Governance, Risk & Compliance Advisory Blog
Insights on best practices related to IT Audit & Compliance

Governance, Risk, and Compliance Management: An Operational Approach

May 3, 2010 07:45 by nirav

Globally integrated markets; new levels of accountability that stem from new laws and regulations; and ever increasing expectations of a broader stakeholder group, who demand effective corporate governance, risk management, transparency, accountability, and optimized performance, have elevated the concerns at board room level of ensuring that effective, transparent and reliable governance and compliance tools are in place and are utilized.

The challenge is that each individual term - Governance, Risk, and Compliance have got different interpretations across the enterprise. We have IT Governance, Corporate Governance, Business Risk, Strategic Risk, Financial Risk, Operational Risk, IT Risk, Corporate Compliance, Sarbanes-Oxley (SOX) Compliance, Privacy Compliance, and Employment and Labor compliance. The list is endless. 

Thus there is a need of a unified GRC strategy that works with multiple roles across the organization—legal, risk, audit, compliance, IT, ethics, finance, lines of business; guides people; standardizes processes; and integrates technology to embed GRC at every organizational level. Following suggests best practices to ensure sound GRC practice in an enterprise:

• User Roles and Access Management

Enforce compliant user provisioning across all systems with integrated user identity and access controls management. Centrally define users and their roles; assign, control, change and revoke access to avoid segregation of duties conflicts. Automate segregation of duties across enterprise applications, custom solutions, and database systems with business-driven rules to prevent unauthorized access to sensitive company and customer information.  All users, including privileged users such as administrators, thus have access to only what they need to do their job.

• Data Management

Collaborate and share information, assessments, metrics, risks, investigations and losses across roles Protect information efficiently and prevent fraud by identifying and preventing access and authorization risks in cross-enterprise IT systems. Reduce redundant information silos and overlapping tasks, while utilizing date-effective audit trails that track the "who, what, and when" of changes made to critical business workflows, information, risk-control metrics, work papers, documentation and other evidence.

• Process Control and Management

Provide support to both cross-industry and industry-specific processes. Enable business process control management by leveraging core processes followed across the business and centrally monitoring key controls and data across-enterprise systems. Automate risk-based processes to address risk management, access control, IT controls testing, data monitoring, and reporting.

• Risk-balanced Strategy Management

Assess the value of a new business opportunity with its associated strategic, financial, legal, and compliance risks to optimize resource usage and minimize the market penalties from high-impact events. Establish tolerance thresholds for risks in the context of business operations. Risk based controls across different business process areas ranging from financial; operational to human resources should be introduced.

• Automated Controls Enforcement

Establish an enterprise understanding of risk with a standardized and automated process to identify, track, assess, and treat risks. Highlight key risk and performance indicators with the help of executive-level dashboards and dynamic drill-down reporting.

Minimize fraud risk with continuous monitoring and automated enforcement of best-practice configuration policies. Enforce comprehensive and automated controls for applications and technologies (all middleware, and database). Determine root causes and accountability for risk by tracking personnel ownership. Route alerts and notifications to concerned personnel/ IT managers for appropriate action.

• Enterprise Performance Management

Set organizational goals and objectives, all this while allowing separate lines of business within the organization to address the distinct risk and compliance requirements within their sphere. Maintain a fine balance between the autonomous and related functions which business units undertake.


Be the first to rate this post

  • Currently 0/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5

Related posts

Comments

May 16. 2010 20:28

Gravatar

I just hope to have understood this the way it was meant

finance

June 4. 2010 21:36

Gravatar

These different areas of management are vital to a logical and practical business plan. Companies must consider each of these variables before launching operations.

forex

October 11. 2010 00:37

Gravatar

Thank you for the post on delivering the IT Governance!!

Ipods maplin lacoste clarins for sale uk

November 4. 2010 09:13

Gravatar

Its a pity you dont have a donate button, i would donate some =)

Porsche Cayman S Sport HD HD Wallpaper

November 4. 2010 12:42

Gravatar

Great site design!!!! Whattemplate did you use?

Magic forum

November 4. 2010 14:39

Gravatar

Thanks for posting this. i really had good time reading this.

Benefits of choosing jewellery as a gift gift jewellery

November 4. 2010 14:53

Gravatar

Thanks for posting this. i really had good time reading this.

