0% found this document useful (0 votes)
95 views

GRC Overview

The document discusses Governance, Risk, and Compliance (GRC) systems. GRC systems allow organizations to identify risks, meet compliance initiatives, and report on findings that could negatively impact the organization. Key features of GRC systems include identifying and calculating financial, IT and operational risks; assessing risk around company assets and entities; identifying, monitoring, and reporting on risk and compliance; and producing actionable results based on risk thresholds. The document then discusses typical use cases for GRC systems in governance, risk management, compliance, audit, issues management, and incident management. It also provides a summary of major GRC vendors including RSA Archer, IBM OpenPages, and MetricStream.

Uploaded by

smedia.006
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
95 views

GRC Overview

The document discusses Governance, Risk, and Compliance (GRC) systems. GRC systems allow organizations to identify risks, meet compliance initiatives, and report on findings that could negatively impact the organization. Key features of GRC systems include identifying and calculating financial, IT and operational risks; assessing risk around company assets and entities; identifying, monitoring, and reporting on risk and compliance; and producing actionable results based on risk thresholds. The document then discusses typical use cases for GRC systems in governance, risk management, compliance, audit, issues management, and incident management. It also provides a summary of major GRC vendors including RSA Archer, IBM OpenPages, and MetricStream.

Uploaded by

smedia.006
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 12

O p e n Te x t C o r p o r a t i o n

GRC Over view

J U N E 2 0 1 8
What’s GRC?

GRC is a discipline that consists of three pillars (Governance, Risk and Compliance) which allows an
organization to identify risks, meet compliance initiatives, and report on findings that could negatively impact
their organization

► Key features of GRC include:

► The identification and calculation of financial, IT and operational risks

► The ability to assess risk around company assets, people, vendors and other business entities

► The ability to identify, monitor and report on risk and compliance across an organization

► The ability to produce actionable results based on preset risk thresholds

► Defined relationships between people, critical business processes, assets, vulnerabilities and other key entities for decision
support

► A process, risk and control (PRC) framework that maps to a business structure to support risk and compliance activities

► The elimination of overlap amongst various organization siloes


How Companies use GRC?

► Gives senior management visibility


into the state of risk and compliance ► Provides the ability to identify risks within an
throughout the organization organization
► Provides a mechanism for managing Governance Risk ► Allows companies to quantify and score
risk at an enterprise level risks for decision making support

GRC
► Reduces costs across the ► Provides due diligence and reporting
organization support for Senior Management
► Provides data mapping to identify ► Manages risks from identification, to
critical relationships between assessment and treatment
corporate objectives, risks and
controls ► Reports, monitors and dashboards of risk
across the environment
Compliance

► Supports compliance audits


► Provides supporting evidence to
ensure organizational compliance
► Provides management of the overall
auditing process
► Controls testing and monitoring
What are GRC systems?

► Federated systems of interoperable modules that provide management reporting and analytics
across an organization’s governance, risk, and compliance work streams

► They provide automation of the management, measurement, remediation and reporting of


controls and risks against objectives, in accordance with rules, regulations, standards, policies
and business decisions
Typical GRC Use Cases

Governance Financial Risk Risk Management Metrics and Reporting


► Asset and hierarchy ► Calculation of risk ► Internal control ► Ad-hoc reporting
management ► Financial risk impact management ► Audit tracking
► Awareness training analysis ► KRI/KPI management ► Dashboards
► Data management ► Impact analysis ► Risk analysis ► Data integration
► Policy management ► Quantitative/qualitative risk ► Risk assessment ► Historical trending
► Process risk control ► Inherent risk scoring ► Risk identification ► Notifications
framework ► Risk modeling ► Risk profiling ► Statistical analysis
► Procedures and standards ► Scenario analysis ► Threat and vulnerability ► Triggered calculations
► Process accountability ► Total risk calculation management ► Organizational
► Project management ► Vendor risk management transparency
► Standards

Compliance Audit Issues Management Incident Management


► Compliance assessment ► Attestation ► Policy exceptions ► Event capture
► Compliance monitoring ► Audit resource ► Risk acceptance ► Loss capture
► Regulatory content management ► Risk transference ► Incident prioritization
management ► Evidence capture ► Risk treatment ► Incident handling
► Program management ► Mapping incidents to
► SAS 70/SOC 2 critical assets
► Work paper management

