IBM Developer

Article

Navigating governance, risk management, and compliance in modern business

Explore the vital synergy of governance, risk, and compliance (GRC) in modern business operations

By Kanti Babu Pinnamraju

Corporate landscapes encompass a diverse array of industries including energy, manufacturing, cybersecurity, supply chain, information technology, and banking and finance. The importance of monitoring compliance and managing risks across the entire business lifecycle has grown exponentially. It’s imperative to define, identify, and remediate the various risks and uncertainties that organizations face.

In this article, get an overview of governance, risk management, and compliance in today’s modern business world. A governance, risk, and compliance (GRC) framework helps organizations to establish policies and practices that minimizes compliance risk. Specifically, IT and security GRC solutions are designed to harness up-to-date information about data and infrastructure as well as virtual, mobile, and cloud applications.

Governance

Governance encompasses a set of rules, including mandates, sub-mandates, regulations, requirements, obligations, policies, and processes that are designed to ensure a smooth and organized execution of enterprise-level activities. You can use governance to achieve distinct financial and reputational goals while ensuring compliance with federal laws and regulations.

Effective governance practices provide top-level management with the ability to influence, direct, and interact with mid and lower-level employees, reviewing their contributions at granular levels. This centralized oversight allows for the equitable distribution of responsibilities and enables management to receive periodic reports and summaries of business outcomes and progress. This, in turn, facilitates the direction or alerting the different departments within your organization to take corrective and preventive measures.

Risk

A risk represents the potential occurrence of an event that can directly or indirectly impact an organization, resulting in the loss of its business outcomes or values. Risk management is a systematic process that involves defining, identifying, assessing, and controlling risks from various business domains, such as information technology and management, data security and quality, legal, business continuity, federal regulatory, and financial sectors.

Defining and identifying risk

Defining risk is the first step in risk management, involving the assessment of likelihood and the impacts, quantitatively and qualitatively. Key risk indicators (KRIs) are derived from these measures, which offers insight into the organization's health about specific risks and whether they are within an acceptable threshold.

For instance, identifying a security threat related to malware or trojan risk requires defining its impacts on critical IT infrastructure. These impact definitions encompass quantitative and qualitative measures to determine the extent of potential loss.

Inherent and residual risk

Inherent risk represents the risk that exists in the absence of controls. Residual risk, on the other hand, is the risk that remains after implementing precautions or controls. Monitoring both inherent and residual risk allows for a quick and accurate identification of potential threats and understanding their potential negative impacts on an organization's finances and reputation.

Inherent and residual risk

Compliance

Compliance involves adhering to rules, policies, standards, and laws that are set forth by industries and government agencies. Failure to comply can result in performance issues, costly mistakes, fines, penalties, and lawsuits.

Regulatory compliance covers external laws, regulations, and industry standards that are applicable to a company. Corporate or internal compliance deals with rules, regulations, and internal controls that are specific to an individual company. It is crucial for the internal compliance management program to seamlessly integrate with external compliance requirements. This integrated compliance program should revolve around a systematic process encompassing the creation, updating, distribution, and tracking of compliance policies while also providing employee training on these policies.

Creating an effective compliance program necessitates a thorough understanding of the areas that are most susceptible to risk within an organization. Resources should then be strategically allocated to address these high-risk areas. Policies must be developed, implemented, and effectively communicated to employees to mitigate risk in these areas.

Additionally, guidance should be established to facilitate adherence to compliance policies for both employees and vendors.

Compliance encompasses various critical areas such as risk assessment compliances, regulatory compliance, security compliance, and more. In detail, it involves:

  • Defining policies, procedures, and regulations: This involves aligning the organization's business processes with federal and organizational laws. By doing so, organizations not only avoid potential federal penalties but also establish high standards of operational excellence.
  • Control management: This includes defining controls, associating them with relevant risk areas and departments, assigning assessors, and regular monitoring to formulate effective remediation plans. It also involves defining methodologies for third-party due diligence, enhancing the effectiveness of these control mechanisms, and ensuring compliance.
  • Security training and assignments: These are the subsequent steps following control management. The activities relate to security training. In the event of significant breaches that impact trust or compliance, workflows for whistle-blower tasks are initiated.
  • Further compliance management: This phase includes various workflows, including risk mitigation, compliance themes, and review and approval templates.