Facebook Statuses

November 4. 2010 19:06

Gravatar

I loved this article

Cross cutting shredder

November 4. 2010 22:59

Gravatar

Great site design!!!! Whattheme did you use?

CUTE Babies HD HD Wallpaper

November 5. 2010 09:05

Gravatar

Its a pity you dont have a donate button, i would donate some =)

Compact refrigerator

November 5. 2010 13:06

Gravatar

Where is your rss? I cant find it

Mandy Moore (15) HD Wallpaper

November 8. 2010 04:01

Gravatar

This site is great. i visit here evaryday.

Near Lighthouse HD Wallpaper

November 8. 2010 07:08

Gravatar

Where is your rss? I cant find it

What is the best luxury hotelresort you have stayed at and why

November 8. 2010 07:59

Gravatar

Hey check out my blog too. I hope i have some interesting stuff too

Emo

November 8. 2010 14:16

Gravatar

Where is your rss? I cant find it

Facebook statuses

November 9. 2010 19:00

Gravatar

Great site design!!!! Whattemplate did you use?

Make up for ever hd microfinish powder 0 35 oz

November 9. 2010 19:56

Gravatar

Hey check out my blog too. I hope i have some interesting stuff too

The sandman vol 1 preludes and nocturnes

November 9. 2010 19:59

Gravatar

Its a pity you dont have a donate button, i would donate some =)

Harold camping says millions will die on may 21 2011

January 19. 2011 09:13

Gravatar

Thanks,have a good time in diablo 2!

diablo 2 cd key

February 14. 2011 17:40

Gravatar

What is the aim of your organisation?

online casino review

March 12. 2011 20:24

Gravatar

aim of your organisation?

thomas sabo

March 21. 2011 01:48

Gravatar

Sage is friendly piece of software. I run a small consultancy and bought this because a lot of shop assistants said it was the best. Must say I don't regret.

sage

April 19. 2011 06:41

Gravatar

Thank you for this article, covers all the tiny bits associated, appreciate it.
Chris Harris

Risk management consultants

May 27. 2011 01:57

Gravatar

I have been reading your posts regularly. I need to say that you are doing a fantastic job. Please keep up the great work.

SEO Pakistan

May 27. 2011 21:32

Gravatar

Wow, what a great site you have there. It's always good to see a site like this.

t-shirt drucken

June 16. 2011 05:04

Gravatar

Thank you for the post on delivering the IT Governance!!

Pandora Charms

June 17. 2011 20:59

Gravatar

These different areas of management are vital to a logical and practical business plan. Companies must consider each of these variables before launching operations.

Pandora Beads

June 30. 2011 16:45

Gravatar


Its been nice to go through your post.
It has given me much knowledge & so many valuable information.

Pandora UK

June 30. 2011 16:46

Gravatar

I like it very much,thank you

Pandora Bracelets

June 30. 2011 16:47

Gravatar


very cool!!!

Pandora Beads

June 30. 2011 16:47

Gravatar

It is very nice!!!

Monster Beats

June 30. 2011 16:48

Gravatar

It is great article. It’s possible to detect the term paper writing services that would like to do the essay writing and custom writing

Beats Headphones

July 1. 2011 08:57

Gravatar

Hi, Thanks for your great post, there are much nice information that I am sure a huge number of guys and gals don’t know.

houses for sale victoria

July 4. 2011 00:02

Gravatar

It's really a informative and attractive blog.The use of immense knowledge in this post has diversify thinking.

hesi exam 

July 4. 2011 01:41

Gravatar

Such a thoughtful blog provides various information about the integration of government.This post helps me to learn the operational tactics.

Apartments for rent in London

July 4. 2011 01:42

Gravatar

Such a thoughtful blog provides various information about the integration of government.This post helps me to learn the operational tactics.

online math

August 7. 2011 07:57

Gravatar

It’s really an admirable post containing interesting and knowledgeable information. This helps me to enhance my concept. Always prepped provides you a online platform for amplifying your math skills.For further information visit on http://www.alwaysprepped.com/practice.html

math practice problems

August 27. 2011 04:53

Gravatar

Thank you for the share, kind of like what's being shared here, I am a clearly very much impressed..

