SlideShare a Scribd company logo
1
Governance, Risk & Compliance -GRC
(Integrated Approach)
16th September 2014
Paul M Simidi
๏‚ง Introduction
๏‚ง GRC component framework
๏‚ง GRC Current status
๏‚ง iGRC & goals
๏‚ง iGRC Models
๏‚ง iGRC & Technology
๏‚ง Overall iGRC benefits
๏‚ง Organization experiences
Overview
Governance
โ€ฆโ€ฆ.setting business strategy & objectives,
determining risks appetite, establishing
culture and values, developing policies
and monitoring performanceโ€ฆโ€ฆ
Introduction
Risk Management
โ€ฆโ€ฆ.identifying and assessing risks that
may affect ability to achieve business
objectives, applying risks management to
obtain competitive advantage, and
determine response strategies and control
activitiesโ€ฆโ€ฆ
Introductionโ€ฆ.cont
Compliance
โ€ฆ..Operating in accordance with
objectives and ensuring adherence with
laws and regulations, internal policies &
procedures and stakeholder
commitmentsโ€ฆ..
Introductionโ€ฆcont
GRC Component Frameworks
โ€ข Control Objectives for Information and Related
Technology - CoBIT Framework provides guidance for
executive management to govern IT within the enterprise.
It is an IT governance framework that bridges the gap
between control requirements, technical issues and
business risks
โ€ข Sarbanesโ€“Oxley Act of 2002 - An Act to protect
investors by improving the accuracy and reliability of
corporate disclosures made pursuant to the securities laws,
and for other purposes
Governance - Examples
โ€ข Information Technology Infrastructure Library -
ITIL is the most widely adopted approach for IT
Service Management in the world. It is a practical
framework for identifying, planning, delivering and
supporting IT services to the business.
Governance - Examples
๏‚ง The Committee of Sponsoring Organizations of the
Treadway Commission (COSO) - A framework dedicated
to providing thought leadership through the development of
frameworks and guidance on enterprise risk management,
internal control and fraud deterrence)
Risk Management - Examples
โ€ข ISO 31000 -Provides principles and generic guidelines
on principles and implementation of risk management.
Can be applied to any kind of organization, risk type and
is not specific to any industry or sector.
โ€ข ISO 31000:2009 is intended to be used by a wide range
of stakeholders including those responsible for
โ€ข Implementing risk management,
โ€ข those who need to manage risk for the organization
as a whole or within a specific area or activity;
โ€ข those needing to evaluate an organization's practices
in managing risk;
โ€ข and developers of standards
Risk Management - Examples
๏‚ง Organizations Policies and Procedures
๏‚ง IFRSs
๏‚ง Legal & Regulatory Framework in Kenya
๏ƒ˜ Companyโ€™s Act
๏ƒ˜ Capital Markets Authority
๏ƒ˜ Nairobi Stock Exchange
๏ƒ˜ Communications Authority of Kenya
๏ƒ˜ Central Bank Regulations
๏ƒ˜ Public Procurement Act
๏ƒ˜ Occupational Safety and Health Administration
Act 2007 (OSHA)
๏ƒ˜ etc
Compliance - Examples
โ€ข Basel Standards i.e. I, II and III โ€“ An
international standard for Banking Regulators
developed by the Basel Committee on Banking
Supervision, to strengthen the regulation, supervision
and risk management of the banking sector.
โ€ข Total Quality Management (TQM)- Management
methods used to enhance quality and productivity in
business organizations
Compliance - Examples
Complexity
Lack of visibility
Duplication
InflexibilityVulnerability
Poor Integration
Increased regulations
Poor Performance
High Costs
Silos
Wasted Information
Frauds
Wasted Resources
GRC Current Status
Public Sector Overview
Private sector Overview
โ€ข iGRC - synchronize information
and activity across governance,
risk management and compliance
in order to create efficiency,
effective information sharing and
reporting, reduce cost and
enhance performance.
ERM
ICT
iGRC Approach
๏‚ง Large, forward-thinking organizations believe that
effective iGRC is a value driver and a source of
competitive advantage.
