3 – Engaging Risk: providing a social GRC architecture, Integrc’s "Engaging Risk”

The 2013 GRC Technology Innovator awards was filled with competition.  The number of submissions more than doubled over 2012.  With 57 submissions there were only twelve slots for winners.  GRC 20/20 looked through all of the submissions, asked for clarification where needed, and selected the 12 recipients to receive this honor.

Number 3 is Integrc’s "Engaging Risk” which showed technology innovation for engaging Risk: providing a social GRC architecture.

Integrc’s "Engaging Risk” is a combination of integrated GRC knowledge solutions that helps organizations achieve greater understanding and interaction. The common aspiration for organizations is to change how they interact, adopt, perceive and embed GRC technologies and initiatives and Engaging Risk achieves this through a portfolio of user facing technologies that include dashboards, apps, adobe forms, and internal tools for GRC. Engaging Risk promotes "social GRC” (gamification) and helps organizations improve participation in risk management. Historical GRC solutions are designed primarily with the risk community in mind; Engaging Risk takes a broader approach by recognizing that successful GRC initiatives engage the users and other stakeholders, encouraging participation, explaining benefits and embedding  into standard processes. Engaging Risk does not replace the core GRC engine but focuses on delivery of the GRC benefits through the wider user community. Engaging Risk increases the participation in the processes and the perception of GRC processes by breaking down the silos and making GRC relevant to the wider community. The core goals are applied; to hunt down the pain for GRC users, to encourage adoption by lowering the participation barriers and embed GRC in the DNA of the business.

 

4 – Delivering GRC Architecture, MEGA’s Holistic Operational Excellence platform (HOPEX)

The 2013 GRC Technology Innovator awards was filled with competition.  The number of submissions more than doubled over 2012.  With 57 submissions there were only twelve slots for winners.  GRC 20/20 looked through all of the submissions, asked for clarification where needed, and selected the 12 recipients to receive this honor.

Number 4 is MEGA’s Holistic Operational Excellence platform (HOPEX) which showed technology innovation for delivering GRC Architecture. 

MEGA’s Holistic Operational Excellence platform (HOPEX) integrates enterprise architecture (EA) capabilities with GRC capabilities into one platform. This enables an organization to manage a GRC program that delivers value, aligns with core business strategy and objectives, and drives operational performance and process execution. The HOPEX platform empowers organizations to gather and understand enterprise strategy, capabilities, business processes, organizational structure and assets, including IT assets, risks, and controls. GRC programs and initiatives can now include modeling capabilities, on top of which assessment and governance capabilities can be used by a large number of employees in the organization to assess and monitor business performance.  By leveraging EA and GRC capabilities on the same platform, GRC Architects can utilize architecture capabilities to understand how their organization works and plan transformations, with execution capabilities to get the transformation implemented and assessed, in a continuous improvement approach. This fosters the alignment with strategies, business processes, information systems and corporate objectives. GRC professionals will then have a clear, detailed vision into the business and the direct results of managing, testing, and monitoring can be shared to improve the organization.

 
 
 

5 – Mind-mapping GRC, C2CSmartCompliance’s Compliance Mapper

The 2013 GRC Technology Innovator awards was filled with competition.  The number of submissions more than doubled over 2012.  With 57 submissions there were only twelve slots for winners.  GRC 20/20 looked through all of the submissions, asked for clarification where needed, and selected the 12 recipients to receive this honor.

Number 5 is C2CSmartCompliance’s Compliance Mapper which showed technology innovation for mind-mapping GRC.  

C2CSmartCompliance’s Compliance Mapper has a powerful GRC content mapping engine that allows an organization to graphically map regulatory and customer-generated content and click to establish bi-directional links.  The organization can graphically map policies and procedures to regulations and standards. Compliance Mapper eliminates the need for generically mapped, document-based approaches and reduces the number of controls needed to validate GRC.  The mapping engine enables ‘anything’ across the GRC spectrum to be linked together such that the relationship(s) many levels deep can be seen. For example, an incident could be mapped to an asset that is linked to a procedure that addresses a policy that meets a requirement (standard or regulatory requirement). Change a policy, regulation, standard or best practice in the GRC framework and see what is affected before making the change. C2C mapping technology highlights both direct mapping and indirect mappings ensuring all affected parties can be notified of possible changes, before a process or supporting document is ‘knocked out’ of compliance. 

 
 
 

6 – The user experience: the Apple of GRC, The Network’s Integrated GRC Suite

The 2013 GRC Technology Innovator awards was filled with competition.  The number of submissions more than doubled over 2012.  With 57 submissions there were only twelve slots for winners.  GRC 20/20 looked through all of the submissions, asked for clarification where needed, and selected the 12 recipients to receive this honor.

