SlideShare una empresa de Scribd logo
1 de 2
Descargar para leer sin conexión
A GLOBAL LIFE SCIENCES COMPANY IMPLEMENTS
ADAPTIVEGRC SOLUTION SUITE FOR VARIOUS GRC
SERVICES
The customer is a global Life Sciences company operating in over 50 international
markets. With $5bn annual turnover it has more than 4000 employees.
CASE STUDY
INDUSTRY
Life Sciences
REGION
North America
SOLUTION
 Compliance Objectives
Framework
 Vendor Management
 Data Privacy Management
 Security Testing Results
Management
 Anti-Corruption Assessments
 Quality Management
 SOX Management
 Risk Management
KEY BENEFITS
 Simplification of processes
 Increased operational efficiency
of GRC activities
 Lower operational impact
 Decreased system operation
costs
 Vastly improved metrics
 Faster system speeds
 Improved collaboration
capabilities
 Better cross-department
information sharing
 Integration with other high value
data sources
COMPANY PROFILE
CHALLENGES
The customer was separating out (divesting) from a Fortune 50 organization with a need
to install and implement a solution across a wide range of GRC activities:
- Compliance Objectives Framework,
- Vendor Management,
- Data Privacy Management,
- Security Testing Results,
- Anti-Corruption,
- Quality Management (Actions, Deviations, Events),
- Risk Management (Technology, Enterprise).
There were many good legacy best practice processes but no licenses for legacy
solutions. Legacy processes were performed across 6 different systems and there were
also many spreadsheet based processes. Legacy data was disparate and hard to use for
executive reporting.
SOLUTION & APPROACH
AdaptiveGRC solution suite was selected and implemented to meet GRC requirements
and needs mentioned above.
First, executive sponsorship was ensured, the intended path was socialized and the right
representative team was put together. Next step was to distill the objectives (activities
and metrics) and identify the organizations priority order for releasing and
operationalizing their GRC activities. Then the required benefits were captured and kept
at the heart of each stage.
Having all of the above in place, a ‘vanilla’ AdaptiveGRC system was provided – with all the
components set-up in COTS (out of the box) configuration, ready to customize and
configure.
The next phase was setting up the central GRC engineering pillars by distilling the primary
GRC engineering correlation points, such as:
a. Governance Factors - the primary regulations, standards and guidelines used by
the organization to drive their GRC activities and executive reporting. In this case
including Information Security (ISO27001), Data Privacy, SOX, PCI DSS, FDA
regulations and more.
b. Process Streams - process scenarios that the company usually uses to check on
compliance status.
Then we configured the GRC engineering pillars in the AdaptiveGRC application for
universal use across the system.
‘So far, the Risk Management & Compliance group has already set-up the initial
baseline of compliance control requirements, implemented a Vendor Compliance
Assessment Service (VCAS) and several other services. We are also supporting Legal
& Procurement in the delivery of FCPA and due diligence through the same
platform, reducing the number of systems, lowering costs and improving the
visibility of compliance status information.’
AdaptiveGRC System Owner
A stepped approach was taken to each delivery:
1. Analyze, understand and leverage legacy best practices
2. Ensure any unmet needs and challenges are captured
3. Design configuration for the activity using GRC engineering pillars while
continuing best practices and meeting the previously unmet needs
4. Verify and socialize plans with all primary stakeholders
5. Modify and adjust based on feedback
6. Configure
7. Train pilot users
8. Deliver to testing
9. Address any improvement items
10. Deploy pilot
11. Address any improvement items
12. Full operational use of the GRC activity
As each process was deployed, we ensured that all high value information sharing
opportunities are leveraged. As an example: for data privacy details about what internal
and external service providers ‘touch’ the system was captured. This information is
correlated in the process against the provider record, so as well as being able to review
suppliers for each system, it is also possible to look at what systems each provider is
involved with.
During the step-based implementation process of three AdaptiveGRC modules
(Compliance Manager, EA Manager, Quality Manager) the following GRC functions were
delivered: Compliance Requirements Framework, Vendor Risk Profiling, Application Risk
Profiling, Vendor Compliance Assessments, Privacy Change Reporting, Security Testing
Results Management, Anti-Corruption Assessments, Quality Management (Events,
Findings, CAPAs, Deviations).
OUTCOME
▪ Vastly improved metrics and earlier identification of issues and risks - now
analyzable across the enterprise and in real time
▪ Decreased system operation costs
a. Savings of millions of dollars compared to global licenses for multiple legacy
systems
b. Zero installation footprint (operates via browser)
c. No internal infrastructure requirement (cloud hosted)
▪ Simplification of processes
a. Single processes are now better automated and able to cover M4L4M (More For
Less For More)
b. Process duplications and overlaps are eliminated
▪ Increased operational efficiency of GRC activities and lower operational impact
a. Processes take staff less time (both GRC staff and operational personnel)
b. Frees up to focus on higher value tasks
c. Improves focus on continuous improvement
▪ Faster system speeds - no data latency (everything is immediately available)
▪ Improved collaboration capabilities and better cross-department information
sharing
a. Information is no longer trapped in pockets
b. Staff are overjoyed at getting better visibility of status
c. Inputted data is available for instant collaboration across the enterprise
▪ Integration with other high value data sources (e.g. CMDB, Active Directory, Attack
& Penetration)
www.adaptivegrc.com
info@adaptivegrc.com
US:
+1 650 600 1459
UK:
+44 203 608 3997
Poland:
+48 22 323 73 60
CONTACT US:
ABOUT AdaptiveGRC
We are an established technology
and support service provider with
solutions live in over 50 different
countries around the world.
Our unique AdaptiveGRC product
helps organizations to transform
their governance, risk management
and compliance activities. Clients tell
us we are the only company that
demonstrates successfully joined-up
enterprise GRC processes across
multiple regulations. This provides
incredibly powerful management
metrics straight out of the box,
including instant GRC status
reporting, offering many
user-selected variables to provide the
specific report required. A further
benefit of the toolset is an optional
set of baseline controls, which makes
it possible to get the system
operational in a matter of days. NEXT STEPS
AdaptiveGRC proved its power, capabilities and flexibility and now is planned to be
a global solution for further business processes in customer’s organization. Next services
to focus on and deliver are: Enterprise Risk Management module, Audit Management
module and SOX Management module.
© 2015 C&F