๏‚ง Organizations that embrace effective iGRC are
realizing significant value in the areas of
reputation and brand, employee retention and
profitability.
iGRC Trends
๏‚ง Significant improvements in the areas of accuracy,
decision-making quality, timeliness and reductions
in task redundancies as organization's move to an
integrated iGRC environment.
๏‚ง Inclusion of iGRC in Corporate Performance
Management
๏‚ง Increased Leverage on Technology
iGRC Trends
iGRC Goals
1. Awareness
โ€ข Changes in internal & external environment,
โ€ข Turn data into information that be analyzed.
โ€ข Share information
2.Alignment
โ€ข Support and inform business objectives
โ€ข Strategic consideration to GRC information
iGRC Goals
3. Responsiveness
โ€ข You cant react to something you
donโ€™t sense
โ€ข Greater awareness and
understanding of info that drives
decisions and actions
iGRC Goals
4. Agile
โ€ข Decisions and actions that are quick,
coordinated and well thought out.
โ€ข Allow an entity to use risk to its
advantages, grasp strategic opportunities
and be confident in its ability to stay on
course
iGRC Goals
5. Resilient
โ€ข Ability to bounce back from changes in
the environment e.g. threats
โ€ข Confidence to rapidly adopt and respond
to opportunities
6.Learn
โ€ข Get rid of unnecessary duplication,
redundancies, misallocation of resources
within GRC capability
โ€ข Examples of iGRC - OCEG-iGRC
โ€ข iGRC - synchronize information
and activity across governance,
risk management and compliance
in order to create efficiency,
enable more effective information
sharing and reporting and avoid
wasteful overlaps
ERM
ICT
iGRC Models
iGRC โ€“ OCEG Model
ORGANIZE AND OVERSEE
O1 โ€“ Outcomes and Commitment
O2 โ€“ Roles and Responsibilities
O3 โ€“ Approach and Accountability
INFORM AND INTEGRATE
I1 โ€“ Information Management and
Documentation
I2 โ€“ Internal and External Communication
I3 โ€“ Technology and Infrastructure
ASSESS AND ALIGN
A1 โ€“ Risk Identification
A2 โ€“ Risk Analysis
A3 โ€“ Risk Optimization
PREVENT AND PROMOTE
P1 โ€“ Codes of Conduct
P2 โ€“ Policies
P3 โ€“ Preventive Process Controls
P4 โ€“ Awareness and Education
P5 โ€“ Human Capital Incentives
P6 โ€“ Human Capital Controls
P7 โ€“ Stakeholder Relations and
Requirements
P8 โ€“ Preventive Technology Controls
P9 โ€“ Preventive Physical Controls
P10 โ€“ Risk Financing/Insurance
DETECT AND DISCERN
D1 โ€“ Hotline and Notification
D2 โ€“ Inquiry and Survey
D3 โ€“ Detective Controls
MONITOR AND MEASURE
M1 โ€“ Context Monitoring
M2 โ€“ Performance Monitoring and Evaluation
M3 โ€“ Systemic Improvement
M4 โ€“ Assurance
CONTEXT AND CULTURE
C1 โ€“ External Business Context
C2 โ€“ Internal Business Context
C3 โ€“ Culture
C4 โ€“ Values and Objectives
RESPOND AND RESOLVE
R1 โ€“ Internal Review and Investigation
R2 โ€“ Third-Party Inquiries and Investigations
R3 โ€“ Crisis Response and Recovery
R4 โ€“ Remediation and Discipline
GRC & Technology Solutions -Examples
Solution Modules
1 SAP GRC Suit ๏‚ง Process Control
๏‚ง Access Control
๏‚ง Risk Management
๏‚ง Fraud Management
๏‚ง Audit Management
2 ACL GRC Packages ๏‚งData Analytics
๏‚งCompliance & Monitoring
๏‚งDashboards Reporting
3 MetricStream GRC
Platform
๏‚งA Web-based platform built on J2EE
architecture with Governance, Risk,
Compliance and Quality programs.
