SlideShare a Scribd company logo
4
Most read
5
Most read
6
Most read
Governance, Risk, & Compliance
Fundamentals
David Houlihan
Principal Analyst
Blue Hill Research
©2013 Blue Hill Research. All Rights Reserved.

©2013 Blue Hill Research. All Rights Reserved.
Need for GRC Solutions is Growing, But
Implementation is Challenging

Compliance becomes top risk priority of Directors
Increasing market / business volatility
Demand
for
Solutions

Regulatory regimes more complex
Agencies more aggressive about enforcement
The frequency and pain of data breaches is growing

Information and function silos results in overlooked opportunities
and exposures
Sorting out GRC vendors visions and value propositions
Challenges
to
Implementation

©2013 Blue Hill Research. All Rights Reserved.

Difficulty conceptualizing ROI
Unclear how to prioritize implementation strategies to maximize
organizational benefit
Map GRC Capabilities to
Organizational Needs
GRC is maturing into a enterprise solution, but still suffers
from fractured perspectives.

Operational
?

Users should start by determining functional areas and use
cases that stand to benefit most.
Financial?

Enterprise?

Legal?

Organizations can then map out where core GRC
capabilities can support their business processes.
IT Security?

Core GRC Capabilities
Identify &
Analyze Risks

Set Controls

©2013 Blue Hill Research. All Rights Reserved.

Monitor

Identify
Vulnerabilities

Respond to
incidents

Report
The “Success Factors” of GRC
Minimize exposure
Reduce Compliance Cost
Recognize Opp./Risk

Executive

Finance
Maintain Data Security

Technology

Technology

Remove Silos
Reduce
redundancy/complexity

Line of
Business

LOB
Reduce time spent on
compliance tasks

©2013 Blue Hill Research. All Rights Reserved.

Increase profile in
organization
Key Themes to Consider

Roll-up of “point” GRC to enterprise GRC
Compliance as a C-suite initiative
Risk agility and intelligence
Data privacy and security
Social media risk
Anti-bribery, anti-laundering, and anti-terror compliance
©2013 Blue Hill Research. All Rights Reserved.
Thank you!
To join the conversation, follow us on

Phone: +1 (617) 624-3600

©2013 Blue Hill Research. All Rights Reserved.

Contact Sales: sales@bluehillresearch.com
Contact Research: research@bluehillresearch.com

1

More Related Content

PPTX
Governance, risk and compliance framework
PPTX
What is GRC – Governance, Risk and Compliance
PPT
It governance
PPTX
Governance risk and compliance
PPTX
Grc governance, risk management & compliance
PPTX
Governance, Risk & Compliance Management Solution
PDF
GRC - Isaca Training 16.9.2014
PPTX
Presentation techniques and presentation style
Governance, risk and compliance framework
What is GRC – Governance, Risk and Compliance
It governance
Governance risk and compliance
Grc governance, risk management & compliance
Governance, Risk & Compliance Management Solution
GRC - Isaca Training 16.9.2014
Presentation techniques and presentation style

What's hot (20)

PDF
Governance, Risk, and Compliance Services
PDF
Governance Risk Management and Compliance (GRC)
PPTX
it grc
PDF
Enterprise Risk Management - Aligning Risk with Strategy and Performance
PDF
Bcp drp
PDF
Cisa domain 3
PDF
Compliance framework
PDF
ISO 22301 Business Continuity Management
PPTX
Awareness iso 22301 danang suryo
PPTX
Business Continuity Planning Presentation
PPSX
GRC Governance, Risk mgmt. & Compliance Executive
PDF
Integrated GRC
PPTX
Information Security Governance and Strategy
PPT
Business Continuity Workshop Final
PDF
ISO 22301: The New Standard for Business Continuity Best Practice
DOCX
Iso 27001 2013 Standard Requirements
PDF
Assessing the impact of a disruption: Building an effective business impact a...
PPTX
27001 awareness Training
PPTX
Business continuity management per ISO 22301 - a certification training cour...
PDF
IT Governance
Governance, Risk, and Compliance Services
Governance Risk Management and Compliance (GRC)
it grc
Enterprise Risk Management - Aligning Risk with Strategy and Performance
Bcp drp
Cisa domain 3
Compliance framework
ISO 22301 Business Continuity Management
Awareness iso 22301 danang suryo
Business Continuity Planning Presentation
GRC Governance, Risk mgmt. & Compliance Executive
Integrated GRC
Information Security Governance and Strategy
Business Continuity Workshop Final
ISO 22301: The New Standard for Business Continuity Best Practice
Iso 27001 2013 Standard Requirements
Assessing the impact of a disruption: Building an effective business impact a...
27001 awareness Training
Business continuity management per ISO 22301 - a certification training cour...
IT Governance
Ad