Más contenido relacionado

La actualidad más candente

Defining Segregation of Duties
Defining Segregation of DutiesDefining Segregation of Duties
Defining Segregation of Duties
Will Kelly
 
EHS Software Buyer Checklist
EHS Software Buyer ChecklistEHS Software Buyer Checklist
EHS Software Buyer Checklist
Anita Amelia
 
Operational Readiness Infographic
Operational Readiness InfographicOperational Readiness Infographic
Operational Readiness Infographic
George Georgalis
 
MCGlobalTech Cyber Capability Statement_Final
MCGlobalTech Cyber Capability Statement_FinalMCGlobalTech Cyber Capability Statement_Final
MCGlobalTech Cyber Capability Statement_Final
William McBorrough
 

La actualidad más candente (20)

Regulatory Considerations for use of Cloud Computing and SaaS Environments
Regulatory Considerations for use of Cloud Computing and SaaS EnvironmentsRegulatory Considerations for use of Cloud Computing and SaaS Environments
Regulatory Considerations for use of Cloud Computing and SaaS Environments
 
Efficient Document Control is Essential to Positive Audit Outcomes
Efficient Document Control is Essential to Positive Audit Outcomes Efficient Document Control is Essential to Positive Audit Outcomes
Efficient Document Control is Essential to Positive Audit Outcomes
 
Defining Segregation of Duties
Defining Segregation of DutiesDefining Segregation of Duties
Defining Segregation of Duties
 
TrustedAgent GRC for Public Sector
TrustedAgent GRC for Public SectorTrustedAgent GRC for Public Sector
TrustedAgent GRC for Public Sector
 
Services catalogue 2019
Services catalogue 2019Services catalogue 2019
Services catalogue 2019
 
EHS Software Buyer Checklist
EHS Software Buyer ChecklistEHS Software Buyer Checklist
EHS Software Buyer Checklist
 
Strategies for Conducting GxP Vendor Assessment of Cloud Service Providers - ...
Strategies for Conducting GxP Vendor Assessment of Cloud Service Providers - ...Strategies for Conducting GxP Vendor Assessment of Cloud Service Providers - ...
Strategies for Conducting GxP Vendor Assessment of Cloud Service Providers - ...
 
