SlideShare una empresa de Scribd logo
1 de 20
Descargar para leer sin conexión
Is your organization
making risk-aware
decisions?
Companies are seeking to embed
Governance, Risk and Compliance
(GRC) into the fabric of the organization—
allowing business managers and leaders
to make more risk-aware decisions.
Why? Because GRC impacts
every aspect of an organization…
Operational
Risk
Compliance
IT
Governance
SOX
EUC
Audit
Vendor Risk
Management
Business
Continuity
ManagementPolicy
Management
Model Risk
Governance
Data Security
GRC has many disciplines that also interact
with each other in a complex web.
Operational
Risk
Compliance
IT
Governance
SOX
EUC
Audit
Vendor Risk
Management
Business
Continuity
ManagementPolicy
Management
Model Risk
Governance
Data Security
A lack of visibility into policy could set
off a series of events across controls
and associated issues and actions.
Operational
Risk
Compliance
IT
Governance
SOX
EUC
Audit
Vendor Risk
Management
Business
Continuity
ManagementPolicy
Management
Model Risk
Governance
Data Security
Business & Risk Owners Executive Oversight Teams Regulators
Process Owners Compliance Teams Audit Teams
Who would benefit most from
an aggregated view of GRC?
An aggregated view informs key individuals
how issues and actions may affect the
organization and departments within it.
Operational
Risk
Compliance
IT
Governance
SOX
EUC
Audit
Vendor Risk
Management
Data Security
Policy
Management
Model Risk
Governance
Business
Continuity
Management
For example, an internal audit team
conducts a test of an organization’s IT
control—changing of passwords…
IT Governance
LDAP
Unauthorized
AccessRisk
Processing Systems
CRM
ERP HR Systems
HR Systems
NA Data Center
Security
Secure Logins
Password Security
Review password
changes and exceptions
Audit
Section
Workpaper
Control Test
Audit
Change passwords
every 60 days.
Control
Operational
Risk Mgmt
Policy and
Compliance
Mgmt
Financial
Controls Mgmt
Business
Area
Retail Banking …
Processing and
Operations …
Payment,
Settlement and
Collections …
Process
Subprocess
Business
Area Reg. Library …
FFIES Info
Security …
Exam Tier II Obj
A.4 …
(Authentication)
Mandate
Sub-
mandate
Business
Area
Finance …
Purchasing and
Payments …
Adjustments and
Payments …
Process
Subprocess
Shared Control
The result of that test has a knock-on
effect to multiple areas of the business.
NA Data Center
Security
Secure Logins
Password Security
Review password
changes and exceptions
Audit
Section
Workpaper
Control Test
Audit
Change passwords
every 60 days.
Control
Unauthorized
Access
Risk
Change
Passwords on
Regular Basis
Requirement Invalid or
Unapproved Entries
Risk
It finds that the policy of regularly
changing passwords has not
been enforced in key systems.
Shared Control
Operational
Risk Mgmt
Policy and
Compliance
Mgmt
Financial
Controls Mgmt
Business
Area
Retail Banking …
Processing and
Operations …
Payment,
Settlement and
Collections …
Process
Business
Area Reg. Library …
FFIES Info
Security …
Exam Tier II Obj
A.4 …
(Authentication)
Mandate
Business
Area
Finance …
Purchasing and
Payments …
Adjustments and
Payments …
Process
Subprocess Sub-
mandate
Subprocess
NA Data Center
Security
Secure Logins
Password Security
Review password
changes and exceptions
Audit
Section
Workpaper
Control Test
Change passwords
every 60 days.
Control
Operational
Risk Mgmt
Policy and
Compliance
Mgmt
Financial
Controls Mgmt
Business
Area
Retail Banking …
Processing and
Operations …
Payment,
Settlement and
Collections …
Unauthorized
Access
Process
Risk
Business
Area Reg. Library …
FFIES Info
Security …
Exam Tier II Obj
A.4 …
(Authentication)
Change
Passwords on
Regular Basis
Mandate
Requirement
Business
Area
Finance …
Purchasing and
Payments …
Adjustments and
Payments …
Invalid or
Unapproved Entries
Process
Risk
A breach of those passwords could impact
the system’s operations and compromise
key processes in various lines of business.
Shared Control
Subprocess Sub-
mandate
Subprocess
NA Data Center
Security
Secure Logins
Password Security
Review password
changes and exceptions
Audit
Section
Workpaper
Control Test
Change passwords
every 60 days.
Control
The impact to the business if risks like
these are incurred could be significant.
So what is keeping organizations from
integrating and optimizing GRC?
Siloed people, data,
knowledge, projects
Defining system
interlock (granularity,
lookup, golden source)
Lack of executive
sponsorship and
alignment
Lack of skills, adoption,
engagement, agile
self-service
Data integration issues
(middleware, API, ETL)
Defining workflow
and reporting across
multiple systems
There are complexities and challenges
to integrating systems and creating a
single view of nonfinancial risk.
No visibility.
No understanding
of how GRC is
interconnected.
Few (if any) IT
resources are
allocated.
Source: GRC Maturity: From Disorganized to Integrated Risk and Performance, Corporate Integrity, 03/12
Departmental Initiatives
??
?
Tactical, siloed
approach to GRC.
No integration or
sharing of
information.
Too much reliance
on fragmented
technology.
Recognizes the
need for greater
GRC integration.
Strategic approach,
mature processes,
good reporting and
trending at the
department level.
Because of these issues, GRC is still at the
departmental level for many organizations...
Fragmented
Integrated
Unaware
No visibility.
No understanding
of how GRC is
interconnected.
Few (if any) IT
resources are
allocated.
Source: GRC Maturity: From Disorganized to Integrated Risk and Performance, Corporate Integrity, 03/12
Departmental Initiatives Enterprise GRC
??
?
Tactical, siloed
approach to GRC.
No integration or
sharing of
information.
Too much reliance
on fragmented
technology.
Recognizes the
need for greater
GRC integration.
Strategic approach,
mature processes,
good reporting and
trending at the
department level.
Strategic approach
to GRC across
departments.
Silos are
eliminated.
Leverages GRC to
realize business
benefits.
GRC is integrated
throughout the
business and is
part of strategic
planning.
Extensive
measurement and
monitoring of GRC
in the context of
business.
While advanced and forward-thinking
organizations have adopted enterprise GRC.
Fragmented
Integrated
Unaware
Aligned
Optimized
How do organizations achieve an
integrated and optimized GRC?
Leverage big data and AI
to create a sophisticated
risk warning system.
Secure a strong
corporate sponsorship
Create a strategy
for integrating all
aspects of GRC
Centralize on one
Enterprise GRC
Software vendor
Prioritize GRC
projects
Establish a centralized
GRC solutions team
Here are our recommendations:
An aggregated view from a standardized
Governance, Risk & Compliance deployment:
There are tangible advantages to
creating this aggregated view of GRC:
Improved alignment of objectives with mission,
vision and values of the organization, resulting in
better decision-making agility and confidence.
Leverage cognitive capabilities to improve quality
of information, user interaction and reduce
manual tasks.
Reduced costs in maintaining duplicated controls,
tests, issues, actions and reporting across multiple
disciplines.
Reduced IT costs by consolidating on a
single GRC solution.
Learn more about IBM solutions for
governance, risk and compliance.
ibm.com/OpenPages