Other functional coverage consists of Vendor Risk Management, Business Continuity and
Disaster Recovery Management, Information Security, Privacy, etc.
GRC tools and vendors
►GartnerMagic Quadrant for Operational
►Forrester
Wave Governance, Risk, and
Risk Management Solutions (December
Compliance Platforms (Q1 2016)
2015)
Summary of Major GRC Vendors

Benefits Concerns EY perspective

RSA Archer (EMC) ► Easy to Configure ► Product interface can be ► RSA Archer is often successful in multi-program
► Comprehensive solution set confusing or lacking eGRC/ IT Risk Management contexts
► Lots of integration already ► Data feed size limitations ► Global presence, established support network and
done ► Reporting is limited large customer base
► Good support and community ► Consistently ranked at the top of the GRC industry
► Library of policies, control for customer service, implementation and quality of
standards, procedures, and work
assessments mapped to ► High ratings for core system (GRC/PRC library
regulatory and business management, user experience, security,
standards configurability, data analytics and issue
management)

IBM OpenPages ► Strong financial reporting and ► Full deployment can be ► OpenPages is often successful in Financial Risk
risk management modules expensive Management and Enterprise Risk Management
► Great integration with IBM ► User Interface can be ► Most mature GRC platform in the market, with the
Cognos for reporting confusing largest distribution amongst industries
► Good with large datasets and ► Requires more technical ► Industry leading business analytics through
data feeds skillsets for support (DBA) integration with IBM’s library of data analytics
► Pre-configured solutions for products
some business processes, ► High marks for configurability, security, issue
medium and small management, customer support and financial
businesses/business units services industry knowledge

MetricStream ► Comprehensive solution set ► High configuration and support ► MetricStream is often successful handling Audit
► Strong product workflow costs and Incident Management
solutions ► Limited solution sets; mainly ► Truly federated and integrated platform, built-in
► Built-in reporting and focused on audit, risk and programming, workflow, security, monitoring and
dashboard features compliance management tools
► Flexible interfacing can connect MetricStream to
virtually data source
► High marks for user interfaces, dashboards and
GRC management tools
Summary of Major GRC Vendors (cont.)

Benefits Concerns EY perspective

Nasdaq (Bwise) ► Strong financial support for ► Takes time to properly set up ► Bwise is often successful in eGRC Risk
eGRC use cases (Risk ► Security model is not robust Management programs
Management, Internal Control, ► Simple changes may require ► Industry leading reporting, security, integration and
Internal Audit, Compliance & professional expertise (Prof. GRC/PRC library management
Policy Management, IT GRC Services) ► One of the higher performing GRC platforms
and Sustainability ► Requires highly technical ► Strong industry focus in banking, energy,
Performance Management) skillsets for support (DBA) pharmaceuticals, insurance and manufacturing
► Strong integration with ► Not a strong IT GRC player ► High marks for availability of online and on premise
Business Objects for reporting training

SAP GRC ► Allows customization of ► Some SAP GRC modules ► SAP GRC is successful where SAP is the
workflows to meet business require HANA (i.e. Fraud primary enterprise software solution
requirements Management)
► Connects to SAP ECC for data ► Requires SAP technical skill
feeds to allow continuous set for Support (i.e. SAP
control monitoring and Security and SAP GRC
automation Administrators)
► Many SAP GRC modules
integrated
► Ability to integrate with HANA
(i.e. Fraud Management)
GRC Transformation