Overall, compliance plays a pivotal role in organizations to navigaterisk, adhere to regulations, and maintain a secure and compliant operational environment.

compliance areas

Domains and applications of GRC

Essential domains and applications of GRC include third party risk management (TPRM), model risk governance (MRG), and business continuity management (BCM).

Third-party risk management

Organizations often engage multiple vendors, suppliers, and outsourcing service providers, each specializing in various services across distinct industries such as manufacturing, IT services, IT security, HR workforce, and more. In this context, it is imperative for the managing organization to identify and assess the vendor-related risks that are associated with these partners, whether they have collaborated in the past or are currently engaged in service delivery. This process of risk assessment also aids your organization in distinguishing among competing suppliers when making critical decisions to ensure the success of your own business.

This practice, known as third-party risk management (TPRM), facilitates the establishment of effective processes. These processes typically involve the use of questionnaires, information evaluation, surveys, and assessments, especially in the context of supply chain management. You can use questionnaires to evaluate the vendors through risk scores and compliance levels. TPRM can also can be seamlessly integrated into the supply chain mechanism by defining vendor risk scores.

After risk scores are defined, organizations can readily conduct regular vendor risk assessments to gain valuable insights into key risk indicators (KRIs). This in-depth analysis serves as a valuable tool for defining and enhancing due diligence measures concerning vendors.

Questionnaires consist of a series of questions designed to facilitate assessments, surveys, or the compilation of informative data, ultimately generating a risk score. You can tailor these questions to your specific needs. You can customize the questions, assign weightages to responses, and even attach the responses themselves. This comprehensive approach enables the evaluation of risk scores associated with particular vendors or assets.

Questionnaires can be directed toward various stakeholders, including team members, user groups, or a list of vendors, ensuring a targeted and efficient assessment process. Questionnaires can also be seamlessly integrated across various modules within the GRC tool, streamlining the risk evaluation process.

Key risk indicator (KRI) serves as a metric designed to gauge the likelihood of a risk and includes both the probability and potential consequences of an event. Although these factors combine to surpass the organization's predetermined threshold or limits, it signifies an elevated risk level. KRIs provide a health check for your organization in relation to specific risks, both before and after conducting assessments during monitoring processes.

Key performance indicator (KPI) is a measurable metric to assess the performance of a particular goal or business objective within a specific domain of your organization. Conversely, the reciprocal of a KRI is a KPI.

A typical vendor management lifecycle stages include:

  • Vendor identification and classification: Start by identifying all vendors and classify them based on their service categories, evaluating the criticality and importance of their roles within your organization.

  • Compliance assessment and rating: Conduct assessments of vendor compliance and standards in accordance with your client's requirements. Use these assessments to assign ratings, creating a measurable scale for vendor comparison and contract assignments.

  • Risk identification and mitigation: Use the rating system to identify potential risks associated with specific vendors. Develop and implement mitigation plans to address these risks effectively.

  • Ongoing monitoring and management: Regularly monitor and manage vendor compliance and risk mitigation efforts. This approach allows you to maintain a comprehensive vendor management strategy, including various levels of vendors such as 3rd-party and 4th-party providers.

vendor management lifecycle stages

Model risk governance

Machine learning (ML) and artificial intelligence (AI) is reshaping various industries, introducing innovations and novel perspectives. This transformation is noticeable in the governance, risk, and compliance sector, where ML and AI are revolutionizing the understanding and interpretation of concepts like such as and Loss Events. IBM® OpenPages® is an AI-driven GRC solution. OpenPages is continuously adapting and evolving in key areas of AI, offering compelling insights. A noteworthy area of evolution is Model Risk Governance.

A model refers to a quantitative method, system, or approach that applies statistical, economic, financial, or mathematical theories, methodologies, and assumptions. While models offer substantial benefits in improving business decisions, they also come with associated costs. Direct costs relate to allocating resources for the development and proper implementation of these models. Potential indirect costs include financial losses, stemming from decisions based on incorrect or misused models. Active management of model risk is important to address the consequences.

Model risk management

Model risk management encompasses more than just addressing the direct costs and losses that are associated with deploying models. It delves into the inherent risks within model predictions, evaluations, and monitoring. These risks encompass aspects such as data quality, the fairness or bias present in model prediction outcomes, prediction accuracy, and various parameters that are associated with outcome predictions. It also involves a comprehensive examination of problems and risks that are linked to model validation and deployment outcomes.