Más contenido relacionado

La actualidad más candente

Maclear’s IT GRC Tools – Key Issues and Trends
Maclear’s  IT GRC Tools – Key Issues and TrendsMaclear’s  IT GRC Tools – Key Issues and Trends
Maclear’s IT GRC Tools – Key Issues and TrendsMaclear LLC
 
Implementing an Effective Third-party & Vendor Risk Management Program
Implementing an Effective Third-party & Vendor Risk Management ProgramImplementing an Effective Third-party & Vendor Risk Management Program
Implementing an Effective Third-party & Vendor Risk Management ProgramKannan Subbiah
 
Designing Enhanced Supervision for the Evolving Wealth Management Ecosystem
Designing Enhanced Supervision for the Evolving Wealth Management EcosystemDesigning Enhanced Supervision for the Evolving Wealth Management Ecosystem
Designing Enhanced Supervision for the Evolving Wealth Management Ecosystemaccenture
 
A Holistic Approach to Insurance Automation
A Holistic Approach to Insurance AutomationA Holistic Approach to Insurance Automation
A Holistic Approach to Insurance AutomationAccenture Insurance
 
Streamlining Identity and Access Management through Unified Identity and Acce...
Streamlining Identity and Access Management through Unified Identity and Acce...Streamlining Identity and Access Management through Unified Identity and Acce...
Streamlining Identity and Access Management through Unified Identity and Acce...happiestmindstech
 
Enterprise Cybersecurity: From Strategy to Operating Model
Enterprise Cybersecurity: From Strategy to Operating ModelEnterprise Cybersecurity: From Strategy to Operating Model
Enterprise Cybersecurity: From Strategy to Operating ModelEryk Budi Pratama
 
Cybersecurity the new metrics
Cybersecurity the new metricsCybersecurity the new metrics
Cybersecurity the new metricsAbhishek Sood
 
Legal Entity Risk and Counter-Party Exposure April 2016
Legal Entity Risk and Counter-Party Exposure  April 2016Legal Entity Risk and Counter-Party Exposure  April 2016
Legal Entity Risk and Counter-Party Exposure April 2016bfreeman1987
 
Identity and Access Intelligence
Identity and Access IntelligenceIdentity and Access Intelligence
Identity and Access IntelligenceTim Bell
 
Optimization as a Golden Layer - Chris Diener, SVP Analytics, Absolutdata
Optimization as a Golden Layer - Chris Diener, SVP Analytics, AbsolutdataOptimization as a Golden Layer - Chris Diener, SVP Analytics, Absolutdata
Optimization as a Golden Layer - Chris Diener, SVP Analytics, AbsolutdataAbsolutdata Analytics
 
Evolution of Records Management in Law Firms
Evolution of Records Management in Law FirmsEvolution of Records Management in Law Firms
Evolution of Records Management in Law FirmsJim Merrifield, IGP, CIP
 
The Soft Costs of MSPs
The Soft Costs of MSPsThe Soft Costs of MSPs
The Soft Costs of MSPsCSI Solutions
 
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firmsaccenture
 
13 Top GRC Tools for an Integrated Governance, Risk and Compliance Strategy
13 Top GRC Tools for an Integrated Governance, Risk and Compliance Strategy13 Top GRC Tools for an Integrated Governance, Risk and Compliance Strategy
13 Top GRC Tools for an Integrated Governance, Risk and Compliance StrategyQuekelsBaro
 
Navigate the Financial Crime Landscape with a Vendor Management Program
Navigate the Financial Crime Landscape with a Vendor Management ProgramNavigate the Financial Crime Landscape with a Vendor Management Program
Navigate the Financial Crime Landscape with a Vendor Management ProgramPerficient, Inc.
 
