looking for solutions that include comprehensive internal audit functionality as a central feature that can be leveraged across the other GRC disciplines. 22 Business Trends Quarterly Technology Solutions. Business Strategy.
For optimal viewing of this digital publication, please enable JavaScript and then refresh the page. If you would like to try to load the digital publication without using Flash Player detection, please click here.