GRC Journal - (Page 95) Governance, Risk & Compliance KNOWLEDGE TRULY IS POWER BUILDING A BRIDGE TO SUPPORT BUSINESS OBJECTIVES Communication and understanding between GRC and IT must be improved; for successful GRC, IT must contribute to the cause. Scott Mitchell, Chairman and CEO of the not-for-profit Open Compliance & Ethics Group (OCEG); and Sebastian Holst, Director of OCEG Technology Programs discuss the growing field of Governance, Risk and Compliance (GRC) management and how OCEG can help. operational, financial, regulatory, reputational, and strategic domains. At OCEG, we work to integrate the management of those risks with the principles of effective corporate governance, regulatory compliance, and a strong, positive culture – and ultimately translate these powerful concepts into practice and process. What is the OCEG Framework, and what does it look to address? SM The OCEG Framework is a comprehensive, best practice model for implementing, managing, and evaluating integrated governance, risk management, compliance, and ethics programs. It documents legal requirements, standards, and principles from a variety of sources, and provides practices that help an organization address these requirements. The OCEG Framework contains two key layers: the Foundation Layer and the Domain Layer. The Foundation Layer provides guidance that helps an organization understand the underlying capability required for effective governance, risk, and compliance management; and addresses areas such as risk assessment, control design and implementation, training, hotline, investigations, etc. The Domain Layer provides detailed and substantive guidance that “fits into” the Foundation Layer. In the Domain Layer, we address topics such as employment, anti-money laundering, antifraud, intellectual property, etc. Basically, in the Foundation Layer, we help an organization understand what good training looks like in the abstract; and in the Domain Layer we help an organization understand the specific training that it should implement to address its antiharassment requirements. In this way, the OCEG Framework helps management with both the underlying processes and substantive issues. What are the business benefits of using the OCEG Framework? SM While organizations may independently develop effective compliance systems, or use other approaches, incorporating the OCEG Framework and leveraging the OCEG community of practice provides an organization with unique benefits. The Framework provides step-by-step guidance and related online What is OCEG’s mission within corporate America? SM Our mission within corporate America is the same as our mission internationally – to help organizations drive performance by enhancing corporate culture and integrating governance, risk management, and compliance processes. We do this by developing guidelines and standards, and fostering a “community of practice” that connects online, at conferences and events, and through publications. We also are a clearing house for high quality measurement and benchmarking criteria by providing a number of free practice aids and free benchmarking tools to help organizations evaluate their progress and success. How does OCEG define enterprise risk? SM Enterprise risk includes all potential obstacles in achieving an organization’s objectives, and typically encompasses 22 BTQ Business Trends Quarterly Q3 2006 | www.btquarterly.com http://btquarterly.com
For optimal viewing of this digital publication, please enable JavaScript and then refresh the page. If you would like to try to load the digital publication without using Flash Player detection, please click here.