Establishing an information governance program
Establishing an information governance programEstablishing an information governance program
Establishing an information governance programLouise Spiteri
 

La actualidad más candente (16)

Maclear’s IT GRC Tools – Key Issues and Trends
Maclear’s  IT GRC Tools – Key Issues and TrendsMaclear’s  IT GRC Tools – Key Issues and Trends
Maclear’s IT GRC Tools – Key Issues and Trends
 
Implementing an Effective Third-party & Vendor Risk Management Program
Implementing an Effective Third-party & Vendor Risk Management ProgramImplementing an Effective Third-party & Vendor Risk Management Program
Implementing an Effective Third-party & Vendor Risk Management Program
 
Designing Enhanced Supervision for the Evolving Wealth Management Ecosystem
Designing Enhanced Supervision for the Evolving Wealth Management EcosystemDesigning Enhanced Supervision for the Evolving Wealth Management Ecosystem
Designing Enhanced Supervision for the Evolving Wealth Management Ecosystem
 
A Holistic Approach to Insurance Automation
A Holistic Approach to Insurance AutomationA Holistic Approach to Insurance Automation
A Holistic Approach to Insurance Automation
 
Streamlining Identity and Access Management through Unified Identity and Acce...
Streamlining Identity and Access Management through Unified Identity and Acce...Streamlining Identity and Access Management through Unified Identity and Acce...
Streamlining Identity and Access Management through Unified Identity and Acce...
 
Enterprise Cybersecurity: From Strategy to Operating Model
Enterprise Cybersecurity: From Strategy to Operating ModelEnterprise Cybersecurity: From Strategy to Operating Model
Enterprise Cybersecurity: From Strategy to Operating Model
 
Cybersecurity the new metrics
Cybersecurity the new metricsCybersecurity the new metrics
Cybersecurity the new metrics
 
Legal Entity Risk and Counter-Party Exposure April 2016
Legal Entity Risk and Counter-Party Exposure  April 2016Legal Entity Risk and Counter-Party Exposure  April 2016
Legal Entity Risk and Counter-Party Exposure April 2016
 
Identity and Access Intelligence
Identity and Access IntelligenceIdentity and Access Intelligence
Identity and Access Intelligence
 
Optimization as a Golden Layer - Chris Diener, SVP Analytics, Absolutdata
Optimization as a Golden Layer - Chris Diener, SVP Analytics, AbsolutdataOptimization as a Golden Layer - Chris Diener, SVP Analytics, Absolutdata
Optimization as a Golden Layer - Chris Diener, SVP Analytics, Absolutdata
 
Evolution of Records Management in Law Firms
Evolution of Records Management in Law FirmsEvolution of Records Management in Law Firms
Evolution of Records Management in Law Firms
 
The Soft Costs of MSPs
The Soft Costs of MSPsThe Soft Costs of MSPs
The Soft Costs of MSPs
 
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firms
 
13 Top GRC Tools for an Integrated Governance, Risk and Compliance Strategy
13 Top GRC Tools for an Integrated Governance, Risk and Compliance Strategy13 Top GRC Tools for an Integrated Governance, Risk and Compliance Strategy
13 Top GRC Tools for an Integrated Governance, Risk and Compliance Strategy
 
Navigate the Financial Crime Landscape with a Vendor Management Program
Navigate the Financial Crime Landscape with a Vendor Management ProgramNavigate the Financial Crime Landscape with a Vendor Management Program
Navigate the Financial Crime Landscape with a Vendor Management Program
 
Establishing an information governance program
Establishing an information governance programEstablishing an information governance program
Establishing an information governance program
 

Similar a Advantages of an integrated governance, risk and compliance environment

Governance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management SolutionGovernance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management SolutionRishabh Software
 
Governance Risk and Compliance for SAP
Governance Risk and Compliance for SAPGovernance Risk and Compliance for SAP
Governance Risk and Compliance for SAPPECB
 
GRC Strategies in a Business_ Trends and Challenges.pdf
GRC Strategies in a Business_ Trends and Challenges.pdfGRC Strategies in a Business_ Trends and Challenges.pdf
GRC Strategies in a Business_ Trends and Challenges.pdfbasilmph
 
7 Grc Myths Webinar 20110127 Final (2)
7 Grc Myths Webinar 20110127 Final (2)7 Grc Myths Webinar 20110127 Final (2)
7 Grc Myths Webinar 20110127 Final (2)GBBLUME
 
Information Security Program & PCI Compliance Planning for your Business
Information Security Program & PCI Compliance Planning for your BusinessInformation Security Program & PCI Compliance Planning for your Business
Information Security Program & PCI Compliance Planning for your BusinessLaura Perry
 
20th March Session Five by Ramesh Shanmughanathan
20th March Session Five by Ramesh Shanmughanathan20th March Session Five by Ramesh Shanmughanathan
20th March Session Five by Ramesh ShanmughanathanSharath Kumar
 
Identity Management: Risk Across The Enterprise
Identity Management: Risk Across The EnterpriseIdentity Management: Risk Across The Enterprise
Identity Management: Risk Across The EnterprisePerficient, Inc.
 
CML Group GRCaaS Dashboard
CML Group GRCaaS Dashboard CML Group GRCaaS Dashboard
CML Group GRCaaS Dashboard Jim Robins
 
Information Systems Audit-Related Designations
Information Systems Audit-Related DesignationsInformation Systems Audit-Related Designations
Information Systems Audit-Related DesignationsMichael Lin
 
Intelligence-Driven GRC for Security
Intelligence-Driven GRC for SecurityIntelligence-Driven GRC for Security
Intelligence-Driven GRC for SecurityEMC
 
Info Security & PCI(original)
Info Security & PCI(original)Info Security & PCI(original)
Info Security & PCI(original)NCTechSymposium
 
FulcrumWay GRC Solutions
FulcrumWay GRC SolutionsFulcrumWay GRC Solutions
FulcrumWay GRC SolutionsMantala
 
Insights on grc grc technology au1488
Insights on grc grc technology au1488Insights on grc grc technology au1488
Insights on grc grc technology au1488Ashwin Kumar
 
Effektiv riskhantering - teori vs praktik - IBM Smarter Business 2011
Effektiv riskhantering - teori vs praktik - IBM Smarter Business 2011Effektiv riskhantering - teori vs praktik - IBM Smarter Business 2011
Effektiv riskhantering - teori vs praktik - IBM Smarter Business 2011IBM Sverige
 