Number 6 is The Network’s Integrated GRC Suite which showed technology innovation for the user experience: the Apple of GRC.  

The Network’s Integrated GRC Suite is innovative for its design and end user experience. While most GRC applications focus on the back-end complexity of GRC, The Network has delivered a platform that is fresh, beautiful, and simply elegant for the user. It features an intuitive, employee-engaging, social media-style interface for ease of use, collaboration and configurability to an organization’s specific needs to match brand and culture, and is scalable to address global needs. The GRC Suite is positioned to help organizations transform the compliance function from a chore into a valued and valuable business asset. The GRC Suite blends GRC technology with awareness and communications expertise to help drive ethical culture. Where other GRC technology providers focus on the professional side of the equation, The Network’s solution adds interface assets that work to engage employees, while providing administrators and executives with the tools needed to manage compliance. Recognizing that employees are both the greatest asset and the biggest risk toward an ethical culture, the GRC Suite has been developed to enhance how employees consume, retain and apply information, to engrain them in the compliance process.

 
 

7 – Integrating content, experience, and process, Compli Portfolio™

The 2013 GRC Technology Innovator awards was filled with competition.  The number of submissions more than doubled over 2012.  With 57 submissions there were only twelve slots for winners.  GRC 20/20 looked through all of the submissions, asked for clarification where needed, and selected the 12 recipients to receive this honor.

Number 7 is Compli Portfolio™ which showed technology innovation for integrating content, experience, and process. 

Think of Compli Portfolio™ as the “electronic binder” that integrates the work of internal and external experts in an elegant user experience to illustrate and manage an organization’s compliance and risk profile. Portfolio allows organizations to take their important disparate systems (which normally generate waste and functional overlap, limiting an organization’s ability to quickly demonstrate a program’s efficacy) and integrate them into a single outlet with a powerful reporting engine thereby “connecting the dots” when it comes to meeting compliance requirements.  Portfolio is an innovative approach to providing the integration of technology, process, and to automate the awareness, training and risk mitigation process. No matter the origin of an organization’s content, Portfolio provides a graceful interface that becomes a GRC binder for policies, procedures, trainings and certifications required of internal and external stakeholders. Portfolio utilizes workflow and content tools that deliver an intuitive, drag and drop interface to quickly create effective awareness, training and reporting campaigns. GRC professionals and subject matter experts can instantly devise complex cross-functional initiatives without requiring additional programming or being technology experts.

 
 
 
 

8 – Managing risk in social networks, OpenQ’s SafeGuard™

The 2013 GRC Technology Innovator awards was filled with competition.  The number of submissions more than doubled over 2012.  With 57 submissions there were only twelve slots for winners.  GRC 20/20 looked through all of the submissions, asked for clarification where needed, and selected the 12 recipients to receive this honor.

Number 8 is OpenQ’s SafeGuard™ which showed technology innovation for managing risk in social networks. 

OpenQ’s SafeGuard™ is addressing the risk of social technologies in regulated industries that have held back from using social technology because of GRC concerns. SafeGuard can be used with any social platform and is currently integrated into more than a dozen platforms.  It monitors risk from interactions over social networking platforms for regulated-industries to enforce corporate policy and regulatory compliance. SafeGuard collects and analyzes data, identifying levels of risk and enabling personnel to address any issues with its workflow-driven remediation capabilities. The product analyzes the internal social data streams and external social media to identify, quarantine and enable management of risk. There are similar products on the market that use keyword searches, however, SafeGuard’s social compliance technology uses a policy/signature driven approach, similar to that of antivirus software, which can adapt to industry and company needs.  It is the first and only product for policy-driven social compliance in the health, life science, and financial services ecosystems.

 
 
 
 

9 – Advancing GRC mobility, Blackthorn's CaseNotes

The 2013 GRC Technology Innovator awards was filled with competition.  The number of submissions more than doubled over 2012.  With 57 submissions there were only twelve slots for winners.  GRC 20/20 looked through all of the submissions, asked for clarification where needed, and selected the 12 recipients to receive this honor.

Number 9 is Blackthorn CaseNotes which showed technology innovation for advancing GRC mobility.

Supporting GRC activities on the move, Blackthorn CaseNotes represents one of the most feature rich GRC mobile apps available. It enables specialists in a range of GRC fields to collect and manage information. Forms are created and published via a web portal to CaseNotes, which are completed by the mobile user on or offline and then sent back to the server for recording and analysis. CaseNotes enables GRC mobile specialists to take contemporaneous notes, complete forms and associate photos, videos, audio recordings and scanned barcodes with each GRC activity they are managing (e.g. cases, incidents, assessments, audits, reviews) What makes it different from other notes apps is that it uses encryption and hashing to give evidential integrity to the notes, making it ideal for uses where accountability, positive assurance and legal admissibility matter while fully supporting a mobile workforce that is both offline and online.