Strategic Plan
๏‚ง Charter
๏‚ง Mission, vision statement
๏‚ง Responsibilities
๏‚ง Performance Measurement
๏‚ง Organization chart
๏‚ง Human capital
๏‚ง Financial plan
๏‚ง Technology plan
๏‚ง Assurance plan
๏‚ง Implementation plan
GRC โ€“ Universal Outcomes
๏‚ง Achieve Business Objectives
๏‚ง Enhanced organization culture towards GRC
๏‚ง Increased stakeholder confidence
๏‚ง Prevent, detect & reduce adversity
๏‚ง Motivates, inspire desired conduct
๏‚ง Improve responsiveness & efficiency
๏‚ง Optimize economic & social value
Why is it working or not working in your
organization ?
END
Paul Simidi
Tel 0720-739-425
email โ€“ paulsimidi@yahoo.com

More Related Content

PPTX
What is GRC โ€“ Governance, Risk and Compliance
PDF
Integrated GRC
PPTX
CISA exam 100 practice question
PDF
Digital Personal Data Protection (DPDP) Practical Approach For CISOs
PPTX
Grc governance, risk management & compliance
PPTX
Integrating Risk into your Balanced Scorecard
PPTX
Mitigating circumstance
PPSX
GRC Governance, Risk mgmt. & Compliance Executive
What is GRC โ€“ Governance, Risk and Compliance
Integrated GRC
CISA exam 100 practice question
Digital Personal Data Protection (DPDP) Practical Approach For CISOs
Grc governance, risk management & compliance
Integrating Risk into your Balanced Scorecard
Mitigating circumstance
GRC Governance, Risk mgmt. & Compliance Executive

What's hot (20)

PPTX
GRC Fundamentals
PDF
Governance, Risk, and Compliance Services
PPTX
Governance, Risk & Compliance Management Solution
PPTX
Governance, risk and compliance framework
ย 
PPTX
Governance risk and compliance
PPTX
it grc
PDF
Governance Risk Management and Compliance (GRC)
PDF
Enterprise Risk Management - Aligning Risk with Strategy and Performance
PPTX
Information Security Governance and Strategy
PPTX
IT Audit For Non-IT Auditors
PPTX
Implementing ISO27001 2013
PPTX
Continuous Transaction Monitoring Detect and analyze anomalous transactions t...
PDF
IT Security & Governance Template
PPTX
Basic introduction to iso27001
DOCX
Iso 27001 2013 Standard Requirements
PPTX
Key risk indicators shareslide
PPTX
Leveraging ISO 31000 for Effective Integration of Risk Management and Interna...
PDF
Cybersecurity roadmap : Global healthcare security architecture
PDF
Business Continuity Management
GRC Fundamentals
Governance, Risk, and Compliance Services
Governance, Risk & Compliance Management Solution
Governance, risk and compliance framework
ย 
Governance risk and compliance
it grc
Governance Risk Management and Compliance (GRC)
Enterprise Risk Management - Aligning Risk with Strategy and Performance
Information Security Governance and Strategy
IT Audit For Non-IT Auditors
Implementing ISO27001 2013
Continuous Transaction Monitoring Detect and analyze anomalous transactions t...
IT Security & Governance Template
Basic introduction to iso27001
Iso 27001 2013 Standard Requirements
Key risk indicators shareslide
Leveraging ISO 31000 for Effective Integration of Risk Management and Interna...
Cybersecurity roadmap : Global healthcare security architecture
Business Continuity Management
Ad

Similar to GRC - Isaca Training 16.9.2014 (20)

PDF
Achieving GRC Excellence White Paper.pdf
PDF
Roadmap to Achieving GRC Excellence White Papers
PDF
๐€๐œ๐ก๐ข๐ž๐ฏ๐ข๐ง๐  ๐†๐‘๐‚ ๐„๐ฑ๐œ๐ž๐ฅ๐ฅ๐ž๐ง๐œ๐ž: ๐˜๐จ๐ฎ๐ซ ๐‘๐จ๐š๐๐ฆ๐š๐ฉ ๐ญ๐จ ๐š ๐’๐ฎ๐œ๐œ๐ž๐ฌ๐ฌ๐Ÿ๐ฎ๐ฅ ๐‚๐š๐ซ๐ž๐ž๐ซ ๐ข๐ง ๐†๐จ๐ฏ๐ž๐ซ๐ง๐š๐ง๐œ๐ž, ...
