• About us
  • GRC-ERM Software
  • Applications
    • Enterprise Risk Management
    • Business Continuity Planning
    • Regulatory Compliance Management
    • Cybersecurity Risk Management
    • Risk-Based Auditing 
    • Third-Party Risk Management
    • Environmental Social and corporate Governance 
    • Information Security Management
    • Strategic Planning Management
  • FAQ
  • Insights
    • Blogs
    • Podcasts
    • Webinars
    • White papers
  • Contact us
z horse
  • About us
  • GRC-ERM Software

      Governance

      Balanced Scorecard

      Plan Management

      RSP Management

      Management Indicators

      Risk

      Risk Management

      Asset Management

      Business Impact Analysis

      Cybersecurity

      Event Management

      Incident Management 

      Compliance

      Assesments 

      Findings

      Audits

  • Applications
    • Enterprise Risk Management
    • Business Continuity Planning
    • Regulatory Compliance Management
    • Cybersecurity Risk Management
    • Risk-Based Auditing 
    • Third-Party Risk Management
    • Environmental Social and corporate Governance 
    • Information Security Management
    • Strategic Planning Management
  • FAQ
  • Insights
    • Blogs
    • Podcasts
    • Webinars
    • White papers
  • Contact us

REQUEST A DEMO
z horse
  • About us
  • GRC-ERM Software

      Governance

      Balanced Scorecard

      Plan Management

      RSP Management

      Management Indicators

      Risk

      Risk Management

      Asset Management

      Business Impact Analysis

      Cybersecurity

      Event Management

      Incident Management 

      Compliance

      Assesments 

      Findings

      Audits

  • Applications
    • Enterprise Risk Management
    • Business Continuity Planning
    • Regulatory Compliance Management
    • Cybersecurity Risk Management
    • Risk-Based Auditing 
    • Third-Party Risk Management
    • Environmental Social and corporate Governance 
    • Information Security Management
    • Strategic Planning Management
  • FAQ
  • Insights
    • Blogs
    • Podcasts
    • Webinars
    • White papers
  • Contact us

REQUEST A DEMO
newsletter

GRC. What’s Next?

By Álvaro Trujillo 

The past seven years have brought many changes to the GRC world. Management is more engaged in talking about risks. Organizations have implemented Enterprise Risk Management (ERM); enhanced Operational Risk to include more than just fraud; strengthened model risk management and at least accepted data risk management as an emerging risk.

Additionally, there has been a wave of developments on the technology front. Software that supports ERM and GRC are readily available. Support for data analytics can easily be found and even Board reporting software is available and in some instances quite robust. Yes there has been a lot of advance in GRC and risk management. So much so that it may make sense to explore what exactly can we do to continue to develop GRC to address future concerns.

While there are several, and some might say many, different developments that will happen or that needs to occur let us share just a few ideas.  These next steps we share are meant to strengthen the holistic risk management approach, not just use of software or development of a report. After all, GRC is more than software or words: it is, or at least it should be, a way of managing risk.

Number 1:  Develop risk management talent that understands the disciplines of GRC so that the organization can easily communicate emerging risk, the impact of risks to processes and controls and provide holistic perspective to the Board of Directors on risks affecting the organization. The one aspect missing in too many of todays Board conversations is the impact one risk has on another. Software alone cannot tell stakeholders what the ramification is of that synergetic impact. While some events may represent an integrated risk perspective that is not always the case. Yet no risk is a stand-alone risk and risk managers need to understand, quantify and communicate that risk synergy.

Number 2: Develop a risk response methodology, process and plan. If we are completely honest with ourselves, predicting risk events is not our strength. It never has been. Each of the past few risk events: 2011, 2017 and COVID-19 have been exacerbated by the lack of adequate response.  That alone should be the lesson to us but it is not evident that we have learned much in this regard. If we focus on the principles of risk management: recognize, measure and mitigate we may be better prepared to actually take advantage of the market in times of trouble.

Number 3: Get software that meets your culture and risk management goals and understand its use, purpose and limits. We often focus on costs and implementation time as key decision points when selecting GRC software. Don’t do that. Focus on cultural fit, ease of building response plans in the software, intuitive links within the software, the ability to recognize risk synergies and the actual “risk” support that the company offering you software provides. Any one can learn to use software but a company that will also train staff, share experienced based risk perspectives and support your risk management processes beyond the software sale is what we should expect.


Data Privacy
Previous Article
Compliance Watch
Next Article

z horse

Contact Us
[email protected]

(800) 519-9078

New Jersey

116 Village Boulevard, Suite 200
Princeton, NJ 08540
(800) 519-9078

  • Home
  • About us
  • Blog
  • Contact us
Youtube Twitter Linkedin
Copyright 2021 by Z-Horse
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT