NASDAQ – GOVERNANCE, RISK
MANAGEMENT, COMPLIANCE
CONTENTS
Masdaq GRC Strategy2
Brief Introduction
Managing Risk Framework
• Conduct Risk
How can technology help manage (Conduct) Risk
Lessons Learned in Implementations
Conclusion
WHO WE ARE
IGNITE YOUR AMBITION3
Nasdaq –BWise is a global leader in Enterprise Governance, Risk Management and
Compliance (GRC) software.
NASDAQ TICKER SYMBOL: NDAQ
MEMBER OF S&P 500
OUR MISSION >
To provide end-to-end solutions supporting an
organization’s ability to understand, track, measure,
and manage key organizational risks
OUR VISION >
To help companies to truly be in control by
balancing performance with their financial and
reputational risks, improving corporate
accountability and operating efficiencies
NASDAQ-BWISE AT A GLANCE
4
The journey to success
NASDAQlists
3400 COMPANIES
$6TRILLION MARKETCAP
10,000
NASDAQ customers
Gartner and Forrester
recognize BWise as GRC
leader since 2006
>1 million
GRC professionals
use BWise daily
NASDAQ BWISE CUSTOMERS
5
WHAT IS CONDUCT
RISK?
CONDUCT RISK
StrategicRisk
ReportingRisk
ComplianceRisk
OperationalRisk
Internal fraud
External fraud
Employment practices &
Workplace safety
Clients, products & business
practices
Damage to physical assets
Business disruption and failures
Execution, delivery & process
management
Conduct Risk
ConductRisk
CONDUCT RISK
StrategicRisk
ReportingRisk
ComplianceRisk
OperationalRisk
Internal fraud
External fraud
Employment practices &
Workplace safety
Clients, products & business
practices
Damage to physical assets
Business disruption and failures
Execution, delivery & process
management
Financial Risk Dimension
Reputational Risk Dimension
Conduct Risk Dimension
ALL AREAS OF THE BUSINESS, BUT TYPICALLY …
(EXAMPLE FOR FINANCIAL SERVICES)
Client-facing processes
• Sales & Marketing Processes
• Asset Management and Investment Advice
• Complaints Management
• Front Office Processes
Back-office processes
• Product Approval
• Remuneration & Incentives Program
IT assets & processes
• IT Assets and IT Processes involved in all of the above processes
NASDAQ GRC
BWise Master Roadmap10
NASDAQ VIEW OF THE GRC INDUSTRY
MAIN AREAS OF GRC
Nasdaq GRC Strategy11
Board-related
categories
Operational Risk
categories
Compliance
Categories
Legal Risk
Categories
Physical
Categories
Financial Risk
Categories
Enterprise Risk
Management
Audit
Management
Corporate
Governance
Corporate Social
Responsibility
Operational Risk
Management
Financial
Assurance &
Control
IT GRC
3rd Party
Management
Anti-corruption
& Fraud
Ethics & Integrity
Privacy
Management
Crisis
Management
Legal Matter
Management
Geo-Political
Risk
Management
Global Trade &
International
Dealings
Employment/
Labor
Physical Security
Management
Quality
Management
Environmental,
Health & Safety
Management
Treasury Risk
Management
Insurance &
Claims
Management
Credit Risk
Management
Market Risk
Management
Financial Crime
Risk
Management
Business
Continuity
Management
Social
Reputation Risk
Management
Regulatory
Compliance
ELEMENTS OF CONDUCT RISK
MAIN AREAS OF GRC
Nasdaq GRC Strategy12
Board-related
categories
Operational Risk
categories
Compliance
Categories
Legal Risk
Categories
Physical
Categories
Financial Risk
Categories
Enterprise Risk
Management
Audit
Management
Corporate
Governance
Corporate Social
Responsibility
Operational Risk
Management
Financial
Assurance &
Control
IT GRC
3rd Party
Management
Anti-corruption
& Fraud
Ethics & Integrity
Privacy
Management
Crisis
Management
Legal Matter
Management
Geo-Political
Risk
Management
Global Trade &
International
Dealings
Employment/
Labor
Physical Security
Management
Quality
Management
Environmental,
Health & Safety
Management
Treasury Risk
Management
Insurance &
Claims
Management
Credit Risk
Management
Market Risk
Management
Financial Crime
Risk
Management
Business
Continuity
Management
Social
Reputation Risk
Management
Regulatory
Compliance
ELEMENTS OF CONDUCT RISK
MAIN AREAS OF GRC
Nasdaq GRC Strategy13
Board-related
categories
Operational Risk
categories
Compliance
Categories
Legal Risk
Categories
Physical
Categories
Financial Risk
Categories
Enterprise Risk
Management
Audit
Management
Corporate
Governance
Corporate Social
Responsibility
Operational Risk
Management
Financial
Assurance &
Control
IT GRC
3rd Party
Management
Anti-corruption
& Fraud
Ethics & Integrity
Privacy
Management
Crisis
Management
Legal Matter
Management
Geo-Political
Risk
Management
Global Trade &
International
Dealings
Employment/
Labor
Physical Security
Management
Quality
Management
Environmental,
Health & Safety
Management
Treasury Risk
Management
Insurance &
Claims
Management
Credit Risk
Management
Financial Crime
Risk
Management
Business
Continuity
Management
Social
Reputation Risk
Management
Regulatory
Compliance
Market Risk
Management
HOW CAN TECHNOLOGY
HELP TO MANAGE RISK?
OPRISK CYCLE
Risk Identification
RCSA
Loss & Incident Management
Action Management Risk Framework
Capital Calculation
Risk Reporting
KRI Management
COMPLIANCE & POLICY MANAGEMENT CYCLE
Regulatory
Requirements
Risk-based Scoping
Policy Creation
Gap Analysis
Policy DisseminationPolicy Attestation
Compliance
Assessment
Regulatory Alerts
Remediation & Risk
Acceptance
Enterprise Reporting
Monitoring
INTERNAL CONTROL CYCLE
THE AUDIT CYCLE
INTEGRATION – SINGLE RISK LANGUAGE
Internal ControlInternal Audit
Compliance Risk Management
IMPLEMENTATION APPROACH
3 variants
IMPLEMENTATION FORMATS
1. RDS
BWise Best
Practice
working system
Gap Analysis
design document
Configuration
Go-Live system
2. Spiral
Business
Design
design document
System Design
design document
Configuration
Go-Live system
3. BCOE
BWise Training
trained team
Design &
Configure
working system
configuration
Go-Live system
WHY NASDAQ OMX BWISE
WHY NASDAQ BWISE
27
Company
Product
Services
Long term focus on GRC
Industry Leader since the start of the GRC market
GRC is an instrumental part of company strategy
100% configurable by client, 100% upgradable
Scalable, secure, east-to-use modern platform
100% integrated GRC functions
Global implementation partnerships, Transcendent
Global implementation teams and support
Long-term customer relationships and references
28
THANK YOU