Board, CEO, CFO, Internal Audit, CFO/VP HR, Supply CIO, CISO, CTO, VP-
CRO
VP` Quality, Compliance Chain, Finance, Sales IT
► Helps executive ► Helps drive towards ► Automates/ ► Enables automation ► Enables automation
management drive transparency and standardizes process and timely monitoring and timely monitoring
down and better visibility for controls of controls owned of controls owned
operationalize the around key assessment and and executed by the and executed by IT
tone at the top performance and risk testing business, which can ► Reduced
through centralized indicators to better ► Centralized lead to business administrative costs
policy management manage the repository of controls process efficiencies resulting from
organization’s risk enables easier ► Facilitates standardization of
posture, and take auditability and rationalization of risk technology
advantage of reporting of and control points platform(s) and
opportunities to avert compliance across spectrum of related risk and
or mitigate risk ► Provides better regulatory controls (across
events visibility to pervasive requirements regulatory
compliance issues ► Helps optimize the requirements)
and enables a mix of controls ► Enables better
consistent approach (manual vs. insight to the
towards managing automated) within the business through a
compliance business process common information
► Enables integrated ► Helps standardize and reporting
management and and embed structure
auditing of multiple automated control
regulatory procedures within the
requirements core business
process
Why Consider a GRC Transformation?

Risk Value Risk Value Risk Value

Cost Cost Cost

► Do we know our key risks? ► Are we focused on the risks ► Are the risks we take aligned
that matter? to our business strategies and
► Do we have effective risk
objectives?
reporting for executive ► Do we have duplicative or
management and the Board? overlapping risk functions? ► Are we getting the right return
on our risk investment?
► Are we accepting the right ► Are we leveraging automated
level of risk? controls versus manual ► Are we getting process
controls? improvement ideas?
► Do we know if our risks are
being properly managed? ► Do we have the right mix of ► Are we taking the right risks to
skills at the right cost? achieve competitive
► Do we have a comprehensive
advantage?
risk framework in place? ► Have we optimized the use of
technology to manage risk? ► Is risk management slowing
► Does internal audit
us down or helping us go
understand the risks that our ► Can we use alternative
faster?
company faces? sourcing strategies to reduce
costs?
Appendix A - Integration of risk management in a GRC tool

• Board reporting • Audit universe • Audit execution


• Enterprise risk assessments • Audit plan management • Issues management
• Financial risk management (credit/market risk) • Audit scoping • Reporting

• Legal and regulatory requirements • ITRM strategy


• Policy, standards, and procedures Enterprise • IT risk management process management
monitoring and management Risk Audit • Risk profiling
Policies & Management • Control/risk assessments
• Policy management metrics IT Risk
Standards
Management Management
• Supplier risk management
• Scenario analysis governance program
• Internal/external loss events • supplier profiling
• Risk and control self-assessments Operational Supplier • Due diligence/risk assessments
• Key risk indicators Risk Risk • Supplier issues management
• Operational risk quantification Management Management • Supplier performance/quality metrics
Integration of risk
processes through
a GRC solution Business • Business impact analysis/
• Configuration management IT
Continuity assessments
• Incident & problem management Operations
Management • Business continuity/disaster
• IS operations
recovery plan management
• Application security
• Crisis management
Business
Capabilities Information
Services Security • Information security program
• Enterprise capabilities definition (ECM) management
• Business services determination • IS security metrics
Information & Regulatory
• Technology aligned business • Organizational security and awareness
strategy
Asset Risk • Threat & vulnerability management/
Management Management assessments

• Information & asset inventory • Regulatory program & • Governance and


• Information & asset classification & profiling change management stakeholder management
• Information & asset monitoring • Dependency management
Appendix B - EY’s GRC solutions enablement lifecycle

Current State Assessment GRC Strategic Roadmap


• Analyze Business • Define Guiding Principles
Requirements • Develop Governance Model
• Define Target State • Enhance Operating Model
Current State Assessment*
• Stakeholder Buy-in • Define Implementation
• Observations & GRC Strategic Strategy
Recommendations Roadmap • Process Optimization

Configuration,
Configure, UAT, Deployment UAT, Business & Functional
& Post Production Support Deployment Requirements
• Configure Solution & Post • Develop Detailed Business &
• User Acceptance Testing Production Business Functional Requirements
• Enhancements and Fixes Support & • Create Use Cases for Supplier
• Production Deployment Functional Selection
• Post Production Support Requirements • Develop Technical
Specifications/Design
Technical
Requirements
Technical Requirements GRC supplier Selection
GRC supplier
• Develop Detailed Technical Selection • Develop Request for Proposal
Requirements (RFP)
• Develop Technical Design and • Perform Feasibility Study
System Implementation • Proof of Concept (PoC)
Architecture Demos

*Annual re-evaluation of current strategic plan and direction

You might also like