PDF
Achieving GRC Excellence White Paper (6).pdf
PDF
Achieving GRC Excellence White Paper.pdf
PDF
Achieving GRC Excellence White Paper.pdf
PDF
From Cave Man to Business Man, the Evolution of the CISO to CIRO
PPTX
Risk - IT Services
PPTX
FRAMEWORKS AND STANDARDS-GRC,GDPR,SOX,PCI DSS,SOX,ISO
PPT
EUCI Mapping Cybersecurity to CIP
PDF
IT Risk Management & Leadership 30 March - 02 April 2014 Dubai UAE
ย 
PDF
Maclearโ€™s IT GRC Tools โ€“ Key Issues and Trends
PDF
The Journey to Integrated Risk Management: Lessons from the Field
PDF
(CISOPlatform Summit & SACON 2024) GRC.pdf
PPTX
CELOE MRKI Lecture Notes 02 v0.1_old.pptx
PPTX
Its time to rethink everything a governance risk compliance primer
PPTX
Third-Party Risk Management: Implementing a Strategy
ย 
DOCX
CHAPTER 6INFORMATION GOVERNANCEInformation Governance Po.docx
DOCX
IT Risk assessment and Audit Planning
PPTX
Erm talking points
Achieving GRC Excellence White Paper.pdf
Roadmap to Achieving GRC Excellence White Papers
๐€๐œ๐ก๐ข๐ž๐ฏ๐ข๐ง๐  ๐†๐‘๐‚ ๐„๐ฑ๐œ๐ž๐ฅ๐ฅ๐ž๐ง๐œ๐ž: ๐˜๐จ๐ฎ๐ซ ๐‘๐จ๐š๐๐ฆ๐š๐ฉ ๐ญ๐จ ๐š ๐’๐ฎ๐œ๐œ๐ž๐ฌ๐ฌ๐Ÿ๐ฎ๐ฅ ๐‚๐š๐ซ๐ž๐ž๐ซ ๐ข๐ง ๐†๐จ๐ฏ๐ž๐ซ๐ง๐š๐ง๐œ๐ž, ...
Achieving GRC Excellence White Paper (6).pdf
Achieving GRC Excellence White Paper.pdf
Achieving GRC Excellence White Paper.pdf
From Cave Man to Business Man, the Evolution of the CISO to CIRO
Risk - IT Services
FRAMEWORKS AND STANDARDS-GRC,GDPR,SOX,PCI DSS,SOX,ISO
EUCI Mapping Cybersecurity to CIP
IT Risk Management & Leadership 30 March - 02 April 2014 Dubai UAE
ย 
Maclearโ€™s IT GRC Tools โ€“ Key Issues and Trends
The Journey to Integrated Risk Management: Lessons from the Field
(CISOPlatform Summit & SACON 2024) GRC.pdf
CELOE MRKI Lecture Notes 02 v0.1_old.pptx
Its time to rethink everything a governance risk compliance primer
Third-Party Risk Management: Implementing a Strategy
ย 
CHAPTER 6INFORMATION GOVERNANCEInformation Governance Po.docx
IT Risk assessment and Audit Planning
Erm talking points
Ad

GRC - Isaca Training 16.9.2014

  • 1. 1 Governance, Risk & Compliance -GRC (Integrated Approach) 16th September 2014 Paul M Simidi
  • 2. ๏‚ง Introduction ๏‚ง GRC component framework ๏‚ง GRC Current status ๏‚ง iGRC & goals ๏‚ง iGRC Models ๏‚ง iGRC & Technology ๏‚ง Overall iGRC benefits ๏‚ง Organization experiences Overview
  • 3. Governance โ€ฆโ€ฆ.setting business strategy & objectives, determining risks appetite, establishing culture and values, developing policies and monitoring performanceโ€ฆโ€ฆ Introduction
  • 4. Risk Management โ€ฆโ€ฆ.identifying and assessing risks that may affect ability to achieve business objectives, applying risks management to obtain competitive advantage, and determine response strategies and control activitiesโ€ฆโ€ฆ Introductionโ€ฆ.cont
  • 5. Compliance โ€ฆ..Operating in accordance with objectives and ensuring adherence with laws and regulations, internal policies & procedures and stakeholder commitmentsโ€ฆ.. Introductionโ€ฆcont
  • 7. โ€ข Control Objectives for Information and Related Technology - CoBIT Framework provides guidance for executive management to govern IT within the enterprise. It is an IT governance framework that bridges the gap between control requirements, technical issues and business risks โ€ข Sarbanesโ€“Oxley Act of 2002 - An Act to protect investors by improving the accuracy and reliability of corporate disclosures made pursuant to the securities laws, and for other purposes Governance - Examples
