Another buzzword to muddy the water

IT buyers should beware vendors offering governance, risk management and compliance solutions because what they are selling does not exist

Written by Bob Blakely

Governance, risk management and compliance (GRC) is a hot marketing buzz phrase ­ see, for example, Oracle’s announcements at its Openworld conference recently ­ but let’s be clear: GRC is not a market category. Using the term GRC conflates three distinct business functions that are best facilitated using different tool sets; cynical readers will be forgiven for wondering if the resulting confusion is intended to trick them into buying more tools than they really need.

Rapid technology evolution and significant changes in regulation have conspired to throw governance, risk management and compliance into confusion over the past two decades. As a result, all three disciplines have become rather dysfunctional. Tools supporting governance, risk management and compliance are immature, and the recent adoption of GRC as a buzzword has further mired an already muddy picture.

There is no such thing as GRC. Its use increases the probability of confusion about critical issues.

Pretending that GRC exists damages businesses by conflating separate issues and obscuring the real problems in a company. Société Générale’s (SocGén’s) €5bn (£4bn) trading loss stemmed not from a single failure but from at least two failures. The first was a risk management failure ­ a trader was able to turn off the monitoring controls that should have alerted the bank to a magnitude of risk that put it in danger.

The second was a governance failure. When the French Banking Commission detected the rogue activity and warned SocGén that its risk management regime was not working properly, SocGén management apparently failed to take effective
action. Not identifying both failures and who was responsible for addressing each one was disastrous for SocGén ­ as it would be for any firm in a similar position.
Companies are most successful when they look past tool deficiencies and focus on a few core goals when designing governance, risk management and compliance programmes.

Governance initiatives should focus on building organisational transparency and business value. This focus should be turned into action by implementing “roundtrip management” processes that allow executives to see whether their mandates are being implemented, to observe the effects of their mandates on behaviour, and to measure the changes those mandates cause in business value.

Risk management initiatives should shift focus from loss avoidance to creation of value through identification of risks that should be taken rather than avoided, and through identification of competitive advantages created by risk management competencies.

Compliance initiatives should shift the focus from avoidance of liability to reduction of losses that create liability.

Governance is the responsibility of senior executive management and focuses on creating business value and building organisational transparency. Risk management is a responsibility shared by business unit executives, the IT leader and the chief financial officer, and focuses on balancing risk-associated losses and gains. Compliance is a responsibility shared by various executives depending on the regulatory environment. Not surprisingly, these diverse activities require diverse tools, and the activities are most effective when they support one another.
Governance, risk management and compliance are three separate but related activities that solve different problems for different executives. They have different goals, are managed by different executives and require different tools, and it is essential for business to recognise this fact.

reader comments

related articles

European CommissionXX-OUT-OF-USE-Regulation

EU data protection supervisor questions data access plans

Raises fears that personal data contained within public documents may not be adequately protected 30 Jun 2008

 

Lessons learned is a good place to begin

Preparation is key to dealing with emergencies effectively 15 May 2008

How small and medium-sized businesses can improve IT security, governance and compliance

31 Mar 2008

UK IT frameworks find international audience

Two thirds of global organisations have used the government's Infrastructure Library 29 Feb 2008

Firms ignoring risk of security breaches

Logica survey uncovers alarming complacency at UK companies 24 Sep 2008

Risk management jumps up enterprise agenda

SAS research finds economic crisis forcing firms to re-examine strategies 18 Sep 2008

Accountants could shed new light on Kerviel's case

SocGen accountants E&Y and Deloitte could be shedding more light on Kerviel's case 14 Oct 2008

related whitepapers

today's top stories

Lack of enterprise appeal takes shine off Chrome OS

Enterprise buyers unlikely to ditch Windows for Chrome OS in the near term, say experts 09 Jul 2009

How Satyam cleaned up its act

Chief executive CP Gurnani tells Angelica Mari why Tech Mahindra opted to keep the Satyam brand after it bought the scandal-hit services firm, and explains what the deal means for existing and prospective customers 09 Jul 2009

Open source bites back

Recession-hit companies are tired of vendors holding a gun to their heads over software licensing, says CEO of Ingres 09 Jul 2009

"We will ensure Britain remains at the forefront of the digital revolution"

As new trials of superfast broadband get under way, minister Pat McFadden explains the government’s digital vision 09 Jul 2009

Put social networks to work on your career

Increasing numbers of IT professionals using sites such as LinkedIn to grow contacts and find jobs 09 Jul 2009

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you use social networking sites to look for a job?

Would you use social networking sites to look for a job?

Tell us what you think about job hunting through LinkedIn, Facebook, Twitter etc

View poll results

Latest audio and video articles

network cablesVideo

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

green footprintsVideo

How to manage enterprise energy use - and the role IT can play

A panel of experts explore how firms can get to grips with their carbon footprint and make smarter use of energy 01 Jul 2009

Latest in-depth articles

Google ChromeAnalysis

Lack of enterprise appeal takes shine off Chrome OS

Enterprise buyers unlikely to ditch Windows for Chrome OS in the near term, say experts 09 Jul 2009

Satyam CEO CP GurnaniNews

How Satyam cleaned up its act

Chief executive CP Gurnani tells Angelica Mari why Tech Mahindra opted to keep the Satyam brand after it bought the scandal-hit services firm, and explains what the deal means for existing and prospective customers 09 Jul 2009

Advertisement

Primary Navigation