 
 
 
 
 
 
 
 

10 – From GRC idea to “there's an app for that,” Compliance Assurance Corporation’s Compliance Idea eXchange

The 2013 GRC Technology Innovator awards was filled with competition.  The number of submissions more than doubled over 2012.  With 57 submissions there were only twelve slots for winners.  GRC 20/20 looked through all of the submissions, asked for clarification where needed, and selected the 12 recipients to receive this honor.

Number 10 is Compliance Assurance Corporation’s Compliance Idea eXchange (CIE) which showed technology innovation for their ability to move from GRC idea to “there's an app for that. 

Compliance Assurance Corporation’s Compliance Idea eXchange (CIE) enables their clients to drive innovation, with a particular focus in GRC in the insurance vertical.  Clients define and model new applications that are made available as applications to other clients.  Client innovations are referred to as ideas that are turned into Apps. The Apps are embeeded into the Idea eXchange interface; allowing other CODE users to find, share, and execute value-added Apps.  The Idea eXchange functions for GRC similar to Apple’s App Store.  CIE provides GRC professionals with the ability to “mold” the platform to solve challenges in a variety of relevant domains. The eXchange provides a platform where these new, innovative ideas can be shared and reused by other companies. It empowers clients to harness their own innovative ideas and concepts, and transform them into real-world business and compliance process improvements.  What is different about this approach compared to similar efforts in the past is the depth of focus for apps and content on the insurance vertical specifically.

 
 
 
 
 
 

11 – Advancing GRC analytics, SAP's HANA Analytics Foundation for SAP GRC Solutions

The 2013 GRC Technology Innovator awards was filled with competition.  The number of submissions more than doubled over 2012.  With 57 submissions there were only twelve slots for winners.  GRC 20/20 looked through all of the submissions, asked for clarification where needed, and selected the 12 recipients to receive this honor.

Number 11 is SAP's HANA Analytics Foundation for SAP GRC Solutions which showed technology innovation for advancing GRC analytics. 

In the era of ‘Big Data,’ SAP HANA Analytics Foundation for SAP Solutions for GRC shows innovation in addressing the burgeoning velocity, volume, and variety of GRC governance, risk and compliance data in the enterprise. This The SAP HANA® platform leverages in-memory data to speed analysis of large volumes of data to provide insight. SAP HANA speeds the process of gathering, analyzing, and reporting and creates new opportunities for cross-system GRC and business analytics.  It allows for complex analysis by aggregating thousands or even millions of pieces of data across systems that used to be a task that must be run overnight or during off-hours. One example of the value of SAP HANA is in the area of fraud analytics with the ability to take an entirely new approach to fraud detection, prevention and management leveraging in-memory technology to provide insights into fraud, waste, and misuse allowing companies to take action before damage occurs. SAP HANA enables fraud detection in quasi-real-time and prevents transactions from proceeding to avoid loss. It significantly improves the accuracy of fraud identification by reducing the number of false positives and investigation team workload, and leverages predictive analytics to analyze potential fraud scenarios and adapt to changing fraud patterns.

 
 
 
 
 
 
 

12 – Efficiencies in reporting, ControlPanelGRC’s AutoAuditor

The 2013 GRC Technology Innovator awards was filled with competition.  The number of submissions more than doubled over 2012.  With 57 submissions there were only twelve slots for winners.  GRC 20/20 looked through all of the submissions, asked for clarification where needed, and selected the 12 recipients to receive this honor.

Number 12 is ControlPanelGRC's AutoAuditor which showed technology innovation for efficiencies in reporting. 

ControlPanelGRC’s AutoAuditor enables companies to be in a state of continuous audit readiness by automating manual reporting processes, and through its intuitive design AutoAuditor adapts to each company’s specific reporting demands. This turnkey solution automates repetitive report generation processes to push the report output to appropriate business or risk owners for review; by eliminating any additional training or tedious setup, once installed AutoAuditor pushes reports directly to those necessary resources rather than needing to be pulled. With AutoAuditor preparing for an audit no longer has to be major cause of stress that requires internal teams to spend weeks researching reports, collating spreadsheets and manually tracking down paper reports buried in filing cabinets. Business or risk owners perform the value add steps of reviewing the output and the workflow engine captures the signoff and exception documentation. The automatic check and balance system not only pushes the necessary report on cue, but also records the mandatory review, which is then automatically saved as future audit evidence. Value is achieved in eliminating human error, missed analysis opportunities, and subsequently, possible penalties if the processes are not executed on a timely basis.