TrackWise Enterprise Quality Management System
TrackWise Enterprise Quality Management SystemTrackWise Enterprise Quality Management System
TrackWise Enterprise Quality Management System
 
Compliance Management Software | Corporate Compliance
Compliance Management Software | Corporate ComplianceCompliance Management Software | Corporate Compliance
Compliance Management Software | Corporate Compliance
 
Why Are Life Science Companies Moving to Office 365?
Why Are Life Science Companies Moving to Office 365?Why Are Life Science Companies Moving to Office 365?
Why Are Life Science Companies Moving to Office 365?
 
Operational Readiness Infographic
Operational Readiness InfographicOperational Readiness Infographic
Operational Readiness Infographic
 
TalaTek Enterprise Compliance Management Solution
TalaTek Enterprise Compliance Management SolutionTalaTek Enterprise Compliance Management Solution
TalaTek Enterprise Compliance Management Solution
 
Reglera Corporate Introduction
Reglera Corporate IntroductionReglera Corporate Introduction
Reglera Corporate Introduction
 
Recovery and Compliance Services provided by Tom Bronack
Recovery and Compliance Services provided by Tom BronackRecovery and Compliance Services provided by Tom Bronack
Recovery and Compliance Services provided by Tom Bronack
 
8D problem solving for NCR management: Beginners training
8D problem solving for NCR management: Beginners training 8D problem solving for NCR management: Beginners training
8D problem solving for NCR management: Beginners training
 
Sage X3 Food
Sage X3 Food Sage X3 Food
Sage X3 Food
 
Preparing for Inspections in eTMF
Preparing for Inspections in eTMFPreparing for Inspections in eTMF
Preparing for Inspections in eTMF
 
Oracle Enterprise Manager
Oracle Enterprise ManagerOracle Enterprise Manager
Oracle Enterprise Manager
 
IBM Maximo and ISO 55000
IBM Maximo and ISO 55000IBM Maximo and ISO 55000
IBM Maximo and ISO 55000
 
MCGlobalTech Cyber Capability Statement_Final
MCGlobalTech Cyber Capability Statement_FinalMCGlobalTech Cyber Capability Statement_Final
MCGlobalTech Cyber Capability Statement_Final
 

Similar a Adaptive grc life_sciences_case_study

Con8154 controlling for multiple erp systems with oracle advanced controls
Con8154 controlling for multiple erp systems with oracle advanced controlsCon8154 controlling for multiple erp systems with oracle advanced controls
Con8154 controlling for multiple erp systems with oracle advanced controls
Oracle
 
Facility Environmental Audit Guidelines
Facility Environmental Audit GuidelinesFacility Environmental Audit Guidelines
Facility Environmental Audit Guidelines
amburyj3c9
 
CML Group GRCaaS Dashboard
CML Group GRCaaS Dashboard CML Group GRCaaS Dashboard
CML Group GRCaaS Dashboard
Jim Robins
 
Stratesys - Flyer QA-CAPA - SEP2014 - ENG
Stratesys - Flyer QA-CAPA - SEP2014 - ENGStratesys - Flyer QA-CAPA - SEP2014 - ENG
Stratesys - Flyer QA-CAPA - SEP2014 - ENG
Stratesys
 

Similar a Adaptive grc life_sciences_case_study (20)

Managing Compliance Issues with ServiceNow GRC Solutions.pdf
Managing Compliance Issues with ServiceNow GRC Solutions.pdfManaging Compliance Issues with ServiceNow GRC Solutions.pdf
Managing Compliance Issues with ServiceNow GRC Solutions.pdf
 
Fixnix GRC Suite A Glance
Fixnix GRC Suite A GlanceFixnix GRC Suite A Glance
Fixnix GRC Suite A Glance
 
Maclear’s IT GRC Tools – Key Issues and Trends
Maclear’s  IT GRC Tools – Key Issues and TrendsMaclear’s  IT GRC Tools – Key Issues and Trends
Maclear’s IT GRC Tools – Key Issues and Trends
 
Con8154 controlling for multiple erp systems with oracle advanced controls
Con8154 controlling for multiple erp systems with oracle advanced controlsCon8154 controlling for multiple erp systems with oracle advanced controls
Con8154 controlling for multiple erp systems with oracle advanced controls
 
Customers talk about controlling access for multiple erp systems with oracle ...
Customers talk about controlling access for multiple erp systems with oracle ...Customers talk about controlling access for multiple erp systems with oracle ...
Customers talk about controlling access for multiple erp systems with oracle ...
 
