No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Featured

Thriving in the GRC Trenches

by Scott Wisniewski
August 25, 2017
in Featured, Governance
play button in macro detail

3 Multidisciplinary Lessons Learned

GRC leaders shouldn’t expect to find an off-the-shelf GRC solution that truly meets their needs. Instead, they should focus on adopting a balanced, iterative approach, likely one involving a variety of technology schemes that include practical, best-practice steps to encourage multiple assurance stakeholders to recognize their shared goals and frameworks while also supporting the unique needs of each group.

Organizations reviewing marketing materials and selecting governance, risk and compliance (GRC) solutions often come away with the impression that they can use plug-and-play technology to manage their multidisciplinary GRC program. However, although many strong technologies are available for GRC, “out-of-the box GRC” simply does not exist. Even single-discipline solutions need some configuration to meet client-specific requirements.

Add to this the complexity of multiple groups and typical GRC program fragmentation, and it becomes essential to avoid holding out hope that a single turnkey solution will do everything required. Instead, GRC leaders should focus on adopting a balanced, iterative approach, likely one involving a variety of technology schemes that include practical, best-practice steps to encourage multiple assurance stakeholders to recognize their shared goals and frameworks while also supporting the unique needs of each group.

Having participated in or supported hundreds of GRC implementations, we have found that a successful multidisciplinary GRC implementation starts with heeding the following three program realities:

1. It’s Difficult – But Definitely Achievable

By their nature, assurance groups have their own processes in place, typically based on how they have successfully run their groups for years or how they did so at other organizations. Some organizations seek to eliminate this natural complexity by imposing a monolithic, top-down GRC solution on all assurance groups. This approach, however, is fraught with peril. A technology can only support a program; it is not the program itself. A good motto to heed is “Methodology first, technology second.”

Besides, there is no guarantee that the technology a single team or the IT function chooses will align with the methodologies the various assurance groups use, especially if the solution is initially over-configured. When an unwieldy, over-configured technology is imposed on an assurance group, the group will tend to ignore or work around the technology or implement it in a way that undercuts its effectiveness.

It is far better to accept that satisfying the needs of multiple assurance groups will be inherently messy and difficult, but that there are effective ways to approach and work through this quagmire. First, ensure strong executive sponsorship. A multidisciplinary GRC program may be deemed essential, but that does not guarantee a sufficient long-term investment of money and resources. Further, without strong sponsorship from the C-suite, it will be more difficult to obtain buy-in from the various assurance groups, and overall, the program will not be able to maintain the high organizational profile it must have to progress through the inevitable challenges.

Next, obtain buy-in from all key stakeholders, including the lines of business (LOBs). Ultimately, GRC efforts involve the assurance and audit functions working well with the LOBs to manage risk, but the LOBs are extremely busy executing their day-to-day activities. Thus, obtaining their buy-in to the approach – and to the level of effort required to manage both the business and operational risks – is crucial.

When multiple stakeholders feed into, update and build a GRC program, it becomes possible to strike a balance between consistency and rationalization across the company on the one side and support for unique stakeholder requirements on the other. Further, when all the groups know they have been represented, they are more likely to accept some imperfection for the greater good, instead of simply ignoring or working around the solution out of frustration.

Finally, develop a strong program management organization (PMO). An operational-based PMO simply is not enough. There must also be a strong program manager. Too often, multidisciplinary projects are given a project manager responsible for managing tasks instead of a program manager with the appropriate subject-matter expertise to understand and rationalize multi-stakeholder requirements and then construct a harmonized corporate approach.

With only a project manager, paralysis tends to ensue as the project team struggles to support every group requirement – or the team pushes ahead, creating unrationalized clutter. Only a strong program manager with the necessary expertise will be able to achieve the balance between unique stakeholder requirements and corporate-level goals.

2. A Common Language Is Key

Assurance groups tend to have their own taxonomies for their risks and controls, creating a multidisciplinary Tower of Babel. By distinguishing between these taxonomies and the actual content, which is often similar among different groups, organizations can develop a standards-based model that allows underlying risks and controls, regardless of whether they’re named differently among different groups, to be linked back to a set of standards that support enterprise objectives.

This model allows stakeholder groups to build out relevant, specific risks and controls while still being able to report back into these enterprise standards. Notably, creating this model requires an iterative approach, which also allows the supporting technology to work toward rationalization over time instead of making 100 percent rationalization a prerequisite of a technology implementation. Certainly, rationalizing risk/control sets as much as possible prior to implementation can eliminate some rework, but it should never be allowed to create paralysis. The key, once again, is striking the right balance.