More Related Content

PDF
Integrated GRC
PPTX
Creating Value Through Enterprise Risk Management
PDF
Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...
PDF
Ten Slides in Ten Minutes - Company Realities - GRC
PDF
Scammed: Defend Against Social Engineering
PPTX
Cyber Security in the Digital Age: A Survey and its Analysis
PDF
Six Degrees: Securing your business data - Nov 29 2018
PPSX
Does audit make us more secure
Integrated GRC
Creating Value Through Enterprise Risk Management
Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...
Ten Slides in Ten Minutes - Company Realities - GRC
Scammed: Defend Against Social Engineering
Cyber Security in the Digital Age: A Survey and its Analysis
Six Degrees: Securing your business data - Nov 29 2018
Does audit make us more secure

What's hot (17)

PDF
Adaptive & Unified Approach to Risk Management & Compliance-via-ccf
PDF
CHIME Lead Forum - Seattle 2015
PDF
Six Degrees Aegis - What's your cybersecurity maturity score?
PDF
Bridging the Gap Between Threat Intelligence and Risk Management
PDF
The Measure of Success: Security Metrics to Tell Your Story
PDF
Crown jewels risk assessment - Cost-effective risk identification
PDF
Security Framework for Digital Risk Managment
PPTX
Security architecture frameworks
PDF
The Demystification of successful cybersecurity initiatives.
PDF
Building an Effective Supply Chain Security Program
PPTX
[ON-DEMAND WEBINAR] Managed Service Providers vs Managed Security Service Pro...
 
