Special Report: GRC Enters Adolescence
June 14, 2010

The discipline known as governance, risk, and compliance (GRC) management — which entered infancy only a few short years ago — has smacked headlong into adolescence, the results of which, according to Business Finance’s 2010 GRC Maturity Study (see “Methodology” sidebar), include a lingering identity crisis as well as some awkward issues interspersed with flashes of highly mature (and effective) behavior.
“You have a lot of organizations that have been somewhat static for about a year in terms of how they were approaching however you want to define GRC,” responds Approva Vice President Michael Evans when asked to provide a snapshot of GRC capabilities in North America. “Now these companies are basically reassessing to make sure that (a) they understand the world they live in now, and (b) their limited resources are properly invested to address these risks. At some level, it seems like the way people approach GRC has been flipped on its head.”
During its infancy 3 or so years ago, “GRC” consisted of documenting the heck out of every internal control that the compliance team — often helmed by internal audit — could unearth. In retrospect, that bottoms-up effort now appears to have been plagued by duplicate work, unnecessary worry, and a host of other headaches.
Today, thanks to welcome doses of Sarbanes-Oxley compliance guidance from the SEC and Public Company Accounting Oversight Board (PCAOB), the majority of public and private companies are engaging in what Evans describes as a “fundamental transformation” to a more (drum roll, please) top-down, risk-based approach.
The survey data confirms that this transition is under way. Nearly three-quarters of respondents describe their GRC strategies as principles-based (more of a top-down and, often, risk-based approach) as opposed to rules-based (which requires a documentation-heavy approach). Nearly 65 percent of respondents report that their companies have some sort of enterprise risk management (ERM) program in place. Moreover, a surprisingly high number of respondents (60 percent) say that their companies have embraced some form of a relatively sophisticated GRC practice, continuous auditing and continuous monitoring.
To be fair, the survey indicates that there are some pimples and other signs of developmental awkwardness (operational risk management, treasury and cash management risk management, and third-party contract management appear in need of improvement) within current GRC programs as well as an identity crisis, which GRC experts echo.
The survey indicates the existence of relatively advanced ERM programs, yet among the disciplines that comprise GRC, respondents say that risk management remains a larger, more important challenge than either governance or compliance.
“There is still a tremendous amount of confusion about what GRC is,” asserts Norman Marks, vice president, GRC, for SAP’s BusinessObjects division.
Findings from Business Finance’s 2010 GRC Maturity Study also suggest that the majority of GRC practitioners know where they want to go. If these companies can address some adolescent angst and insecurity, their entire GRC programs should soon develop in ways that individual components of their programs already have matured.

See a larger version of the GRC Maturity Index.























I remember that we had to
I remember that we had to wear lanyards with our id cards when we were in the company’s premises as part of some obscure audit that was coming up, and we had never done it before, so it caused quite a bit of confusion and unhappiness amongst us.
Coca Cola Gifts Coca Cola
Coca Cola Gifts
Coca Cola Gifts
Wholesale Belt Wholesale Mouse 0.682610506
Wholesale Speakers
Spring Keychain
Wholesale Pen Wholesale Flag 0.492005134
Wholesale Coaster
Wholesale Camera
Wholesale Magnifier Wholesale Mirror 0.210656341
Wholesale Tie
Fruit Picker
Promotional Gifts Muslim Products 0.079137096
Hair Products
Wholesale Glove
Automotive Products Wholesale Wallet 0.464943648
Inflatable Products
Wholesale Scarf
Wholesale Keychain Wholesale iPod iPhone 0.485624998
Giveaway Material
Portfolio
Poncho Raincoat Ice Bottle 0.659834878
Mouse Pad
China Wholesaler
Lunch Box Water Bottle 0.483878894
Wholesale Candle
UV Pen
Wholesale Tableware Banner Stand 0.843460609
Promotional Gifts
Shaker Bottle
Silicone Bakeware Wholesale Keychain 0.277716646
Eye Mask
Shaped Clock
Silicone Products Wholesale Helmet 0.518167094
Wine Set
Pen Holder
Industrial Supplies Wholesale Scarf 0.948931277
Lunch Box
Wholesale Clothes Rack
Wholesale Mouse Wedding Favors 0.391247059
Industrial Supplies
Voice Recorder
Wholesale Cap Business Gift 0.533333506
Water Filter Bottle
Multifunction Tool Card
Digital Spoon Scale Glass Rimmers 0.570599974
Silicone Bakeware
Highlighter Pen
Wholesale Whistle Wholesale Knife 0.940404323
Coca Cola Glass
Waterproof Hard Case
Mini Hockey Stick Gloves Clapper 0.728405686
Wholesale Earphone
Level Tape Measure
Bottle Holder Teeth whitening Pen 0.799409911
Decision Maker
Baby Bib
Wholesale Candle Wholesale Calendar 0.622351024
Safety Suppliers
Wholesale Stress Ball
Wholesale Shoe Wholesale Magnifier 0.249163301
Companies are seeking a GRC
Companies are seeking a GRC maturity model to understand where their program stands against accepted best practices and in comparison to their peers.
The survey data confirms
The survey data confirms that this transition is under way. Nearly three-quarters of respondents describe their GRC strategies as principles-based (more of a top-down and, often, risk-based approach) as opposed to rules-based (which requires a documentation-heavy approach). Nearly 65 percent of respondents report that their companies have some sort of enterprise risk management (ERM) program in place.