Viewers also liked (20)

PPTX
Blue Hill Research: Managing Mobile Now and in the Future
PPTX
Hurricane Preparedness for Business Continuity - GRC Learning Series
KEY
Mobile Apps 101
PPTX
Ourschool
PDF
Construyendo la reputacion corporativa desde el principio
PDF
Presentation encuesta
PPTX
The analytic hero's journey
PDF
Shopper insights Tracking
PPTX
Food Safety Webcast: Allergen Management
PPTX
Presentation1 karen-mc-clintock
PDF
CMU Portugal inRes Initiative Presentation April 2014
PPTX
The Analytic Hero’s Journey
PPTX
Research guides tour (February 2016)
PDF
201502 cmu portugal_highlights
PPTX
Why AWS's Redshift is a Game Changer
PPTX
Library website features (February 2016)
PPTX
10 Things About the Library Website
PPTX
Naperville north tech workshop day 1
PPT
Ch4 1 v1
PPT
Ch3 5 v1
Blue Hill Research: Managing Mobile Now and in the Future
Hurricane Preparedness for Business Continuity - GRC Learning Series
Mobile Apps 101
Ourschool
Construyendo la reputacion corporativa desde el principio
Presentation encuesta
The analytic hero's journey
Shopper insights Tracking
Food Safety Webcast: Allergen Management
Presentation1 karen-mc-clintock
CMU Portugal inRes Initiative Presentation April 2014
The Analytic Hero’s Journey
Research guides tour (February 2016)
201502 cmu portugal_highlights
Why AWS's Redshift is a Game Changer
Library website features (February 2016)
10 Things About the Library Website
Naperville north tech workshop day 1
Ch4 1 v1
Ch3 5 v1
Ad

Similar to GRC Fundamentals (20)

PDF
GRC Strategies in a Business_ Trends and Challenges.pdf
PDF
Applying risk management_to_your_business_continuity_management_efforts
PPTX
7 Grc Myths Webinar 20110127 Final (2)
PDF
13 Top GRC Tools for an Integrated Governance, Risk and Compliance Strategy
PDF
Managing the Complexities of Governance, Risk & Compliance Requires
PPT
SLVA - Developing an IT GRC Strategy
PDF
Streamlining Identity and Access Management through Unified Identity and Acce...
PPTX
Information Rich, Knowledge Poor: Overcoming Insurers’ Data Conundrum
PPTX
Analytics for manufacturers: The three-minute guide
PPT
Ags001 Wilhoit 091707
PDF
ADP Human Capital Insights Magazine - Volume 2
PDF
Risk & Advisory Services: Quarterly Risk Advisor Feb. 2016
PPTX
Tech M&A Monthly - What To Do When You're Approached - December 2013
PPT
How It All Ties Together Sun Idm Roadshow For Sun
PDF
Improve success DevOps
PPTX
Innovatively Managing the Business Process to Create Excellence
PPTX
Concept of Governance - Management of Operational Risk for IT Officers/Execut...
PPTX
Big data governance as a corporate governance imperative
PDF
(CISOPlatform Summit & SACON 2024) GRC.pdf
GRC Strategies in a Business_ Trends and Challenges.pdf
Applying risk management_to_your_business_continuity_management_efforts
7 Grc Myths Webinar 20110127 Final (2)
13 Top GRC Tools for an Integrated Governance, Risk and Compliance Strategy
Managing the Complexities of Governance, Risk & Compliance Requires
SLVA - Developing an IT GRC Strategy
Streamlining Identity and Access Management through Unified Identity and Acce...
Information Rich, Knowledge Poor: Overcoming Insurers’ Data Conundrum
Analytics for manufacturers: The three-minute guide
Ags001 Wilhoit 091707
ADP Human Capital Insights Magazine - Volume 2
Risk & Advisory Services: Quarterly Risk Advisor Feb. 2016
Tech M&A Monthly - What To Do When You're Approached - December 2013
How It All Ties Together Sun Idm Roadshow For Sun
Improve success DevOps
Innovatively Managing the Business Process to Create Excellence
Concept of Governance - Management of Operational Risk for IT Officers/Execut...
Big data governance as a corporate governance imperative
(CISOPlatform Summit & SACON 2024) GRC.pdf