PDF
Emerging Trends in Information Privacy and Security
PDF
Integrating Cybersecurity into Supply Chain Risk Management
PDF
Cyber Security Audits and Risk Management 20160119
PDF
GRCAlert Capabilities Deck - 2018
PPTX
Finding and Protecting Your Organizations Crown Jewels
PDF
GRC - Isaca Training 16.9.2014
Adaptive & Unified Approach to Risk Management & Compliance-via-ccf
CHIME Lead Forum - Seattle 2015
Six Degrees Aegis - What's your cybersecurity maturity score?
Bridging the Gap Between Threat Intelligence and Risk Management
The Measure of Success: Security Metrics to Tell Your Story
Crown jewels risk assessment - Cost-effective risk identification
Security Framework for Digital Risk Managment
Security architecture frameworks
The Demystification of successful cybersecurity initiatives.
Building an Effective Supply Chain Security Program
[ON-DEMAND WEBINAR] Managed Service Providers vs Managed Security Service Pro...
 
Emerging Trends in Information Privacy and Security
Integrating Cybersecurity into Supply Chain Risk Management
Cyber Security Audits and Risk Management 20160119
GRCAlert Capabilities Deck - 2018
Finding and Protecting Your Organizations Crown Jewels
GRC - Isaca Training 16.9.2014
Ad

Viewers also liked (20)

PDF
Vad innebär den nya penningtvättslagen
PDF
Måling og visualisering av informasjonssikkerhet
PDF
Rundabordssamtal kring FISK:en - hur tillämpas förordningen i praktiken och t...
PDF
Utvecklandet av en strategisk plan för din internrevisionsaktivitet
PDF
Skärpta krav för informationssäkerhet IT verksamhet och insättningssystem
PDF
Frukostseminarium om återhämtningsplaner
PDF
Frukostseminarium om finansiell brottslighet
PDF
Personlig integritet – möjliggörare eller hinder för verksamheten?
PDF
Penningtvättsgranskning i finansiella institut
PDF
How we got domain admin
PDF
Fem dataanalyser varje internrevisor bör ha med i sin revisionsplan
PDF
Nya IT-säkerhetshot och trender i en värld av lösningar
PDF
Hur kan kvaliten förbättras på din internrevisionsaktivitet vad fungerar
PDF
Cybersecurity inom bilindustrin
PDF
Är kris en förutsättning för compliance.pptx
PDF
Åtgärder mot penningtvätt och kommande förändringar
PDF
Mobila enheter och informationssäkerhetsrisker för nybörjaren
PDF
Projektstyrning i en komplex miljö
PDF
Finansiering av terrorism
PDF
Vad är kvalitet i internrevision?
Vad innebär den nya penningtvättslagen
Måling og visualisering av informasjonssikkerhet
Rundabordssamtal kring FISK:en - hur tillämpas förordningen i praktiken och t...
Utvecklandet av en strategisk plan för din internrevisionsaktivitet
Skärpta krav för informationssäkerhet IT verksamhet och insättningssystem
Frukostseminarium om återhämtningsplaner
Frukostseminarium om finansiell brottslighet
Personlig integritet – möjliggörare eller hinder för verksamheten?
Penningtvättsgranskning i finansiella institut
How we got domain admin
Fem dataanalyser varje internrevisor bör ha med i sin revisionsplan
Nya IT-säkerhetshot och trender i en värld av lösningar
Hur kan kvaliten förbättras på din internrevisionsaktivitet vad fungerar
Cybersecurity inom bilindustrin
Är kris en förutsättning för compliance.pptx
Åtgärder mot penningtvätt och kommande förändringar
Mobila enheter och informationssäkerhetsrisker för nybörjaren
Projektstyrning i en komplex miljö
Finansiering av terrorism
Vad är kvalitet i internrevision?
Ad

Similar to Effectively managing operational risk (20)

PDF
Applying risk management_to_your_business_continuity_management_efforts
PDF
Wise Men- SAP GRC Webinar Deck- March 2015
PDF
From Cave Man to Business Man, the Evolution of the CISO to CIRO
PPT
Iaccm Risk Slides
PPTX
Concept of Governance - Management of Operational Risk for IT Officers/Execut...
PDF
Mitigate Risk with Better Plan Execution and Organizational Alignment
PPTX
Risk Technology Strategy, Selection and Implementation
PDF
Tracxn - GRC Software Startup Landscape
PDF
Achieving GRC Excellence White Paper.pdf
PDF
Achieving GRC Excellence White Paper.pdf
PDF
Achieving GRC Excellence White Paper.pdf
PDF
Roadmap to Achieving GRC Excellence White Papers
PDF
𝐀𝐜𝐡𝐢𝐞𝐯𝐢𝐧𝐠 𝐆𝐑𝐂 𝐄𝐱𝐜𝐞𝐥𝐥𝐞𝐧𝐜𝐞: 𝐘𝐨𝐮𝐫 𝐑𝐨𝐚𝐝𝐦𝐚𝐩 𝐭𝐨 𝐚 𝐒𝐮𝐜𝐜𝐞𝐬𝐬𝐟𝐮𝐥 𝐂𝐚𝐫𝐞𝐞𝐫 𝐢𝐧 𝐆𝐨𝐯𝐞𝐫𝐧𝐚𝐧𝐜𝐞, ...
PDF
Achieving GRC Excellence White Paper (6).pdf
PPT
Mahindra Special Services Group - Services
PPTX
What is GRC – Governance, Risk and Compliance
PPTX
Top at risk drg s in the post icd 10 era and how to proactively address codin...
PDF
Riskpro construction industry 2013
PDF
Riskpro construction industry 2013
Applying risk management_to_your_business_continuity_management_efforts
Wise Men- SAP GRC Webinar Deck- March 2015
From Cave Man to Business Man, the Evolution of the CISO to CIRO
Iaccm Risk Slides
Concept of Governance - Management of Operational Risk for IT Officers/Execut...
Mitigate Risk with Better Plan Execution and Organizational Alignment
Risk Technology Strategy, Selection and Implementation
Tracxn - GRC Software Startup Landscape
Achieving GRC Excellence White Paper.pdf
Achieving GRC Excellence White Paper.pdf
Achieving GRC Excellence White Paper.pdf
Roadmap to Achieving GRC Excellence White Papers
𝐀𝐜𝐡𝐢𝐞𝐯𝐢𝐧𝐠 𝐆𝐑𝐂 𝐄𝐱𝐜𝐞𝐥𝐥𝐞𝐧𝐜𝐞: 𝐘𝐨𝐮𝐫 𝐑𝐨𝐚𝐝𝐦𝐚𝐩 𝐭𝐨 𝐚 𝐒𝐮𝐜𝐜𝐞𝐬𝐬𝐟𝐮𝐥 𝐂𝐚𝐫𝐞𝐞𝐫 𝐢𝐧 𝐆𝐨𝐯𝐞𝐫𝐧𝐚𝐧𝐜𝐞, ...
Achieving GRC Excellence White Paper (6).pdf
Mahindra Special Services Group - Services
What is GRC – Governance, Risk and Compliance
Top at risk drg s in the post icd 10 era and how to proactively address codin...
Riskpro construction industry 2013
Riskpro construction industry 2013

More from Transcendent Group (18)

PDF
Penetration testing as an internal audit activity
PDF
Sensommarmingel på temat finansiell brottslighet
PDF
Next generation access controls
PDF
Star strategy en inspirerande metod för mål och verksamhetsstyrning
PDF
Har ditt företag implementerat en process för att identifiera och hantera int...
PDF
Varför kostnadskontroll och riskhantering av programvara blir allt viktigare
PDF
Ta kontroll över personuppgiftshanteringen på ett effektivt sätt
PDF
Hur etablerar man en effektiv kris och kontinuitetshantering
PDF
Grc succéfaktorer; hur får man ut mer värde av grc än enbart regelefterlevnad
PDF
Den anpassningsbare överlever; den ökade regleringens effekter på svenska banker
PDF
Vem är personen bakom masken hur man hanterar interna bedrägerier
PDF
Styrelseledamotens roll och ansvar
PDF
Strängare krav på personuppgiftsbehandling senaste nytt om vår nya eu lag
PDF
Solvency ii and return on equity; optimizing capital and manage the risk
PDF
Kravställning för grc systemstöd
PDF
Erfarenhet från granskning av tredje parter utifrån fffs 20145
PDF
Frukostseminarium om informationssäkerhet
PDF
Förberedelser inför GRC-systemimplementering
Penetration testing as an internal audit activity
Sensommarmingel på temat finansiell brottslighet
Next generation access controls
Star strategy en inspirerande metod för mål och verksamhetsstyrning
Har ditt företag implementerat en process för att identifiera och hantera int...
Varför kostnadskontroll och riskhantering av programvara blir allt viktigare
Ta kontroll över personuppgiftshanteringen på ett effektivt sätt
Hur etablerar man en effektiv kris och kontinuitetshantering
Grc succéfaktorer; hur får man ut mer värde av grc än enbart regelefterlevnad
Den anpassningsbare överlever; den ökade regleringens effekter på svenska banker
Vem är personen bakom masken hur man hanterar interna bedrägerier
Styrelseledamotens roll och ansvar
Strängare krav på personuppgiftsbehandling senaste nytt om vår nya eu lag
Solvency ii and return on equity; optimizing capital and manage the risk
Kravställning för grc systemstöd
Erfarenhet från granskning av tredje parter utifrån fffs 20145
Frukostseminarium om informationssäkerhet
Förberedelser inför GRC-systemimplementering

