GRC Journal - (Page 82) HAND IN HAND miChAeL rASmUSSen, vice President, Forrester research, says, “The GrC software platform enables an enterprise risk and compliance strategy; the software itself is not a strategy.” Organizations confront a complex web of compliance mandates and enterprise risks. Historically, they have treated their risk and compliance initiatives as independent silos that they scatter across distributed business operations around the globe. With increased focus on corporate governance and enterprise risk management, firms need governance, risk and compliance (GRC) software platforms to drive sustainability, efficiency and consistency in managing enterprise risk and compliance. The GRC software platform market has grown considerably in the last five years and should expand to over $1 billion by 2011. Today, the GRC software platform market is fragmented and includes 64 vendors – thus, it is ripe both for further specialization of products and consolidation of small vendors. What is the Value of the GRC Software Platform? The GRC software platform enables an enterprise risk and compliance strategy; the software itself is not a strategy. To get the most value out of a GRC software platform requires that existing risk and compliance organizational structure and processes are in place so that the software can support and enhance through technology enablement. GRC software platforms must be: Sustainable – Although firms might wish otherwise, risk and compliance activities are not going away. Organizations that have approached risk and compliance as a project have learned the hard way that it needs to be managed as a process. The dynamism of business results in rapid changes to business processes, relationships and technologies that firms must continually map to risk and compliance requirements. When firms add new acquisitions, relationships, lines of business or products, compliance officers must keep abreast of these changes. The only way to build a sustainable risk and compliance process is to invest in a GRC software platform. Consistent – In an era of increased accountability and corporate governance, firms can’t afford not to consistently understand, approach and measure risks and controls. The GRC software platform provides a centralized hub with which to manage risk and compliance across a firm’s disparate business silos. Using business process and content management technologies, GRC software can maintain a consistent taxonomy, approach and accuracy of risk- and control-related information and communication. GRC software platforms allow an organization to centrally store policies, procedures and controls, as well as use common assessment processes. Then information that is gathered can be reused for other assessments. Efficient – Business operations today struggle with risk and compliance processes that have been stove-piped, ad hoc and inconsistent. Gathering risk information once, as opposed to through a barrage of independent assessments asking the same questions, alleviates the frustration of line-of-business organizations. GRC software platforms automate risk and compliance processes with workflow, content management and collaboration features, thus relieving the burden on the business through the shared use of information across assessments instead of taxing the business by asking them the same question week after week. Transparent – The end game is an organization that is able to accurately identify and manage risk and compliance in an era of increased corporate governance. Organizations today need transparency into business operations and strategies so the organization can navigate around threats and seize on opportunities. Further, organizations need to strive for greater transparency in reporting to executives, the board, regulators and stakeholders, as well as the community at large. Business Trends Quarterly Technology Solutions. Business Strategy.
For optimal viewing of this digital publication, please enable JavaScript and then refresh the page. If you would like to try to load the digital publication without using Flash Player detection, please click here.