  • 8. โ€ข Information Technology Infrastructure Library - ITIL is the most widely adopted approach for IT Service Management in the world. It is a practical framework for identifying, planning, delivering and supporting IT services to the business. Governance - Examples
  • 9. ๏‚ง The Committee of Sponsoring Organizations of the Treadway Commission (COSO) - A framework dedicated to providing thought leadership through the development of frameworks and guidance on enterprise risk management, internal control and fraud deterrence) Risk Management - Examples
  • 10. โ€ข ISO 31000 -Provides principles and generic guidelines on principles and implementation of risk management. Can be applied to any kind of organization, risk type and is not specific to any industry or sector. โ€ข ISO 31000:2009 is intended to be used by a wide range of stakeholders including those responsible for โ€ข Implementing risk management, โ€ข those who need to manage risk for the organization as a whole or within a specific area or activity; โ€ข those needing to evaluate an organization's practices in managing risk; โ€ข and developers of standards Risk Management - Examples
  • 11. ๏‚ง Organizations Policies and Procedures ๏‚ง IFRSs ๏‚ง Legal & Regulatory Framework in Kenya ๏ƒ˜ Companyโ€™s Act ๏ƒ˜ Capital Markets Authority ๏ƒ˜ Nairobi Stock Exchange ๏ƒ˜ Communications Authority of Kenya ๏ƒ˜ Central Bank Regulations ๏ƒ˜ Public Procurement Act ๏ƒ˜ Occupational Safety and Health Administration Act 2007 (OSHA) ๏ƒ˜ etc Compliance - Examples
  • 12. โ€ข Basel Standards i.e. I, II and III โ€“ An international standard for Banking Regulators developed by the Basel Committee on Banking Supervision, to strengthen the regulation, supervision and risk management of the banking sector. โ€ข Total Quality Management (TQM)- Management methods used to enhance quality and productivity in business organizations Compliance - Examples
  • 13. Complexity Lack of visibility Duplication InflexibilityVulnerability Poor Integration Increased regulations Poor Performance High Costs Silos Wasted Information Frauds Wasted Resources GRC Current Status
  • 16. โ€ข iGRC - synchronize information and activity across governance, risk management and compliance in order to create efficiency, effective information sharing and reporting, reduce cost and enhance performance. ERM ICT iGRC Approach
  • 17. ๏‚ง Large, forward-thinking organizations believe that effective iGRC is a value driver and a source of competitive advantage. ๏‚ง Organizations that embrace effective iGRC are realizing significant value in the areas of reputation and brand, employee retention and profitability. iGRC Trends
  • 18. ๏‚ง Significant improvements in the areas of accuracy, decision-making quality, timeliness and reductions in task redundancies as organization's move to an integrated iGRC environment. ๏‚ง Inclusion of iGRC in Corporate Performance Management ๏‚ง Increased Leverage on Technology iGRC Trends
  • 19. iGRC Goals 1. Awareness โ€ข Changes in internal & external environment, โ€ข Turn data into information that be analyzed. โ€ข Share information 2.Alignment โ€ข Support and inform business objectives โ€ข Strategic consideration to GRC information
