• Skip Navigation |
  • Accessibility 
IT-Director.com Logo
  • Singularity go SaaS with LiveAgility
  • User Experience Monitoring as Governance?
  • Running IT as a business: don't be daft
 

Main navigation - go to a section of this website:

  • ARCHIVE
  • PAPERS
  • EVENTS
  • NEWSWIRE
  • BLOGS

  

Member Login | Become a Member

 
DOMAINS
  • Enterprise
  • SME
  • Business Issues
    • Compliance
    • Regulation
    • Employment
    • Innovation
    • Security & Risk
    • Costs
    • Change
    • Quality
  • Technology
  • Services
  • Channels
FEATURED EVENTS
  • Legal IT Show 2010
    10th February - 11th February
    London, United Kingdom
  • Data Modelling Fundamentals
    15th February - 16th February
    London, United Kingdom
POPULAR PAPERS
  • Log and Event Management by Bloor Research
  • Warehousing for low latency analytics by Bloor Research
TRANSLATE PAGE



USEFUL LINKS
  • Last 7 Days
  • Archives
  • Market Place
  • Top Articles
INTERACT
  • Advertising
  • Site Feedback
  • Newsletters
  • Contact Us
  • Registration
CONTENT FEED

Business Issues -> Compliance
RSS Feed:

RSS Icon

What is RSS?

RANDOM QUOTE
Famous Slights - "That part of his speech was rather like being savaged by a dead sheep." - Dennis Healy, on Geoffrey Howe

ADVERTISEMENT
Analysis

GRC is not enough

Philip Howard By: Philip Howard, Research Director - Data Management, Bloor Research
Published: 29th July 2009
Copyright Bloor Research © 2009
Logo for Bloor Research
Page Tools

Request Reprints
Tell A Friend
Contact Author

More from author
  • February 2010
    Making sense of it all 2
  • February 2010
    Bribery
  • February 2010
    Making sense of it all 1
  • February 2010
    Columns aren't enough anymore
  • February 2010
    Calpont finally comes to market
  • January 2010
    Informatica 9: (r)evolutionary?
  • January 2010
    Cadis EDM
Syndication
  • Delicious Icon Delicious
  • Digg Icon Digg
  • reddit Icon reddit
  • Facebook Icon Facebook
  • StumbleUpon Icon StumbleUpon

The problem with GRC (governance, risk and compliance) is that it's not a three-way issue. At minimum, there are four or five different forms of governance, two types of compliance and seven different types of risk.

Compliance is easy: it's either internal, imposed by corporate governance standards, or it's external, imposed by regulations or standards of various types. You could probably split the latter up into categories but why create unnecessary complications?

As far as governance is concerned, there's corporate governance, IT governance, and process governance. There is also either data governance and content/web governance or you could concatenate these into information governance.

But it is risk that is the real issue. This is partly because people use different terminology: to some people risk is simply about business risk: if I make a business decision what is the potential downside if I call this wrong? In capital markets, for example, what is my exposure in case I have shorted the market and it goes long, or vice versa?

The problem is that this is far too limited a view of what risk is. Take data quality for example, if you have poor data quality then you expose yourself to risk through uncertainty about the truth reflected in the data. For example, one company I was recently talking to was able to reduce its capital requirements by £50m simply by getting more surety about the quality of its data. Similarly, there is spreadsheet risk—that is, the risk (near certainty in many cases) that there may be errors in critical spreadsheets—which also relates to capital markets because many algorithms are built using spreadsheets.

That's three types of risk but we're not finished yet. There's compliance risk. If you don't comply then you may get fined (see HSBC) or you may be forced into extra work (being raised PCI levels) or you won't be able to do something that you would like to (GCSx) or you may even go to gaol (Sarbanes-Oxley).

Next there's IT risk: what's the impact on your business if your systems go down? Or if SLAs are not met? Or if a migration (Heathrow Terminal 5) goes wrong?

Then there is the risk of direct attacks on your business: either external attacks on your IT systems or internal attacks such as fraud, malicious damage or information theft.

Now, GRC vendors do not recognise most of these types of risk. Fraud, which any layman would consider a form of risk, is not typically treated within so-called GRC solutions. And you can see why not: GRC, treated literally and in its entirety, is too big for most (any) vendors to handle, so they've cut it down into silos that they can treat. But silos are always a problem and I think a more holistic approach is needed.

If you think about these different forms of risk, they can mostly be managed within existing GRC frameworks: business risk, data and IT governance and compliance cover five of these seven types of risk. But they don't cover fraud or cyber attacks or similar security issues. I therefore we think that we should really be thinking about GRCS (S for security), at least organisationally, if we want to be complete about this. Of course, security works closely with compliance: meeting the EU data retention directive, for example, is as much a security issue as a compliance one, and the same applies to PCI, GCSx and so on. On the other hand, there are security risks that are not about compliance and compliance (accessibility, for example) risks that are not to do with security.

There's a lot more to consider of course, and I'll return to this in future articles but unless someone can convince me otherwise I'm going to be working on the basis of GRCS.

Reader Comments

Sorry, we are no longer accepting comments on this item. We suggest trying to contact the author directly.

31st July 2009: 'Dan French' said:

Whilst I agree with the theme of the article that GRC in software terms tries to claim too much, the fact is that whilst security (GRCS) is the major focus of most software solutions, it is not the only one. We work with large firms on GRC programmes where Security is a major focus, but where the application of smart technology is also being used to address business risks associated with ensuring that data and process execution reflect what is expected/required in the business. This can relate to directly to the risk of inefficient operations (loss, wastage, improvement opportunity etc) in finance, production or shared services, for example.

Reply to Dan French?

4th August 2009: 'Peter KU' said:

I agree with Philip's statements as to the varying definitions and sub-classifications of risk when companies refer to "GRC". My concern is that GRC is used too loosely across industries as trend setters attempted to align traditionally siloed practices under an "enterprise" theme. Unfortunately, depending on industry, role, division, and time of day, governance, risk, and compliance can mean completely different things to the same company.

One thing however that holds true and constant across any industry, company, or sub-category of GRC is the need and reliance for trusted, timely, and accurate data. GRC applications are designed to perform its calculations, generate reports, and deliver business user-friendly dashboards however, many organizations struggle in gaining access to all their data, in a timely fashion, with zero errors, along with a consistent set of business definitions everyone can understand. Thus successful GRC strategies and practices begin with data integration and data governance. The combination of people, process, policies, and technologies to allow companies to access and deliver the data organizations need to effectively govern, regulate, and mitigate risk.

Reply to Peter KU?

The messages above were all contributed by IT-Director.com readers. Whilst we take care to remove any posts deemed inappropriate, we can take no responsibility for these comments. If you would like a comment removed please contact our editorial team.

  • Site Map
  • | Terms of Use
  • | Privacy

Published by: IT Analysis Communications Ltd.
T: +44 (0)1908 880760 | F: +44 (0)1908 880761