Casualty Insurance
Casualty Insurance Casualty Insurance
Casualty Insurance
 
Best Practices for Rating and Policy Administration System Replacement
Best Practices for Rating and Policy Administration System ReplacementBest Practices for Rating and Policy Administration System Replacement
Best Practices for Rating and Policy Administration System Replacement
 
Facility Environmental Audit Guidelines
Facility Environmental Audit GuidelinesFacility Environmental Audit Guidelines
Facility Environmental Audit Guidelines
 
CML Group GRCaaS Dashboard
CML Group GRCaaS Dashboard CML Group GRCaaS Dashboard
CML Group GRCaaS Dashboard
 
Does audit make us more secure
Does audit make us more secureDoes audit make us more secure
Does audit make us more secure
 
Financial Services - New Approach to Data Management in the Digital Era
Financial Services - New Approach to Data Management in the Digital EraFinancial Services - New Approach to Data Management in the Digital Era
Financial Services - New Approach to Data Management in the Digital Era
 
An Introduction to econsys
An Introduction to econsysAn Introduction to econsys
An Introduction to econsys
 
SAP GRC
SAP GRC SAP GRC
SAP GRC
 
IT Security and Risk Management - Visionet Systems
IT Security and Risk Management - Visionet SystemsIT Security and Risk Management - Visionet Systems
IT Security and Risk Management - Visionet Systems
 
FDA News Webinar - Inspection Intelligence
FDA News Webinar - Inspection IntelligenceFDA News Webinar - Inspection Intelligence
FDA News Webinar - Inspection Intelligence
 
FDA News Webinar - Inspection Intelligence
FDA News Webinar - Inspection IntelligenceFDA News Webinar - Inspection Intelligence
FDA News Webinar - Inspection Intelligence
 
Dhaval Shah on "Strategic Alignment Of Projects For Higher Profits And Increa...
Dhaval Shah on "Strategic Alignment Of Projects For Higher Profits And Increa...Dhaval Shah on "Strategic Alignment Of Projects For Higher Profits And Increa...
Dhaval Shah on "Strategic Alignment Of Projects For Higher Profits And Increa...
 
GRC
GRCGRC
GRC
 
Stratesys - Flyer QA-CAPA - SEP2014 - ENG
Stratesys - Flyer QA-CAPA - SEP2014 - ENGStratesys - Flyer QA-CAPA - SEP2014 - ENG
Stratesys - Flyer QA-CAPA - SEP2014 - ENG
 
Stratesys - Flyer QA-CAPA - SEP2014 ENG
Stratesys - Flyer QA-CAPA - SEP2014 ENGStratesys - Flyer QA-CAPA - SEP2014 ENG
Stratesys - Flyer QA-CAPA - SEP2014 ENG
 

Último

Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Último (20)

Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 

Adaptive grc life_sciences_case_study

  • 1. A GLOBAL LIFE SCIENCES COMPANY IMPLEMENTS ADAPTIVEGRC SOLUTION SUITE FOR VARIOUS GRC SERVICES The customer is a global Life Sciences company operating in over 50 international markets. With $5bn annual turnover it has more than 4000 employees. CASE STUDY INDUSTRY Life Sciences REGION North America SOLUTION  Compliance Objectives Framework  Vendor Management  Data Privacy Management  Security Testing Results Management  Anti-Corruption Assessments  Quality Management  SOX Management  Risk Management KEY BENEFITS  Simplification of processes  Increased operational efficiency of GRC activities  Lower operational impact  Decreased system operation costs  Vastly improved metrics  Faster system speeds  Improved collaboration capabilities  Better cross-department information sharing  Integration with other high value data sources COMPANY PROFILE CHALLENGES The customer was separating out (divesting) from a Fortune 50 organization with a need to install and implement a solution across a wide range of GRC activities: - Compliance Objectives Framework, - Vendor Management, - Data Privacy Management, - Security Testing Results, - Anti-Corruption, - Quality Management (Actions, Deviations, Events), - Risk Management (Technology, Enterprise). There were many good legacy best practice processes but no licenses for legacy solutions. Legacy processes were performed across 6 different systems and there were also many spreadsheet based processes. Legacy data was disparate and hard to use for executive reporting. SOLUTION & APPROACH AdaptiveGRC solution suite was selected and implemented to meet GRC requirements and needs mentioned above. First, executive sponsorship was ensured, the intended path was socialized and the right representative team was put together. Next step was to distill the objectives (activities and metrics) and identify the organizations priority order for releasing and operationalizing their GRC activities. Then the required benefits were captured and kept at the heart of each stage. Having all of the above in place, a ‘vanilla’ AdaptiveGRC system was provided – with all the components set-up in COTS (out of the box) configuration, ready to customize and configure. The next phase was setting up the central GRC engineering pillars by distilling the primary GRC engineering correlation points, such as: a. Governance Factors - the primary regulations, standards and guidelines used by the organization to drive their GRC activities and executive reporting. In this case including Information Security (ISO27001), Data Privacy, SOX, PCI DSS, FDA regulations and more. b. Process Streams - process scenarios that the company usually uses to check on compliance status. Then we configured the GRC engineering pillars in the AdaptiveGRC application for universal use across the system. ‘So far, the Risk Management & Compliance group has already set-up the initial baseline of compliance control requirements, implemented a Vendor Compliance Assessment Service (VCAS) and several other services. We are also supporting Legal & Procurement in the delivery of FCPA and due diligence through the same platform, reducing the number of systems, lowering costs and improving the visibility of compliance status information.’ AdaptiveGRC System Owner
  • 2. A stepped approach was taken to each delivery: 1. Analyze, understand and leverage legacy best practices 2. Ensure any unmet needs and challenges are captured 3. Design configuration for the activity using GRC engineering pillars while continuing best practices and meeting the previously unmet needs 4. Verify and socialize plans with all primary stakeholders 5. Modify and adjust based on feedback 6. Configure 7. Train pilot users 8. Deliver to testing 9. Address any improvement items 10. Deploy pilot 11. Address any improvement items 12. Full operational use of the GRC activity As each process was deployed, we ensured that all high value information sharing opportunities are leveraged. As an example: for data privacy details about what internal and external service providers ‘touch’ the system was captured. This information is correlated in the process against the provider record, so as well as being able to review suppliers for each system, it is also possible to look at what systems each provider is involved with. During the step-based implementation process of three AdaptiveGRC modules (Compliance Manager, EA Manager, Quality Manager) the following GRC functions were delivered: Compliance Requirements Framework, Vendor Risk Profiling, Application Risk Profiling, Vendor Compliance Assessments, Privacy Change Reporting, Security Testing Results Management, Anti-Corruption Assessments, Quality Management (Events, Findings, CAPAs, Deviations). OUTCOME ▪ Vastly improved metrics and earlier identification of issues and risks - now analyzable across the enterprise and in real time ▪ Decreased system operation costs a. Savings of millions of dollars compared to global licenses for multiple legacy systems b. Zero installation footprint (operates via browser) c. No internal infrastructure requirement (cloud hosted) ▪ Simplification of processes a. Single processes are now better automated and able to cover M4L4M (More For Less For More) b. Process duplications and overlaps are eliminated ▪ Increased operational efficiency of GRC activities and lower operational impact a. Processes take staff less time (both GRC staff and operational personnel) b. Frees up to focus on higher value tasks c. Improves focus on continuous improvement ▪ Faster system speeds - no data latency (everything is immediately available) ▪ Improved collaboration capabilities and better cross-department information sharing a. Information is no longer trapped in pockets b. Staff are overjoyed at getting better visibility of status c. Inputted data is available for instant collaboration across the enterprise ▪ Integration with other high value data sources (e.g. CMDB, Active Directory, Attack & Penetration) www.adaptivegrc.com info@adaptivegrc.com US: +1 650 600 1459 UK: +44 203 608 3997 Poland: +48 22 323 73 60 CONTACT US: ABOUT AdaptiveGRC We are an established technology and support service provider with solutions live in over 50 different countries around the world. Our unique AdaptiveGRC product helps organizations to transform their governance, risk management and compliance activities. Clients tell us we are the only company that demonstrates successfully joined-up enterprise GRC processes across multiple regulations. This provides incredibly powerful management metrics straight out of the box, including instant GRC status reporting, offering many user-selected variables to provide the specific report required. A further benefit of the toolset is an optional set of baseline controls, which makes it possible to get the system operational in a matter of days. NEXT STEPS AdaptiveGRC proved its power, capabilities and flexibility and now is planned to be a global solution for further business processes in customer’s organization. Next services to focus on and deliver are: Enterprise Risk Management module, Audit Management module and SOX Management module. © 2015 C&F