Risk management consultants

August 30. 2011 08:50

Gravatar

Highlight key risk and performance indicators with the help of executive-level dashboards and dynamic drill-down reporting.

apb cash

August 31. 2011 19:48

Gravatar

Really cool math games are available at Math Chimp for free. Great for students grades 1 - 5. Games are organized by grade-level and standard. http://www.mathchimp.com

cool math games

September 18. 2011 23:05

Gravatar

Thanks for sharing the valuable information about the enterprise performance management,I hope your information would be profitable in the future.So keep it up these interesting topics.

UAE universities

September 19. 2011 18:59

Gravatar

Nice blog!

University Dubai

September 19. 2011 19:01

Gravatar

Nice blog Thanks for sharing it and i like to give the comment on your blog keep it up these interesting blogs keep it up.

University Dubai

September 27. 2011 06:38

Gravatar

give the comment on your blog keep it up these interesting blogs keep it up.

superdry uk

October 8. 2011 02:38

Gravatar

This is a interesting topic, thank you for taking the time to make such a wonderful site. Another good site that I have found recently is .excellent one to check out.
http://www.ladiesfair.com/pearl-earrings.html provides Pearl earrings which are made up of pearl heads. There are different types of pearl which can be used in different earrings. Their design ranges and patterns range vary from small loops to large plates.

Pearl earrings

November 12. 2011 21:08

Gravatar

thanks to post this nice article.It's a highly helpful document. It is quite educational therefore you have definitely done your groundwork well before penning this post.

Cottage in Yorkshire

November 15. 2011 06:07

Gravatar

Zune and iPod: Most people compare the Zune to the Touch, but after seeing how slim and surprisingly small and light it is, I consider it to be a rather unique hybrid that combines qualities of both the Touch and the Nano. It's very colorful and lovely OLED screen is slightly smaller than the touch screen, but the player itself feels quite a bit smaller and lighter. It weighs about 2/3 as much, and is noticeably smaller in width and height, while being just a hair thicker.

The Shampoo

November 15. 2011 06:15

Gravatar

Hands down, Apple's app store wins by a mile. It's a huge selection of all sorts of apps vs a rather sad selection of a handful for Zune. Microsoft has plans, especially in the realm of games, but I'm not sure I'd want to bet on the future if this aspect is important to you. The iPod is a much better choice in that case.

Free Shampoo

November 16. 2011 04:45

Gravatar

Apple now has Rhapsody as an app, which is a great start, but it is currently hampered by the inability to store locally on your iPod, and has a dismal 64kbps bit rate. If this changes, then it will somewhat negate this advantage for the Zune, but the 10 songs per month will still be a big plus in Zune Pass' favor.

Sulfate Free Shampoo

November 16. 2011 04:49

Gravatar

Zune and iPod: Most people compare the Zune to the Touch, but after seeing how slim and surprisingly small and light it is, I consider it to be a rather unique hybrid that combines qualities of both the Touch and the Nano. It's very colorful and lovely OLED screen is slightly smaller than the touch screen, but the player itself feels quite a bit smaller and lighter. It weighs about 2/3 as much, and is noticeably smaller in width and height, while being just a hair thicker.

Sulfate Free Shampoo

November 19. 2011 11:10

Gravatar

hat is a good factor, I am very glad to read this posting, and I approve with the opinions of this posting. I think this is the best suggestion. I like to do something after reading it.

Maroochydore Accommodation

December 20. 2011 21:23

Gravatar

Nice Information! I personally really appreciate your article. This is a great website. I will make sure that I back again.

noosa accommodation

January 31. 2012 14:02

Gravatar

I happen to enter your blog with the help of Google search. To my sheer luck I got what I was searching for. Thanks

Diamond Earrings

February 4. 2012 00:47

Gravatar

This is my first visit here. I found some really interesting stuff in your blog especially this discussion. Keep up the good work.

Lennox Humidifier at best prices

February 4. 2012 02:09

Gravatar

It’s really a great post..I would like to appreciate your work and I am going to recommend it to my friends.Thanks for sharing. 

Bathroom Suites StormBathrooms

Add comment


(Will show your Gravatar icon)  

  Country flag




Live preview

February 5. 2012 11:17

Gravatar