Recently uploaded (20)

PPT
Galois Field Theory of Risk: A Perspective, Protocol, and Mathematical Backgr...
PDF
Abstractive summarization using multilingual text-to-text transfer transforme...
PDF
1 - Historical Antecedents, Social Consideration.pdf
PDF
OpenACC and Open Hackathons Monthly Highlights July 2025
PDF
Hindi spoken digit analysis for native and non-native speakers
PDF
The influence of sentiment analysis in enhancing early warning system model f...
PDF
CloudStack 4.21: First Look Webinar slides
PDF
A contest of sentiment analysis: k-nearest neighbor versus neural network
PDF
Credit Without Borders: AI and Financial Inclusion in Bangladesh
PPTX
Final SEM Unit 1 for mit wpu at pune .pptx
PDF
Convolutional neural network based encoder-decoder for efficient real-time ob...
PPTX
Modernising the Digital Integration Hub
PPTX
The various Industrial Revolutions .pptx
PDF
NewMind AI Weekly Chronicles – August ’25 Week III
PDF
Five Habits of High-Impact Board Members
PDF
TrustArc Webinar - Click, Consent, Trust: Winning the Privacy Game
DOCX
search engine optimization ppt fir known well about this
PPT
What is a Computer? Input Devices /output devices
PDF
A proposed approach for plagiarism detection in Myanmar Unicode text
PDF
A review of recent deep learning applications in wood surface defect identifi...
Galois Field Theory of Risk: A Perspective, Protocol, and Mathematical Backgr...
Abstractive summarization using multilingual text-to-text transfer transforme...
1 - Historical Antecedents, Social Consideration.pdf
OpenACC and Open Hackathons Monthly Highlights July 2025
Hindi spoken digit analysis for native and non-native speakers
The influence of sentiment analysis in enhancing early warning system model f...
CloudStack 4.21: First Look Webinar slides
A contest of sentiment analysis: k-nearest neighbor versus neural network
Credit Without Borders: AI and Financial Inclusion in Bangladesh
Final SEM Unit 1 for mit wpu at pune .pptx
Convolutional neural network based encoder-decoder for efficient real-time ob...
Modernising the Digital Integration Hub
The various Industrial Revolutions .pptx
NewMind AI Weekly Chronicles – August ’25 Week III
Five Habits of High-Impact Board Members
TrustArc Webinar - Click, Consent, Trust: Winning the Privacy Game
search engine optimization ppt fir known well about this
What is a Computer? Input Devices /output devices
A proposed approach for plagiarism detection in Myanmar Unicode text
A review of recent deep learning applications in wood surface defect identifi...