Allgress High Level Presentation
Allgress High Level PresentationAllgress High Level Presentation
Allgress High Level Presentatione9128
 
Supply Chain Transformation
Supply Chain TransformationSupply Chain Transformation
Supply Chain TransformationElm Valle
 
Credit Union Cyber Security
Credit Union Cyber SecurityCredit Union Cyber Security
Credit Union Cyber SecurityStacy Willis
 

Similar a Advantages of an integrated governance, risk and compliance environment (20)

Governance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management SolutionGovernance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management Solution
 
Governance Risk and Compliance for SAP
Governance Risk and Compliance for SAPGovernance Risk and Compliance for SAP
Governance Risk and Compliance for SAP
 
GRC Strategies in a Business_ Trends and Challenges.pdf
GRC Strategies in a Business_ Trends and Challenges.pdfGRC Strategies in a Business_ Trends and Challenges.pdf
GRC Strategies in a Business_ Trends and Challenges.pdf
 
7 Grc Myths Webinar 20110127 Final (2)
7 Grc Myths Webinar 20110127 Final (2)7 Grc Myths Webinar 20110127 Final (2)
7 Grc Myths Webinar 20110127 Final (2)
 
Information Security Program & PCI Compliance Planning for your Business
Information Security Program & PCI Compliance Planning for your BusinessInformation Security Program & PCI Compliance Planning for your Business
Information Security Program & PCI Compliance Planning for your Business
 
20th March Session Five by Ramesh Shanmughanathan
20th March Session Five by Ramesh Shanmughanathan20th March Session Five by Ramesh Shanmughanathan
20th March Session Five by Ramesh Shanmughanathan
 
Identity Management: Risk Across The Enterprise
Identity Management: Risk Across The EnterpriseIdentity Management: Risk Across The Enterprise
Identity Management: Risk Across The Enterprise
 
CML Group GRCaaS Dashboard
CML Group GRCaaS Dashboard CML Group GRCaaS Dashboard
CML Group GRCaaS Dashboard
 
Erm talking points
Erm talking pointsErm talking points
Erm talking points
 
Government and SOX Compliance for ERP Systems
Government and SOX Compliance for ERP SystemsGovernment and SOX Compliance for ERP Systems
Government and SOX Compliance for ERP Systems
 
Information Systems Audit-Related Designations
Information Systems Audit-Related DesignationsInformation Systems Audit-Related Designations
Information Systems Audit-Related Designations
 
Intelligence-Driven GRC for Security
Intelligence-Driven GRC for SecurityIntelligence-Driven GRC for Security
Intelligence-Driven GRC for Security
 
Info Security & PCI(original)
Info Security & PCI(original)Info Security & PCI(original)
Info Security & PCI(original)
 
FulcrumWay GRC Solutions
FulcrumWay GRC SolutionsFulcrumWay GRC Solutions
FulcrumWay GRC Solutions
 
Insights on grc grc technology au1488
Insights on grc grc technology au1488Insights on grc grc technology au1488
Insights on grc grc technology au1488
 
Effektiv riskhantering - teori vs praktik - IBM Smarter Business 2011
Effektiv riskhantering - teori vs praktik - IBM Smarter Business 2011Effektiv riskhantering - teori vs praktik - IBM Smarter Business 2011
Effektiv riskhantering - teori vs praktik - IBM Smarter Business 2011
 
Enterprise governance risk_compliance_fcm slides
Enterprise governance risk_compliance_fcm slidesEnterprise governance risk_compliance_fcm slides
Enterprise governance risk_compliance_fcm slides
 
Allgress High Level Presentation
Allgress High Level PresentationAllgress High Level Presentation
Allgress High Level Presentation
 
Supply Chain Transformation
Supply Chain TransformationSupply Chain Transformation
Supply Chain Transformation
 
Credit Union Cyber Security
Credit Union Cyber SecurityCredit Union Cyber Security
Credit Union Cyber Security
 

Más de IBM Analytics

Data Lake: A simple introduction
Data Lake: A simple introductionData Lake: A simple introduction
Data Lake: A simple introductionIBM Analytics
 
10 WealthTech podcasts every wealth advisor should listen to
10 WealthTech podcasts every wealth advisor should listen to10 WealthTech podcasts every wealth advisor should listen to
10 WealthTech podcasts every wealth advisor should listen toIBM Analytics
 
Cognitive banking with expert insights
Cognitive banking with expert insightsCognitive banking with expert insights
Cognitive banking with expert insightsIBM Analytics
 
Sales performance management and C-level goals
Sales performance management and C-level goalsSales performance management and C-level goals
Sales performance management and C-level goalsIBM Analytics
 
The science of client insight: Increase revenue through improved engagement
The science of client insight: Increase revenue through improved engagementThe science of client insight: Increase revenue through improved engagement
The science of client insight: Increase revenue through improved engagementIBM Analytics
 
Expert opinion on managing data breaches
Expert opinion on managing data breachesExpert opinion on managing data breaches
Expert opinion on managing data breachesIBM Analytics
 
Top industry use cases for streaming analytics
Top industry use cases for streaming analyticsTop industry use cases for streaming analytics
Top industry use cases for streaming analyticsIBM Analytics
 
Make data simple in the cognitive era
Make data simple in the cognitive eraMake data simple in the cognitive era
Make data simple in the cognitive eraIBM Analytics
 
IBM CDO Fall Summit 2016 Keynote: Driving innovation in the cognitive era
IBM CDO Fall Summit 2016 Keynote: Driving innovation in the cognitive eraIBM CDO Fall Summit 2016 Keynote: Driving innovation in the cognitive era
IBM CDO Fall Summit 2016 Keynote: Driving innovation in the cognitive eraIBM Analytics
 
