Special Report: GRC Enters Adolescence

June 14, 2010

by Eric Krell

The discipline known as governance, risk, and compliance (GRC) management — which entered infancy only a few short years ago — has smacked headlong into adolescence, the results of which, according to Business Finance’s 2010 GRC Maturity Study (see “Methodology” sidebar), include a lingering identity crisis as well as some awkward issues interspersed with flashes of highly mature (and effective) behavior.

“You have a lot of organizations that have been somewhat static for about a year in terms of how they were approaching however you want to define GRC,” responds Approva Vice President Michael Evans when asked to provide a snapshot of GRC capabilities in North America. “Now these companies are basically reassessing to make sure that (a) they understand the world they live in now, and (b) their limited resources are properly invested to address these risks. At some level, it seems like the way people approach GRC has been flipped on its head.”

During its infancy 3 or so years ago, “GRC” consisted of documenting the heck out of every internal control that the compliance team — often helmed by internal audit — could unearth. In retrospect, that bottoms-up effort now appears to have been plagued by duplicate work, unnecessary worry, and a host of other headaches.

Today, thanks to welcome doses of Sarbanes-Oxley compliance guidance from the SEC and Public Company Accounting Oversight Board (PCAOB), the majority of public and private companies are engaging in what Evans describes as a “fundamental transformation” to a more (drum roll, please) top-down, risk-based approach.

The survey data confirms that this transition is under way. Nearly three-quarters of respondents describe their GRC strategies as principles-based (more of a top-down and, often, risk-based approach) as opposed to rules-based (which requires a documentation-heavy approach). Nearly 65 percent of respondents report that their companies have some sort of enterprise risk management (ERM) program in place. Moreover, a surprisingly high number of respondents (60 percent) say that their companies have embraced some form of a relatively sophisticated GRC practice, continuous auditing and continuous monitoring.

To be fair, the survey indicates that there are some pimples and other signs of developmental awkwardness (operational risk management, treasury and cash management risk management, and third-party contract management appear in need of improvement) within current GRC programs as well as an identity crisis, which GRC experts echo.

The survey indicates the existence of relatively advanced ERM programs, yet among the disciplines that comprise GRC, respondents say that risk management remains a larger, more important challenge than either governance or compliance.
“There is still a tremendous amount of confusion about what GRC is,” asserts Norman Marks, vice president, GRC, for SAP’s BusinessObjects division.

Findings from Business Finance’s 2010 GRC Maturity Study also suggest that the majority of GRC practitioners know where they want to go. If these companies can address some adolescent angst and insecurity, their entire GRC programs should soon develop in ways that individual components of their programs already have matured.

GRC Maturity Index

See a larger version of the GRC Maturity Index.

Average: 10 (2 votes)

I remember that we had to

I remember that we had to wear lanyards with our id cards when we were in the company’s premises as part of some obscure audit that was coming up, and we had never done it before, so it caused quite a bit of confusion and unhappiness amongst us.

Coca Cola Gifts Coca Cola

Coca Cola Gifts

Coca Cola Gifts

Wholesale Belt Wholesale Mouse 0.682610506
Wholesale Speakers

Spring Keychain

Wholesale Pen Wholesale Flag 0.492005134
Wholesale Coaster

Wholesale Camera

Wholesale Magnifier Wholesale Mirror 0.210656341
Wholesale Tie

Fruit Picker

Promotional Gifts Muslim Products 0.079137096
Hair Products

Wholesale Glove

Automotive Products Wholesale Wallet 0.464943648
Inflatable Products

Wholesale Scarf

Wholesale Keychain Wholesale iPod iPhone 0.485624998
Giveaway Material

Portfolio

Poncho Raincoat Ice Bottle 0.659834878
Mouse Pad

China Wholesaler

Lunch Box Water Bottle 0.483878894
Wholesale Candle

UV Pen

Wholesale Tableware Banner Stand 0.843460609
Promotional Gifts

Shaker Bottle

Silicone Bakeware Wholesale Keychain 0.277716646
Eye Mask

Shaped Clock

Silicone Products Wholesale Helmet 0.518167094
Wine Set

Pen Holder

Industrial Supplies Wholesale Scarf 0.948931277
Lunch Box

Wholesale Clothes Rack

Wholesale Mouse Wedding Favors 0.391247059
Industrial Supplies

Voice Recorder

Wholesale Cap Business Gift 0.533333506
Water Filter Bottle

Multifunction Tool Card

Digital Spoon Scale Glass Rimmers 0.570599974
Silicone Bakeware

Highlighter Pen

Wholesale Whistle Wholesale Knife 0.940404323
Coca Cola Glass

Waterproof Hard Case

Mini Hockey Stick Gloves Clapper 0.728405686
Wholesale Earphone

Level Tape Measure

Bottle Holder Teeth whitening Pen 0.799409911
Decision Maker

Baby Bib

Wholesale Candle Wholesale Calendar 0.622351024
Safety Suppliers

Wholesale Stress Ball

Wholesale Shoe Wholesale Magnifier 0.249163301

Companies are seeking a GRC

Companies are seeking a GRC maturity model to understand where their program stands against accepted best practices and in comparison to their peers.

The survey data confirms

The survey data confirms that this transition is under way. Nearly three-quarters of respondents describe their GRC strategies as principles-based (more of a top-down and, often, risk-based approach) as opposed to rules-based (which requires a documentation-heavy approach). Nearly 65 percent of respondents report that their companies have some sort of enterprise risk management (ERM) program in place.