GRC Overview
GRC Overview
J U N E 2 0 1 8
What’s GRC?
GRC is a discipline that consists of three pillars (Governance, Risk and Compliance) which allows an
organization to identify risks, meet compliance initiatives, and report on findings that could negatively impact
their organization
► The ability to assess risk around company assets, people, vendors and other business entities
► The ability to identify, monitor and report on risk and compliance across an organization
► Defined relationships between people, critical business processes, assets, vulnerabilities and other key entities for decision
support
► A process, risk and control (PRC) framework that maps to a business structure to support risk and compliance activities
GRC
► Reduces costs across the ► Provides due diligence and reporting
organization support for Senior Management
► Provides data mapping to identify ► Manages risks from identification, to
critical relationships between assessment and treatment
corporate objectives, risks and
controls ► Reports, monitors and dashboards of risk
across the environment
Compliance
► Federated systems of interoperable modules that provide management reporting and analytics
across an organization’s governance, risk, and compliance work streams
Other functional coverage consists of Vendor Risk Management, Business Continuity and
Disaster Recovery Management, Information Security, Privacy, etc.
GRC tools and vendors
►GartnerMagic Quadrant for Operational
►Forrester
Wave Governance, Risk, and
Risk Management Solutions (December
Compliance Platforms (Q1 2016)
2015)
Summary of Major GRC Vendors
RSA Archer (EMC) ► Easy to Configure ► Product interface can be ► RSA Archer is often successful in multi-program
► Comprehensive solution set confusing or lacking eGRC/ IT Risk Management contexts
► Lots of integration already ► Data feed size limitations ► Global presence, established support network and
done ► Reporting is limited large customer base
► Good support and community ► Consistently ranked at the top of the GRC industry
► Library of policies, control for customer service, implementation and quality of
standards, procedures, and work
assessments mapped to ► High ratings for core system (GRC/PRC library
regulatory and business management, user experience, security,
standards configurability, data analytics and issue
management)
IBM OpenPages ► Strong financial reporting and ► Full deployment can be ► OpenPages is often successful in Financial Risk
risk management modules expensive Management and Enterprise Risk Management
► Great integration with IBM ► User Interface can be ► Most mature GRC platform in the market, with the
Cognos for reporting confusing largest distribution amongst industries
► Good with large datasets and ► Requires more technical ► Industry leading business analytics through
data feeds skillsets for support (DBA) integration with IBM’s library of data analytics
► Pre-configured solutions for products
some business processes, ► High marks for configurability, security, issue
medium and small management, customer support and financial
businesses/business units services industry knowledge
MetricStream ► Comprehensive solution set ► High configuration and support ► MetricStream is often successful handling Audit
► Strong product workflow costs and Incident Management
solutions ► Limited solution sets; mainly ► Truly federated and integrated platform, built-in
► Built-in reporting and focused on audit, risk and programming, workflow, security, monitoring and
dashboard features compliance management tools
► Flexible interfacing can connect MetricStream to
virtually data source
► High marks for user interfaces, dashboards and
GRC management tools
Summary of Major GRC Vendors (cont.)
Nasdaq (Bwise) ► Strong financial support for ► Takes time to properly set up ► Bwise is often successful in eGRC Risk
eGRC use cases (Risk ► Security model is not robust Management programs
Management, Internal Control, ► Simple changes may require ► Industry leading reporting, security, integration and
Internal Audit, Compliance & professional expertise (Prof. GRC/PRC library management
Policy Management, IT GRC Services) ► One of the higher performing GRC platforms
and Sustainability ► Requires highly technical ► Strong industry focus in banking, energy,
Performance Management) skillsets for support (DBA) pharmaceuticals, insurance and manufacturing
► Strong integration with ► Not a strong IT GRC player ► High marks for availability of online and on premise
Business Objects for reporting training
SAP GRC ► Allows customization of ► Some SAP GRC modules ► SAP GRC is successful where SAP is the
workflows to meet business require HANA (i.e. Fraud primary enterprise software solution
requirements Management)
► Connects to SAP ECC for data ► Requires SAP technical skill
feeds to allow continuous set for Support (i.e. SAP
control monitoring and Security and SAP GRC
automation Administrators)
► Many SAP GRC modules
integrated
► Ability to integrate with HANA
(i.e. Fraud Management)
GRC Transformation
Board, CEO, CFO, Internal Audit, CFO/VP HR, Supply CIO, CISO, CTO, VP-
CRO
VP` Quality, Compliance Chain, Finance, Sales IT
► Helps executive ► Helps drive towards ► Automates/ ► Enables automation ► Enables automation
management drive transparency and standardizes process and timely monitoring and timely monitoring
down and better visibility for controls of controls owned of controls owned
operationalize the around key assessment and and executed by the and executed by IT
tone at the top performance and risk testing business, which can ► Reduced
through centralized indicators to better ► Centralized lead to business administrative costs
policy management manage the repository of controls process efficiencies resulting from
organization’s risk enables easier ► Facilitates standardization of
posture, and take auditability and rationalization of risk technology
advantage of reporting of and control points platform(s) and
opportunities to avert compliance across spectrum of related risk and
or mitigate risk ► Provides better regulatory controls (across
events visibility to pervasive requirements regulatory
compliance issues ► Helps optimize the requirements)
and enables a mix of controls ► Enables better
consistent approach (manual vs. insight to the
towards managing automated) within the business through a
compliance business process common information
► Enables integrated ► Helps standardize and reporting
management and and embed structure
auditing of multiple automated control
regulatory procedures within the
requirements core business
process
Why Consider a GRC Transformation?
► Do we know our key risks? ► Are we focused on the risks ► Are the risks we take aligned
that matter? to our business strategies and
► Do we have effective risk
objectives?
reporting for executive ► Do we have duplicative or
management and the Board? overlapping risk functions? ► Are we getting the right return
on our risk investment?
► Are we accepting the right ► Are we leveraging automated
level of risk? controls versus manual ► Are we getting process
controls? improvement ideas?
► Do we know if our risks are
being properly managed? ► Do we have the right mix of ► Are we taking the right risks to
skills at the right cost? achieve competitive
► Do we have a comprehensive
advantage?
risk framework in place? ► Have we optimized the use of
technology to manage risk? ► Is risk management slowing
► Does internal audit
us down or helping us go
understand the risks that our ► Can we use alternative
faster?
company faces? sourcing strategies to reduce
costs?
Appendix A - Integration of risk management in a GRC tool
Configuration,
Configure, UAT, Deployment UAT, Business & Functional
& Post Production Support Deployment Requirements
• Configure Solution & Post • Develop Detailed Business &
• User Acceptance Testing Production Business Functional Requirements
• Enhancements and Fixes Support & • Create Use Cases for Supplier
• Production Deployment Functional Selection
• Post Production Support Requirements • Develop Technical
Specifications/Design
Technical
Requirements
Technical Requirements GRC supplier Selection
GRC supplier
• Develop Detailed Technical Selection • Develop Request for Proposal
Requirements (RFP)
• Develop Technical Design and • Perform Feasibility Study
System Implementation • Proof of Concept (PoC)
Architecture Demos