IBM Virtual Finance Forum 2016: Top 10 reasons to attend
IBM Virtual Finance Forum 2016: Top 10 reasons to attendIBM Virtual Finance Forum 2016: Top 10 reasons to attend
IBM Virtual Finance Forum 2016: Top 10 reasons to attendIBM Analytics
 
Data science tips for data engineers
Data science tips for data engineersData science tips for data engineers
Data science tips for data engineersIBM Analytics
 
How secure is your enterprise from threats?
How secure is your enterprise from threats? How secure is your enterprise from threats?
How secure is your enterprise from threats? IBM Analytics
 
10 benefits to thinking inside Box
10 benefits to thinking inside Box10 benefits to thinking inside Box
10 benefits to thinking inside BoxIBM Analytics
 
The digital transformation of the French Open
The digital transformation of the French OpenThe digital transformation of the French Open
The digital transformation of the French OpenIBM Analytics
 
Bridging to a hybrid cloud data services architecture
Bridging to a hybrid cloud data services architectureBridging to a hybrid cloud data services architecture
Bridging to a hybrid cloud data services architectureIBM Analytics
 
What does data tell you about the customer journey?
What does data tell you about the customer journey?What does data tell you about the customer journey?
What does data tell you about the customer journey?IBM Analytics
 
What CEOs want from CDOs and how to deliver on it
What CEOs want from CDOs and how to deliver on itWhat CEOs want from CDOs and how to deliver on it
What CEOs want from CDOs and how to deliver on itIBM Analytics
 
Banking in the age of the empowered consumer
Banking in the age of the empowered consumerBanking in the age of the empowered consumer
Banking in the age of the empowered consumerIBM Analytics
 
Wimbledon fans love real-time analytics
Wimbledon fans love real-time analyticsWimbledon fans love real-time analytics
Wimbledon fans love real-time analyticsIBM Analytics
 
How IoT and weather data are transforming business decisions
How IoT and weather data are transforming business decisionsHow IoT and weather data are transforming business decisions
How IoT and weather data are transforming business decisionsIBM Analytics
 

Más de IBM Analytics (20)

Data Lake: A simple introduction
Data Lake: A simple introductionData Lake: A simple introduction
Data Lake: A simple introduction
 
10 WealthTech podcasts every wealth advisor should listen to
10 WealthTech podcasts every wealth advisor should listen to10 WealthTech podcasts every wealth advisor should listen to
10 WealthTech podcasts every wealth advisor should listen to
 
Cognitive banking with expert insights
Cognitive banking with expert insightsCognitive banking with expert insights
Cognitive banking with expert insights
 
Sales performance management and C-level goals
Sales performance management and C-level goalsSales performance management and C-level goals
Sales performance management and C-level goals
 
The science of client insight: Increase revenue through improved engagement
The science of client insight: Increase revenue through improved engagementThe science of client insight: Increase revenue through improved engagement
The science of client insight: Increase revenue through improved engagement
 
Expert opinion on managing data breaches
Expert opinion on managing data breachesExpert opinion on managing data breaches
Expert opinion on managing data breaches
 
Top industry use cases for streaming analytics
Top industry use cases for streaming analyticsTop industry use cases for streaming analytics
Top industry use cases for streaming analytics
 
Make data simple in the cognitive era
Make data simple in the cognitive eraMake data simple in the cognitive era
Make data simple in the cognitive era
 
IBM CDO Fall Summit 2016 Keynote: Driving innovation in the cognitive era
IBM CDO Fall Summit 2016 Keynote: Driving innovation in the cognitive eraIBM CDO Fall Summit 2016 Keynote: Driving innovation in the cognitive era
IBM CDO Fall Summit 2016 Keynote: Driving innovation in the cognitive era
 
IBM Virtual Finance Forum 2016: Top 10 reasons to attend
IBM Virtual Finance Forum 2016: Top 10 reasons to attendIBM Virtual Finance Forum 2016: Top 10 reasons to attend
IBM Virtual Finance Forum 2016: Top 10 reasons to attend
 
Data science tips for data engineers
Data science tips for data engineersData science tips for data engineers
Data science tips for data engineers
 
How secure is your enterprise from threats?
How secure is your enterprise from threats? How secure is your enterprise from threats?
How secure is your enterprise from threats?
 
10 benefits to thinking inside Box
10 benefits to thinking inside Box10 benefits to thinking inside Box
10 benefits to thinking inside Box
 
The digital transformation of the French Open
The digital transformation of the French OpenThe digital transformation of the French Open
The digital transformation of the French Open
 
Bridging to a hybrid cloud data services architecture
Bridging to a hybrid cloud data services architectureBridging to a hybrid cloud data services architecture
Bridging to a hybrid cloud data services architecture
 
What does data tell you about the customer journey?
What does data tell you about the customer journey?What does data tell you about the customer journey?
What does data tell you about the customer journey?
 
What CEOs want from CDOs and how to deliver on it
What CEOs want from CDOs and how to deliver on itWhat CEOs want from CDOs and how to deliver on it
What CEOs want from CDOs and how to deliver on it
 
Banking in the age of the empowered consumer
Banking in the age of the empowered consumerBanking in the age of the empowered consumer
Banking in the age of the empowered consumer
 
Wimbledon fans love real-time analytics
Wimbledon fans love real-time analyticsWimbledon fans love real-time analytics
Wimbledon fans love real-time analytics
 
How IoT and weather data are transforming business decisions
How IoT and weather data are transforming business decisionsHow IoT and weather data are transforming business decisions
How IoT and weather data are transforming business decisions
 

Último

Expressive clarity oral presentation.pptx
Expressive clarity oral presentation.pptxExpressive clarity oral presentation.pptx
Expressive clarity oral presentation.pptxtsionhagos36
 