Many organizations spend far too much time up front trying to work out a single taxonomy, only to become hung up on abstractions, including word choice to describe common elements, data relationships, data models, etc. While it is critical to think through the taxonomy before embarking on the GRC effort to avoid a spaghetti implementation, it is equally critical to move quickly beyond the abstractions and let teams roll up their sleeves and get to the actual data. Too often, organizations attempt to perfect a taxonomy before building out their content set. However, the latter can inform the former, as analyzing patterns in the content set leads to reciprocal insights with respect to the taxonomy.

The initial strategy should be to develop a preliminary taxonomy, analyze actual data and then adjust the taxonomy. Only then should the system be configured. Even with this, the taxonomy should be allowed to evolve over time, establishing the most appropriate fit for the current requirements of the organization. Some rework is fine if it means the organization can make solid progress toward a unified, multidisciplinary approach. Definitely start with a plan and with a good foundational taxonomy that has broad-level buy-in. However, don’t let perfection of this taxonomy paralyze efforts to develop the requisite content needed to initialize the GRC program and implementation.

3. Scope Management Is Essential

To get on the road to a successful multidisciplinary GRC system, organizations must establish the right balance between ensuring critical path elements are in place on the one hand, and over-engineering the solution on the other. For example, while it is essential to design the GRC system with an eye toward the desired output, over-specifying reporting requirements up front can be a waste of time, as some of the reports will likely go unused, while new requirements will certainly arise. The goal is to be able to accomplish the most important tasks – such as being able to issue the most critical reports – right away, then improve the implementation over time.

Similarly, watch out for automating business rules where the exception becomes the rule. Once again, it’s about the data. The less data the organization has with which to initialize the system, the less confident it should feel about imposing validation rules, system calculations or business rules that may become invalid once patterns in the actual data are analyzed. However, if the organization has substantive data or, better yet, experience from a legacy system that has created growing challenges, then automation can definitely drive efficiency.

Start by defining what constitutes the minimal viable product (MVP). This is essential because it will dictate the critical-path elements that must be deployed immediately. Many organizations struggle to implement enterprise GRC not because the systems can’t handle it, but because there is no defined roadmap for onboarding new disciplines. And because there is no defined roadmap, schedules are not aligned with IT configuration windows so that one group’s configurations do not adversely impact another’s, once again leading to project paralysis.

Starting with an MVP approach not only prevents paralysis, but also leads to a better end product. By budgeting properly for the required follow-on investments in the GRC effort, the organization will be able to respond to feedback along the way to develop approaches that make the GRC program more efficient while also producing more useful information.

Balance Is the Key

In each lesson learned, the key is to strike a balance between the needs of each assurance group and the organization as a whole. By ensuring representation from all groups while working iteratively toward a common language, a PMO led by a strong program manager can navigate complexity, keep the top-line goals of the organization always in sight, accommodate individual groups as necessary and maintain the goodwill of all the stakeholders. This way, over time, a successful, rationalized multidisciplinary GRC program can evolve.


Tags: Technology
Previous Post

Setting the Tone: No Back Seat for the CEO

Next Post

5 Questions Compliance Should Be Asking About GDPR

Scott Wisniewski

Scott Wisniewski

Scott Wisniewski is a managing director in the Risk Technology Solutions practice at Protiviti, a global consulting firm. He is responsible for implementing technology solutions that help companies define, communicate, and monitor governance, risk and compliance activities across the enterprise. He is focused on helping clients adopt best-of-breed technology approaches that appropriately utilize off-the-shelf software while leveraging elements of their existing IT infrastructure to accelerate business process enablement. He also leads development of Protiviti’s proprietary technology, with a core focus on helping clients implement multidisciplinary GRC programs.

Related Posts

imessage on phone

The Hidden Compliance Risks Lurking in Your iMessages

by Harriet Christie
March 3, 2025

How end-to-end encryption and lack of native archiving tools complicate regulatory compliance

remote worker not at desk

The Unseen Risks of Remote Work: Stopping Employee Fraud Before It Starts

by Prakash Santhana
February 3, 2025

From unauthorized data access to BYOD risks, hybrid work demands smarter strategies to combat employee fraud before it escalates

GAN Integrity Buyers Guide to TPRM Software

Buyer’s Guide to TPRM Software

by Corporate Compliance Insights
January 14, 2025

Simplify your third-party risk management software selection Buyer's Guide Guide to Third-Party Risk Management Software What’s in this guide from...

GAN Integrity Buyers Guide to Corporate Compliance Software

Ultimate Buyers’ Guide to Corporate Compliance Software

by Corporate Compliance Insights
November 19, 2024

Take the complexity out of compliance Buyers’ Guide Ultimate Guide to Corporate Compliance Software What’s in this guide from GAN...

Next Post
man working on virtual screen reading personal data protection

5 Questions Compliance Should Be Asking About GDPR

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights