What is 'GRC,' and How Can It Bring the Enterprise Together?
Posted in Best Practices, Compliance, Enterprise Data Management, Enterprise Data Warehousing, Governance / Stewardship, Integrated Performance, Management, Monitoring by Joe McKendrick | No Comments![]() |
We all know how mandates such as Sarbanes-Oxley place a burden on many businesses, by requiring that they be able to document the reliability and quality of data. Most major mandates, which have now been in place for several years, have given rise to a whole industry dedicated to reporting. In many companies, the equivalents of small departments have been kept busy 52 weeks a year doing little more than generating reports and reviewing data to meet compliance requirements.
Obviously, things can't go on like this. Rather than spending money to just keep simply meeting requirements, many companies are seeking to better integrate compliance into their day-to-day operations in a more automated, systematic form. In doing so, they seek to go far beyond meeting the letter of the law, to take the opportunity to improve and streamline their own processes - which will pay off in battling the challenges of an increasingly competitive marketplace.
By eliminating the silos that have separated data across the enterprise, as well as the silos that have pigeonholed the compliance efforts intended to gather and report this information, organizations can make impressive strides in moving forward with greater agility. In the process, automation can reduce the burden of paperwork and manual processes that drive up the costs of compliance.
Such "sustainable" compliance management can be built on top of three disciplines that already exist within most businesses today. These include governance, or the oversight of corporate activities and processes; risk management, or the identification, assessment and monitoring of risks and controls; and compliance management. This integrated approach - known as Governance, Risk, and Compliance Management, or GRC, takes its three namesake disciplines and takes a more holistic approach to increasing information visibility and management. [Read more]