2024: The FAR, Federal Acquisition Regulations, Part 30
2024: The FAR, Federal Acquisition Regulations, Part 302024: The FAR, Federal Acquisition Regulations, Part 30
2024: The FAR, Federal Acquisition Regulations, Part 30JSchaus & Associates
 
Junnar ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
Junnar ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...Junnar ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...
Junnar ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...tanu pandey
 
Scaling up coastal adaptation in Maldives through the NAP process
Scaling up coastal adaptation in Maldives through the NAP processScaling up coastal adaptation in Maldives through the NAP process
Scaling up coastal adaptation in Maldives through the NAP processNAP Global Network
 
Call Girls Sangamwadi Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Sangamwadi Call Me 7737669865 Budget Friendly No Advance BookingCall Girls Sangamwadi Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Sangamwadi Call Me 7737669865 Budget Friendly No Advance Bookingroncy bisnoi
 
Financing strategies for adaptation. Presentation for CANCC
Financing strategies for adaptation. Presentation for CANCCFinancing strategies for adaptation. Presentation for CANCC
Financing strategies for adaptation. Presentation for CANCCNAP Global Network
 
VIP Model Call Girls Lohegaon ( Pune ) Call ON 8005736733 Starting From 5K to...
VIP Model Call Girls Lohegaon ( Pune ) Call ON 8005736733 Starting From 5K to...VIP Model Call Girls Lohegaon ( Pune ) Call ON 8005736733 Starting From 5K to...
VIP Model Call Girls Lohegaon ( Pune ) Call ON 8005736733 Starting From 5K to...SUHANI PANDEY
 
The Economic and Organised Crime Office (EOCO) has been advised by the Office...
The Economic and Organised Crime Office (EOCO) has been advised by the Office...The Economic and Organised Crime Office (EOCO) has been advised by the Office...
The Economic and Organised Crime Office (EOCO) has been advised by the Office...nservice241
 
Coastal Protection Measures in Hulhumale'
Coastal Protection Measures in Hulhumale'Coastal Protection Measures in Hulhumale'
Coastal Protection Measures in Hulhumale'NAP Global Network
 
Get Premium Budhwar Peth Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...
Get Premium Budhwar Peth Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...Get Premium Budhwar Peth Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...
Get Premium Budhwar Peth Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...MOHANI PANDEY
 
CBO’s Recent Appeals for New Research on Health-Related Topics
CBO’s Recent Appeals for New Research on Health-Related TopicsCBO’s Recent Appeals for New Research on Health-Related Topics
CBO’s Recent Appeals for New Research on Health-Related TopicsCongressional Budget Office
 
Antisemitism Awareness Act: pénaliser la critique de l'Etat d'Israël
Antisemitism Awareness Act: pénaliser la critique de l'Etat d'IsraëlAntisemitism Awareness Act: pénaliser la critique de l'Etat d'Israël
Antisemitism Awareness Act: pénaliser la critique de l'Etat d'IsraëlEdouardHusson
 
An Atoll Futures Research Institute? Presentation for CANCC
An Atoll Futures Research Institute? Presentation for CANCCAn Atoll Futures Research Institute? Presentation for CANCC
An Atoll Futures Research Institute? Presentation for CANCCNAP Global Network
 
The Most Attractive Pune Call Girls Handewadi Road 8250192130 Will You Miss T...
The Most Attractive Pune Call Girls Handewadi Road 8250192130 Will You Miss T...The Most Attractive Pune Call Girls Handewadi Road 8250192130 Will You Miss T...
The Most Attractive Pune Call Girls Handewadi Road 8250192130 Will You Miss T...ranjana rawat
 
PPT Item # 4 - 231 Encino Ave (Significance Only)
PPT Item # 4 - 231 Encino Ave (Significance Only)PPT Item # 4 - 231 Encino Ave (Significance Only)
PPT Item # 4 - 231 Encino Ave (Significance Only)ahcitycouncil
 
The U.S. Budget and Economic Outlook (Presentation)
The U.S. Budget and Economic Outlook (Presentation)The U.S. Budget and Economic Outlook (Presentation)
The U.S. Budget and Economic Outlook (Presentation)Congressional Budget Office
 
Call Girls Nanded City Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Nanded City Call Me 7737669865 Budget Friendly No Advance BookingCall Girls Nanded City Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Nanded City Call Me 7737669865 Budget Friendly No Advance Bookingroncy bisnoi
 
Item # 4 - 231 Encino Ave (Significance Only).pdf
Item # 4 - 231 Encino Ave (Significance Only).pdfItem # 4 - 231 Encino Ave (Significance Only).pdf
Item # 4 - 231 Encino Ave (Significance Only).pdfahcitycouncil
 
↑VVIP celebrity ( Pune ) Serampore Call Girls 8250192130 unlimited shot and a...
↑VVIP celebrity ( Pune ) Serampore Call Girls 8250192130 unlimited shot and a...↑VVIP celebrity ( Pune ) Serampore Call Girls 8250192130 unlimited shot and a...
↑VVIP celebrity ( Pune ) Serampore Call Girls 8250192130 unlimited shot and a...ranjana rawat
 
Booking open Available Pune Call Girls Shukrawar Peth 6297143586 Call Hot In...
Booking open Available Pune Call Girls Shukrawar Peth  6297143586 Call Hot In...Booking open Available Pune Call Girls Shukrawar Peth  6297143586 Call Hot In...
Booking open Available Pune Call Girls Shukrawar Peth 6297143586 Call Hot In...tanu pandey
 

Último (20)

Expressive clarity oral presentation.pptx
Expressive clarity oral presentation.pptxExpressive clarity oral presentation.pptx
Expressive clarity oral presentation.pptx
 