  • 20. iGRC Goals 3. Responsiveness โ€ข You cant react to something you donโ€™t sense โ€ข Greater awareness and understanding of info that drives decisions and actions
  • 21. iGRC Goals 4. Agile โ€ข Decisions and actions that are quick, coordinated and well thought out. โ€ข Allow an entity to use risk to its advantages, grasp strategic opportunities and be confident in its ability to stay on course
  • 22. iGRC Goals 5. Resilient โ€ข Ability to bounce back from changes in the environment e.g. threats โ€ข Confidence to rapidly adopt and respond to opportunities 6.Learn โ€ข Get rid of unnecessary duplication, redundancies, misallocation of resources within GRC capability
  • 23. โ€ข Examples of iGRC - OCEG-iGRC โ€ข iGRC - synchronize information and activity across governance, risk management and compliance in order to create efficiency, enable more effective information sharing and reporting and avoid wasteful overlaps ERM ICT iGRC Models
  • 24. iGRC โ€“ OCEG Model ORGANIZE AND OVERSEE O1 โ€“ Outcomes and Commitment O2 โ€“ Roles and Responsibilities O3 โ€“ Approach and Accountability INFORM AND INTEGRATE I1 โ€“ Information Management and Documentation I2 โ€“ Internal and External Communication I3 โ€“ Technology and Infrastructure ASSESS AND ALIGN A1 โ€“ Risk Identification A2 โ€“ Risk Analysis A3 โ€“ Risk Optimization PREVENT AND PROMOTE P1 โ€“ Codes of Conduct P2 โ€“ Policies P3 โ€“ Preventive Process Controls P4 โ€“ Awareness and Education P5 โ€“ Human Capital Incentives P6 โ€“ Human Capital Controls P7 โ€“ Stakeholder Relations and Requirements P8 โ€“ Preventive Technology Controls P9 โ€“ Preventive Physical Controls P10 โ€“ Risk Financing/Insurance DETECT AND DISCERN D1 โ€“ Hotline and Notification D2 โ€“ Inquiry and Survey D3 โ€“ Detective Controls MONITOR AND MEASURE M1 โ€“ Context Monitoring M2 โ€“ Performance Monitoring and Evaluation M3 โ€“ Systemic Improvement M4 โ€“ Assurance CONTEXT AND CULTURE C1 โ€“ External Business Context C2 โ€“ Internal Business Context C3 โ€“ Culture C4 โ€“ Values and Objectives RESPOND AND RESOLVE R1 โ€“ Internal Review and Investigation R2 โ€“ Third-Party Inquiries and Investigations R3 โ€“ Crisis Response and Recovery R4 โ€“ Remediation and Discipline
  • 25. GRC & Technology Solutions -Examples Solution Modules 1 SAP GRC Suit ๏‚ง Process Control ๏‚ง Access Control ๏‚ง Risk Management ๏‚ง Fraud Management ๏‚ง Audit Management 2 ACL GRC Packages ๏‚งData Analytics ๏‚งCompliance & Monitoring ๏‚งDashboards Reporting 3 MetricStream GRC Platform ๏‚งA Web-based platform built on J2EE architecture with Governance, Risk, Compliance and Quality programs.
  • 26. Strategic Plan ๏‚ง Charter ๏‚ง Mission, vision statement ๏‚ง Responsibilities ๏‚ง Performance Measurement ๏‚ง Organization chart ๏‚ง Human capital ๏‚ง Financial plan ๏‚ง Technology plan ๏‚ง Assurance plan ๏‚ง Implementation plan
  • 27. GRC โ€“ Universal Outcomes ๏‚ง Achieve Business Objectives ๏‚ง Enhanced organization culture towards GRC ๏‚ง Increased stakeholder confidence ๏‚ง Prevent, detect & reduce adversity ๏‚ง Motivates, inspire desired conduct ๏‚ง Improve responsiveness & efficiency ๏‚ง Optimize economic & social value
  • 28. Why is it working or not working in your organization ?
  • 29. END Paul Simidi Tel 0720-739-425 email โ€“ paulsimidi@yahoo.com