Model risk factors

In summary, ML and AI are shaping the landscape of GRC and introducing innovative approaches to model risk governance, particularly in the banking, financial services and insurance (BFSI) sector, where the use of data-driven models is integral to informed decision-making but also necessitates vigilant risk management.

Business continuity management

Organizations frequently encounter challenging situations such as economic downturns, natural disasters, or unexpected disruptions that disrupt normal business operations. This becomes especially critical during pandemics like COVID-19, where the availability of reliable data is vital for identifying critical and sensitive aspects of business execution.

Business continuity management (BCM) is a structured approach that guides legal entities and businesses in centralizing data related to business continuity management into a single location. This approach can be implemented consistently across the entire enterprise. BCM relies on a set of tools for planning and testing, which encompass processes and procedures. These tools also incorporate strategies for alternative business locations and the activation of recovery and disaster management teams in a timely manner. Additionally, BCM includes provisions for testing these alternative procedures and plans through Business Unit test plans. These tests are conducted by considering "what if" scenarios and associated risks.

Some key components of BCM are:

  • The BCM module identifies various risks, such as natural calamities like earthquakes, cyclones, pandemics, and security attacks, by monitoring specific parameters.
  • In the event that any of the aforementioned risks occur, incidents are automatically triggered, and the relevant teams are promptly notified.
  • Established counter processes and controls are activated to initiate the necessary remedial actions.
  • BCM incorporates scenario analysis, unit test plans, and procedures for remediation and recovery to ensure your organization's resilience in the face of disruptions.

Scenario analysis in business continuity management

Scenario analysis (SA) is a crucial assessment technique employed within the realm of business continuity management (BCM). It identifies and quantifies the potential occurrence of operational risk events. Unlike traditional operational risk assessments, SA adopts a forward-looking approach, asking "what if" questions.

Scenario analysis derives well-reasoned assessments regarding the likelihood and impact of plausible operational losses. This methodology identifies and quantifies events that are characterized by low frequency but high severity, such as natural disasters, acts of terrorism, or unexpected actions by rogue traders. In addition to its qualitative aspects, scenario analysis serves as a direct input into your origanization’s risk capital estimate.

Organizations can leverage the scenario analysis process within the IBM OpenPages platform to construct these analyses and gather qualitative and quantitative data to support their assessments. Scenario analyses are typically created for specific Business Entities and are assigned to a designated Risk Category. Associations can be created with supporting Operational Risk Management (ORM) data, including risk assessments, relevant loss events, losses recorded by the Operational Risk Insurance Consortium (ORIC), losses from the Operational Risk eXchange (ORX), and various risks that are associated with the scenario.

Scenario analysis example

Let’s use scenario analysis SA-0001 as an example. This scenario was conducted in the context of cybersecurity and the likelihood of this scenario occurring is estimated to be once in 10 years. The analysis provides a comprehensive overview of the potential impacts on the company should this scenario materialize. Such high-impact scenarios, even if they occur infrequently, warrant in-depth examination.

The example analysis explores the various drivers that could lead to the scenario, including loss events, risks, key risk indicators (KRIs), and other pertinent factors. These elements are closely associated with the scenario to ensure a comprehensive understanding of its potential consequences.

When the assessment completes, the Scenario Result objects are returned. The workflow then defines and determines the expected criteria for creating these result objects during the assessment review workflow. This ensures that the results are automatically generated according to a predefined and customized workflow.

scenario analysis

Scenario Analysis in BCM is a forward-looking, in-depth assessment technique that identifies and quantifies potential operational risk events. You can understand and prepare for low-frequency and high-impact scenarios with valuable insights to enhance your organization’s resilience and response strategies.

The following IBM OpenPages platform screen shows scenario analysis results after the Scenario Analysis Review:

IBM OpenPages platform screen showing scenario analysis results after the Scenario Analysis Review

Conclusion

This article provided an overview of governance, risk, and compliance topics, and explained why it has gained prominence across various business and industry sectors. The article explained the various terms, and explored key facets of GRC applications, including commonly used terminology such as questionnaires, key risk indicators (KRIs), and scenario analysis.

As a next step, learn how to Incorporate enterprise governance in your data.