2024: The FAR, Federal Acquisition Regulations, Part 30
2024: The FAR, Federal Acquisition Regulations, Part 302024: The FAR, Federal Acquisition Regulations, Part 30
2024: The FAR, Federal Acquisition Regulations, Part 30
 
Junnar ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
Junnar ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...Junnar ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...
Junnar ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
 
Scaling up coastal adaptation in Maldives through the NAP process
Scaling up coastal adaptation in Maldives through the NAP processScaling up coastal adaptation in Maldives through the NAP process
Scaling up coastal adaptation in Maldives through the NAP process
 
Call Girls Sangamwadi Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Sangamwadi Call Me 7737669865 Budget Friendly No Advance BookingCall Girls Sangamwadi Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Sangamwadi Call Me 7737669865 Budget Friendly No Advance Booking
 
Financing strategies for adaptation. Presentation for CANCC
Financing strategies for adaptation. Presentation for CANCCFinancing strategies for adaptation. Presentation for CANCC
Financing strategies for adaptation. Presentation for CANCC
 
VIP Model Call Girls Lohegaon ( Pune ) Call ON 8005736733 Starting From 5K to...
VIP Model Call Girls Lohegaon ( Pune ) Call ON 8005736733 Starting From 5K to...VIP Model Call Girls Lohegaon ( Pune ) Call ON 8005736733 Starting From 5K to...
VIP Model Call Girls Lohegaon ( Pune ) Call ON 8005736733 Starting From 5K to...
 
The Economic and Organised Crime Office (EOCO) has been advised by the Office...
The Economic and Organised Crime Office (EOCO) has been advised by the Office...The Economic and Organised Crime Office (EOCO) has been advised by the Office...
The Economic and Organised Crime Office (EOCO) has been advised by the Office...
 
Coastal Protection Measures in Hulhumale'
Coastal Protection Measures in Hulhumale'Coastal Protection Measures in Hulhumale'
Coastal Protection Measures in Hulhumale'
 
Get Premium Budhwar Peth Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...
Get Premium Budhwar Peth Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...Get Premium Budhwar Peth Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...
Get Premium Budhwar Peth Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...
 
CBO’s Recent Appeals for New Research on Health-Related Topics
CBO’s Recent Appeals for New Research on Health-Related TopicsCBO’s Recent Appeals for New Research on Health-Related Topics
CBO’s Recent Appeals for New Research on Health-Related Topics
 
Antisemitism Awareness Act: pénaliser la critique de l'Etat d'Israël
Antisemitism Awareness Act: pénaliser la critique de l'Etat d'IsraëlAntisemitism Awareness Act: pénaliser la critique de l'Etat d'Israël
Antisemitism Awareness Act: pénaliser la critique de l'Etat d'Israël
 
An Atoll Futures Research Institute? Presentation for CANCC
An Atoll Futures Research Institute? Presentation for CANCCAn Atoll Futures Research Institute? Presentation for CANCC
An Atoll Futures Research Institute? Presentation for CANCC
 
The Most Attractive Pune Call Girls Handewadi Road 8250192130 Will You Miss T...
The Most Attractive Pune Call Girls Handewadi Road 8250192130 Will You Miss T...The Most Attractive Pune Call Girls Handewadi Road 8250192130 Will You Miss T...
The Most Attractive Pune Call Girls Handewadi Road 8250192130 Will You Miss T...
 
PPT Item # 4 - 231 Encino Ave (Significance Only)
PPT Item # 4 - 231 Encino Ave (Significance Only)PPT Item # 4 - 231 Encino Ave (Significance Only)
PPT Item # 4 - 231 Encino Ave (Significance Only)
 
The U.S. Budget and Economic Outlook (Presentation)
The U.S. Budget and Economic Outlook (Presentation)The U.S. Budget and Economic Outlook (Presentation)
The U.S. Budget and Economic Outlook (Presentation)
 
Call Girls Nanded City Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Nanded City Call Me 7737669865 Budget Friendly No Advance BookingCall Girls Nanded City Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Nanded City Call Me 7737669865 Budget Friendly No Advance Booking
 
Item # 4 - 231 Encino Ave (Significance Only).pdf
Item # 4 - 231 Encino Ave (Significance Only).pdfItem # 4 - 231 Encino Ave (Significance Only).pdf
Item # 4 - 231 Encino Ave (Significance Only).pdf
 
↑VVIP celebrity ( Pune ) Serampore Call Girls 8250192130 unlimited shot and a...
↑VVIP celebrity ( Pune ) Serampore Call Girls 8250192130 unlimited shot and a...↑VVIP celebrity ( Pune ) Serampore Call Girls 8250192130 unlimited shot and a...
↑VVIP celebrity ( Pune ) Serampore Call Girls 8250192130 unlimited shot and a...
 
Booking open Available Pune Call Girls Shukrawar Peth 6297143586 Call Hot In...
Booking open Available Pune Call Girls Shukrawar Peth  6297143586 Call Hot In...Booking open Available Pune Call Girls Shukrawar Peth  6297143586 Call Hot In...
Booking open Available Pune Call Girls Shukrawar Peth 6297143586 Call Hot In...
 

