Governance, risk management, and compliance (GRC) is something organizations do. You cannot buy GRC. In fact, every organization already does GRC – they have some approach to governance, risk management, and compliance. It can be scattered and ad hoc, it can be very structured and agile. The proper question to ask is how mature an organization’s approach to GRC is.
Technology and GRC solutions, if selected properly, help the organization improve their GRC strategy and process maturity by delivering an information and technology architecture that makes GRC more effective, efficient and agile. The challenge is that organizations often put the cart before the horse and are quick to purchase a GRC solution before understanding what their specific GRC strategy and process needs are. The result can be disaster.
|