Effectively managing operational risk

  • 1. NASDAQ – GOVERNANCE, RISK MANAGEMENT, COMPLIANCE
  • 2. CONTENTS Masdaq GRC Strategy2 Brief Introduction Managing Risk Framework • Conduct Risk How can technology help manage (Conduct) Risk Lessons Learned in Implementations Conclusion
  • 3. WHO WE ARE IGNITE YOUR AMBITION3 Nasdaq –BWise is a global leader in Enterprise Governance, Risk Management and Compliance (GRC) software. NASDAQ TICKER SYMBOL: NDAQ MEMBER OF S&P 500 OUR MISSION > To provide end-to-end solutions supporting an organization’s ability to understand, track, measure, and manage key organizational risks OUR VISION > To help companies to truly be in control by balancing performance with their financial and reputational risks, improving corporate accountability and operating efficiencies
  • 4. NASDAQ-BWISE AT A GLANCE 4 The journey to success NASDAQlists 3400 COMPANIES $6TRILLION MARKETCAP 10,000 NASDAQ customers Gartner and Forrester recognize BWise as GRC leader since 2006 >1 million GRC professionals use BWise daily
  • 7. CONDUCT RISK StrategicRisk ReportingRisk ComplianceRisk OperationalRisk Internal fraud External fraud Employment practices & Workplace safety Clients, products & business practices Damage to physical assets Business disruption and failures Execution, delivery & process management Conduct Risk ConductRisk
  • 8. CONDUCT RISK StrategicRisk ReportingRisk ComplianceRisk OperationalRisk Internal fraud External fraud Employment practices & Workplace safety Clients, products & business practices Damage to physical assets Business disruption and failures Execution, delivery & process management Financial Risk Dimension Reputational Risk Dimension Conduct Risk Dimension
  • 9. ALL AREAS OF THE BUSINESS, BUT TYPICALLY … (EXAMPLE FOR FINANCIAL SERVICES) Client-facing processes • Sales & Marketing Processes • Asset Management and Investment Advice • Complaints Management • Front Office Processes Back-office processes • Product Approval • Remuneration & Incentives Program IT assets & processes • IT Assets and IT Processes involved in all of the above processes
  • 11. NASDAQ VIEW OF THE GRC INDUSTRY MAIN AREAS OF GRC Nasdaq GRC Strategy11 Board-related categories Operational Risk categories Compliance Categories Legal Risk Categories Physical Categories Financial Risk Categories Enterprise Risk Management Audit Management Corporate Governance Corporate Social Responsibility Operational Risk Management Financial Assurance & Control IT GRC 3rd Party Management Anti-corruption & Fraud Ethics & Integrity Privacy Management Crisis Management Legal Matter Management Geo-Political Risk Management Global Trade & International Dealings Employment/ Labor Physical Security Management Quality Management Environmental, Health & Safety Management Treasury Risk Management Insurance & Claims Management Credit Risk Management Market Risk Management Financial Crime Risk Management Business Continuity Management Social Reputation Risk Management Regulatory Compliance
  • 12. ELEMENTS OF CONDUCT RISK MAIN AREAS OF GRC Nasdaq GRC Strategy12 Board-related categories Operational Risk categories Compliance Categories Legal Risk Categories Physical Categories Financial Risk Categories Enterprise Risk Management Audit Management Corporate Governance Corporate Social Responsibility Operational Risk Management Financial Assurance & Control IT GRC 3rd Party Management Anti-corruption & Fraud Ethics & Integrity Privacy Management Crisis Management Legal Matter Management Geo-Political Risk Management Global Trade & International Dealings Employment/ Labor Physical Security Management Quality Management Environmental, Health & Safety Management Treasury Risk Management Insurance & Claims Management Credit Risk Management Market Risk Management Financial Crime Risk Management Business Continuity Management Social Reputation Risk Management Regulatory Compliance
  • 13. ELEMENTS OF CONDUCT RISK MAIN AREAS OF GRC Nasdaq GRC Strategy13 Board-related categories Operational Risk categories Compliance Categories Legal Risk Categories Physical Categories Financial Risk Categories Enterprise Risk Management Audit Management Corporate Governance Corporate Social Responsibility Operational Risk Management Financial Assurance & Control IT GRC 3rd Party Management Anti-corruption & Fraud Ethics & Integrity Privacy Management Crisis Management Legal Matter Management Geo-Political Risk Management Global Trade & International Dealings Employment/ Labor Physical Security Management Quality Management Environmental, Health & Safety Management Treasury Risk Management Insurance & Claims Management Credit Risk Management Financial Crime Risk Management Business Continuity Management Social Reputation Risk Management Regulatory Compliance Market Risk Management
  • 14. HOW CAN TECHNOLOGY HELP TO MANAGE RISK?
  • 15. OPRISK CYCLE Risk Identification RCSA Loss & Incident Management Action Management Risk Framework Capital Calculation Risk Reporting KRI Management
  • 16. COMPLIANCE & POLICY MANAGEMENT CYCLE Regulatory Requirements Risk-based Scoping Policy Creation Gap Analysis Policy DisseminationPolicy Attestation Compliance Assessment Regulatory Alerts Remediation & Risk Acceptance Enterprise Reporting
  • 19. INTEGRATION – SINGLE RISK LANGUAGE Internal ControlInternal Audit Compliance Risk Management
  • 21. IMPLEMENTATION FORMATS 1. RDS BWise Best Practice working system Gap Analysis design document Configuration Go-Live system 2. Spiral Business Design design document System Design design document Configuration Go-Live system 3. BCOE BWise Training trained team Design & Configure working system configuration Go-Live system
  • 22. WHY NASDAQ OMX BWISE
  • 23. WHY NASDAQ BWISE 27 Company Product Services Long term focus on GRC Industry Leader since the start of the GRC market GRC is an instrumental part of company strategy 100% configurable by client, 100% upgradable Scalable, secure, east-to-use modern platform 100% integrated GRC functions Global implementation partnerships, Transcendent Global implementation teams and support Long-term customer relationships and references