Advantages of an integrated governance, risk and compliance environment

  • 1. Is your organization making risk-aware decisions?
  • 2. Companies are seeking to embed Governance, Risk and Compliance (GRC) into the fabric of the organization— allowing business managers and leaders to make more risk-aware decisions.
  • 3. Why? Because GRC impacts every aspect of an organization… Operational Risk Compliance IT Governance SOX EUC Audit Vendor Risk Management Business Continuity ManagementPolicy Management Model Risk Governance Data Security
  • 4. GRC has many disciplines that also interact with each other in a complex web. Operational Risk Compliance IT Governance SOX EUC Audit Vendor Risk Management Business Continuity ManagementPolicy Management Model Risk Governance Data Security
  • 5. A lack of visibility into policy could set off a series of events across controls and associated issues and actions. Operational Risk Compliance IT Governance SOX EUC Audit Vendor Risk Management Business Continuity ManagementPolicy Management Model Risk Governance Data Security
  • 6. Business & Risk Owners Executive Oversight Teams Regulators Process Owners Compliance Teams Audit Teams Who would benefit most from an aggregated view of GRC?
  • 7. An aggregated view informs key individuals how issues and actions may affect the organization and departments within it. Operational Risk Compliance IT Governance SOX EUC Audit Vendor Risk Management Data Security Policy Management Model Risk Governance Business Continuity Management
  • 8. For example, an internal audit team conducts a test of an organization’s IT control—changing of passwords… IT Governance LDAP Unauthorized AccessRisk Processing Systems CRM ERP HR Systems HR Systems NA Data Center Security Secure Logins Password Security Review password changes and exceptions Audit Section Workpaper Control Test Audit Change passwords every 60 days. Control
  • 9. Operational Risk Mgmt Policy and Compliance Mgmt Financial Controls Mgmt Business Area Retail Banking … Processing and Operations … Payment, Settlement and Collections … Process Subprocess Business Area Reg. Library … FFIES Info Security … Exam Tier II Obj A.4 … (Authentication) Mandate Sub- mandate Business Area Finance … Purchasing and Payments … Adjustments and Payments … Process Subprocess Shared Control The result of that test has a knock-on effect to multiple areas of the business. NA Data Center Security Secure Logins Password Security Review password changes and exceptions Audit Section Workpaper Control Test Audit Change passwords every 60 days. Control
  • 10. Unauthorized Access Risk Change Passwords on Regular Basis Requirement Invalid or Unapproved Entries Risk It finds that the policy of regularly changing passwords has not been enforced in key systems. Shared Control Operational Risk Mgmt Policy and Compliance Mgmt Financial Controls Mgmt Business Area Retail Banking … Processing and Operations … Payment, Settlement and Collections … Process Business Area Reg. Library … FFIES Info Security … Exam Tier II Obj A.4 … (Authentication) Mandate Business Area Finance … Purchasing and Payments … Adjustments and Payments … Process Subprocess Sub- mandate Subprocess NA Data Center Security Secure Logins Password Security Review password changes and exceptions Audit Section Workpaper Control Test Change passwords every 60 days. Control
  • 11. Operational Risk Mgmt Policy and Compliance Mgmt Financial Controls Mgmt Business Area Retail Banking … Processing and Operations … Payment, Settlement and Collections … Unauthorized Access Process Risk Business Area Reg. Library … FFIES Info Security … Exam Tier II Obj A.4 … (Authentication) Change Passwords on Regular Basis Mandate Requirement Business Area Finance … Purchasing and Payments … Adjustments and Payments … Invalid or Unapproved Entries Process Risk A breach of those passwords could impact the system’s operations and compromise key processes in various lines of business. Shared Control Subprocess Sub- mandate Subprocess NA Data Center Security Secure Logins Password Security Review password changes and exceptions Audit Section Workpaper Control Test Change passwords every 60 days. Control
  • 12. The impact to the business if risks like these are incurred could be significant. So what is keeping organizations from integrating and optimizing GRC?
  • 13. Siloed people, data, knowledge, projects Defining system interlock (granularity, lookup, golden source) Lack of executive sponsorship and alignment Lack of skills, adoption, engagement, agile self-service Data integration issues (middleware, API, ETL) Defining workflow and reporting across multiple systems There are complexities and challenges to integrating systems and creating a single view of nonfinancial risk.
  • 14. No visibility. No understanding of how GRC is interconnected. Few (if any) IT resources are allocated. Source: GRC Maturity: From Disorganized to Integrated Risk and Performance, Corporate Integrity, 03/12 Departmental Initiatives ?? ? Tactical, siloed approach to GRC. No integration or sharing of information. Too much reliance on fragmented technology. Recognizes the need for greater GRC integration. Strategic approach, mature processes, good reporting and trending at the department level. Because of these issues, GRC is still at the departmental level for many organizations... Fragmented Integrated Unaware
  • 15. No visibility. No understanding of how GRC is interconnected. Few (if any) IT resources are allocated. Source: GRC Maturity: From Disorganized to Integrated Risk and Performance, Corporate Integrity, 03/12 Departmental Initiatives Enterprise GRC ?? ? Tactical, siloed approach to GRC. No integration or sharing of information. Too much reliance on fragmented technology. Recognizes the need for greater GRC integration. Strategic approach, mature processes, good reporting and trending at the department level. Strategic approach to GRC across departments. Silos are eliminated. Leverages GRC to realize business benefits. GRC is integrated throughout the business and is part of strategic planning. Extensive measurement and monitoring of GRC in the context of business. While advanced and forward-thinking organizations have adopted enterprise GRC. Fragmented Integrated Unaware Aligned Optimized
  • 16. How do organizations achieve an integrated and optimized GRC?
  • 17. Leverage big data and AI to create a sophisticated risk warning system. Secure a strong corporate sponsorship Create a strategy for integrating all aspects of GRC Centralize on one Enterprise GRC Software vendor Prioritize GRC projects Establish a centralized GRC solutions team Here are our recommendations:
  • 18. An aggregated view from a standardized Governance, Risk & Compliance deployment:
  • 19. There are tangible advantages to creating this aggregated view of GRC: Improved alignment of objectives with mission, vision and values of the organization, resulting in better decision-making agility and confidence. Leverage cognitive capabilities to improve quality of information, user interaction and reduce manual tasks. Reduced costs in maintaining duplicated controls, tests, issues, actions and reporting across multiple disciplines. Reduced IT costs by consolidating on a single GRC solution.
  • 20. Learn more about IBM solutions for governance, risk and compliance. ibm.com/OpenPages