More from 3Sixty Insights (9)

PPTX
The Future of Finance in a World of Global Digital Transformation
PPTX
The Analytic Hero's Journey
PPTX
The Foundations of Social Media Risk Management
PPTX
ROI of A Liberated Data Analyst
PPTX
Achieving Better Credit and Collections with FinancialForce Accounting & Chatter
PPTX
Choosing AirWatch by VMware as a BYOD solution - A Blue Hill Research Case Study
PPTX
Investing in the Front End of Compliance
PPTX
SMAC talk for the enterprise
PPTX
Microsoft, Innovation, and its HR Failure
The Future of Finance in a World of Global Digital Transformation
The Analytic Hero's Journey
The Foundations of Social Media Risk Management
ROI of A Liberated Data Analyst
Achieving Better Credit and Collections with FinancialForce Accounting & Chatter
Choosing AirWatch by VMware as a BYOD solution - A Blue Hill Research Case Study
Investing in the Front End of Compliance
SMAC talk for the enterprise
Microsoft, Innovation, and its HR Failure

Recently uploaded (20)

PPTX
Big Data Technologies - Introduction.pptx
PDF
Machine learning based COVID-19 study performance prediction
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PPTX
A Presentation on Artificial Intelligence
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
Unlocking AI with Model Context Protocol (MCP)
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
cuic standard and advanced reporting.pdf
PDF
Encapsulation theory and applications.pdf
PDF
Encapsulation_ Review paper, used for researhc scholars
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Approach and Philosophy of On baking technology
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PDF
NewMind AI Monthly Chronicles - July 2025
Big Data Technologies - Introduction.pptx
Machine learning based COVID-19 study performance prediction
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
A Presentation on Artificial Intelligence
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Unlocking AI with Model Context Protocol (MCP)
“AI and Expert System Decision Support & Business Intelligence Systems”
Per capita expenditure prediction using model stacking based on satellite ima...
Advanced methodologies resolving dimensionality complications for autism neur...
Understanding_Digital_Forensics_Presentation.pptx
cuic standard and advanced reporting.pdf
Encapsulation theory and applications.pdf
Encapsulation_ Review paper, used for researhc scholars
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Approach and Philosophy of On baking technology
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
Mobile App Security Testing_ A Comprehensive Guide.pdf
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
NewMind AI Monthly Chronicles - July 2025

GRC Fundamentals

  • 1. Governance, Risk, & Compliance Fundamentals David Houlihan Principal Analyst Blue Hill Research ©2013 Blue Hill Research. All Rights Reserved. ©2013 Blue Hill Research. All Rights Reserved.
  • 2. Need for GRC Solutions is Growing, But Implementation is Challenging Compliance becomes top risk priority of Directors Increasing market / business volatility Demand for Solutions Regulatory regimes more complex Agencies more aggressive about enforcement The frequency and pain of data breaches is growing Information and function silos results in overlooked opportunities and exposures Sorting out GRC vendors visions and value propositions Challenges to Implementation ©2013 Blue Hill Research. All Rights Reserved. Difficulty conceptualizing ROI Unclear how to prioritize implementation strategies to maximize organizational benefit
  • 3. Map GRC Capabilities to Organizational Needs GRC is maturing into a enterprise solution, but still suffers from fractured perspectives. Operational ? Users should start by determining functional areas and use cases that stand to benefit most. Financial? Enterprise? Legal? Organizations can then map out where core GRC capabilities can support their business processes. IT Security? Core GRC Capabilities Identify & Analyze Risks Set Controls ©2013 Blue Hill Research. All Rights Reserved. Monitor Identify Vulnerabilities Respond to incidents Report
  • 4. The “Success Factors” of GRC Minimize exposure Reduce Compliance Cost Recognize Opp./Risk Executive Finance Maintain Data Security Technology Technology Remove Silos Reduce redundancy/complexity Line of Business LOB Reduce time spent on compliance tasks ©2013 Blue Hill Research. All Rights Reserved. Increase profile in organization
  • 5. Key Themes to Consider Roll-up of “point” GRC to enterprise GRC Compliance as a C-suite initiative Risk agility and intelligence Data privacy and security Social media risk Anti-bribery, anti-laundering, and anti-terror compliance ©2013 Blue Hill Research. All Rights Reserved.
  • 6. Thank you! To join the conversation, follow us on Phone: +1 (617) 624-3600 ©2013 Blue Hill Research. All Rights Reserved. Contact Sales: sales@bluehillresearch.com Contact Research: research@bluehillresearch.com 1