About
Subscribe

GRC needs strategic planning to succeed

Staff Writer
By Staff Writer, ITWeb
Johannesburg, 30 Apr 2014

The sooner organisations take the first step in implementing , and (GRC), the sooner they will achieve good corporate governance, visibility, consistent dashboards and the ability to make swift, accurate decisions.

So says Servaas Venter, country manager of EMC Southern Africa, who notes that there is no quick fix in the quest to achieve effective GRC - extensive planning is required and, to attain the desired results, each organisation needs to travel its own specific journey.

"Some companies believe that they are too immature to start implementing GRC processes and systems, and that they need to have all the policies in place first," says Venter.

"On the contrary, this isn't necessary - a better approach would be to start small by finding ways to optimise and align existing forms of GRC which are already taking place in the company," he explains.

Organisations need to realise that governance, risk and compliance is a journey, not a once-off project, he adds.

He believes that it's possible to understand the issues and build the system over time until good corporate governance is achieved.

"It's highly motivational to achieve a series of quick wins by automating and optimising existing GRC processes which deliver value and are easy to grow into an ongoing programme."

According to Venter, there is increasing demand for multi-functional GRC solutions capable of providing all parties in the organisation with access to the same information. This plays a key role in quicker, more effective decision-making.

"Initially, there was a tendency to focus on risk management or compliance as the use case for GRC. Now, we are seeing more organisations with broader expectations, often driven by escalating regulation requirements such as the Protection of Personal Information Act from a security perspective, advanced persistent threats," explains Venter.

Organisations want to ensure that they are doing the right things, and have the right checks and balances in place for good corporate governance, and that means not having multiple sets of data within the enterprise, he notes.

This is where systems management software comes into play, with its ability to provide access to the right information on the fly, and to ensure that the organisation is aligned with accepted global practices and standards. This is essential whether a company is striving to increase its footprint in SA or to be a global player, says Venter.

Commenting on the challenges faced by companies regarding information risk, Venter says not knowing there's a problem is the biggest challenge.

"After all, if you don't know what the risk is, how can you fix it? It's essential that companies identify issues timeously and put measures in place to mitigate risk which could otherwise cause reputational, financial and brand damage," he advises.

"It's best to be proactive. When there is no choice but to implement reactive risk management, the priority is to ensure the impact is contained, follow best practice, and put plans in place to alleviate the business impact.

"The truth is that automating GRC processes creates more effective processes, enables the organisation to hold people accountable, fosters better collaboration and enables visibility into true governance, risk and compliance. In addition, there is less risk of fines and its adds value back into the business," concludes Venter.

Share