Restructuring Third-Party Risk Management: Meeting Challenges with a Holistic Approach

The breadth of third-party risk management strategies and programs are undergoing a seismic shift within organizations. Over the past several months, I’ve observed a dramatic uptick in the number of organizations issuing requests for proposals (RFPs) for third-party risk management solutions and asking my advice on what solutions, services, and intelligence they should consider in these. This surge reflects a growing awareness of the need to rethink and restructure how businesses govern their extended enterprise. There are several RFPs that I have interacted on where I have flat out stated they need to look at different solutions as they ones they are down to will not deliver on the breadth and complexity of the program they are trying to achieve.

Driving this urgency is a wave of regulatory developments that are reshaping the expectations placed on organizations. The EU Corporate Sustainability Due Diligence Directive (CSDDD) looms large, demanding that companies actively manage sustainability risks across their supply chains. Meanwhile, the EU’s progress yesterday toward a Forced Labor Ban adds another layer of complexity, requiring businesses to ensure that forced labor has no place in their operations or those of their suppliers. These, and others, illustrate the demand for Environmental, Social, and Governance (ESG) assurance that is pressuring companies to provide transparency and accountability across their third-party relationships.

These dynamics have pushed organizations to move beyond siloed and reactive approaches to third-party risk management. Instead, they are embracing more integrated, holistic processes that can deliver greater transparency, agility, and resilience.

The Persistent Challenges of Third-Party Risk Management

Organizations are grappling with significant challenges in third-party risk management. These challenges are often rooted in scattered, siloed, outdated, and too often manual processes (or scattered solutions) that can no longer keep pace with today’s complex and fast-moving third-party risk environment.

One of the most pervasive issues is the fragmentation of data and processes. Many organizations still operate in silos, with different departments managing third-party risk independently. This makes it nearly impossible to achieve a unified view of third-party risks and creates redundancies that waste time and resources, and fail to deliver on holistic reporting that is required from things like EU DORA, EU CSRD / EU CSDDD, and more.

Adding to the complexity is the lack of real-time information. When data is scattered across disconnected systems, organizations are unable to identify and respond to emerging risks quickly. This problem is compounded by the difficulty of scaling traditional third-party risk management processes to accommodate growing ecosystems of suppliers, vendors, and partners.

Without integrated systems, even basic tasks like performance evaluations or compliance tracking become cumbersome. Audits and inspections, which are critical for maintaining accountability, often suffer from insufficient documentation and poor visibility into third-party activities. These gaps leave organizations vulnerable to both operational disruptions and regulatory penalties.

The Need for Modern Third-Party GRC Solutions

To meet these evolving demands, organizations are increasingly turning to modern Third-Party GRC (Governance, Risk, and Compliance) solutions. Modern Third-Party GRC platforms are designed to overcome these obstacles by providing a comprehensive, integrated approach to third-party risk management. These platforms do more than just automate the management of third-party relationships; they enable organizations to proactively govern and monitor risks across the lifecycle of their third-party engagements.

What makes these solutions so powerful is their ability to provide real-time insights into third-party performance, risk, and compliance. By integrating data from multiple sources and delivering it in a unified view, these platforms empower organizations to move away from reactive, fragmented processes and toward proactive, strategic decision-making.

For example, onboarding new third parties becomes faster and more thorough, with automated due diligence processes that ensure each supplier or partner meets regulatory and contractual standards. Ongoing monitoring ensures that risks are continuously evaluated, while regular audits and inspections verify that third parties remain compliant throughout the relationship. Even the process of offboarding—a phase often overlooked—becomes more structured, reducing the risk of data breaches or unresolved compliance issues when a relationship ends.

By providing these capabilities, Third-Party GRC solutions not only streamline operations but also ensure alignment with broader organizational objectives, such as sustainability, ethical sourcing, and resilience.

At the core of these solutions is the ability to unify data and processes across the organization. By breaking down silos, these platforms create a single source of truth for third-party risks, performance, and compliance. This integration not only improves efficiency but also enables more strategic decision-making.

Another key strength of these solutions is their real-time monitoring capabilities. Whether it’s tracking key performance indicators (KPIs) or conducting periodic risk assessments, organizations gain the ability to continuously evaluate their third-party relationships. This ensures that risks are identified and addressed before they escalate into major issues.

Automation is another critical feature. By automating routine tasks like due diligence and compliance tracking, these platforms reduce the burden on internal teams and free up resources for more strategic activities. For example, automated due diligence processes can flag potential red flags, such as connections to politically exposed persons or adverse media coverage, while ensuring that all third-party interactions are thoroughly documented.

The NEED for Integration of Third-Party Risk Intelligence

What sets today’s leading Third-Party GRC solutions apart is their integration with third-party risk intelligence services. These integrations allow organizations to tap into a wealth of external data that enhances their ability to assess and manage risks.

For instance, platforms can provide real-time updates on watch lists, sanctions, and negative news, enabling organizations to respond swiftly to potential threats. They can also deliver insights into security and financial viability ratings, helping companies make informed decisions about their third-party engagements. And as ESG becomes a critical area of focus, many platforms now offer detailed ESG ratings and compliance data, ensuring that third-party relationships align with organizational values and regulatory requirements.

Preparing for the Future: The Business Case for Third-Party GRC

Investing in a Third-Party GRC solution delivers tangible benefits that extend beyond compliance. These platforms drive efficiency by automating manual processes and reducing redundancies. They enhance effectiveness by providing a comprehensive view of third-party risks and ensuring accountability at every stage of the relationship.

Moreover, Third-Party GRC solutions strengthen organizational resilience by enabling proactive risk management. By identifying and addressing risks early, companies can avoid costly disruptions and maintain business continuity. Finally, these solutions provide the agility needed to adapt to an ever-changing regulatory environment, ensuring that organizations remain compliant even as new challenges emerge.

The regulatory landscape is only becoming more complex, and the risks associated with third-party relationships are growing in both scale and scope. The introduction of measures like the EU CSDDD and the Forced Labor Ban is a clear signal that organizations can no longer afford to take a reactive approach to third-party risk management.

By adopting modern Third-Party GRC solutions, businesses can position themselves to navigate these challenges with confidence. These platforms provide the tools needed to not only meet regulatory requirements but also build stronger, more resilient third-party ecosystems.

As organizations restructure their approaches to third-party risk management, the emphasis must be on creating processes that are not only efficient and effective but also aligned with their broader values and goals. In doing so, they can turn third-party risk management from a compliance burden into a strategic advantage.

6 Ways to Create a Repeatable, Scalable Compliance Program

Compliance programs are critical in ensuring organizations adhere to established regulations, laws, and ethical standards, fostering trust with stakeholders, employees, business partners, and the public. A repeatable and scalable compliance program ensures consistency and efficiency in managing compliance risks across various operational scales and ensures compliance in the context of regulatory/obligation and business change. Organizations across industries and sizes must create a compliance program that meets the legal requisites and is repeatable and scalable in a dynamic, distributed, and ever-changing business environment.

What’s Required to Establish a Successful Compliance Program?

Creating a scalable and repeatable compliance program requires . . .

[The rest of this blog can be read on the SimpleRisk blog, where GRC 20/20’s Michael Rasmussen is a guest author]

Where Policy Management Fails

After exploring Where Third-Party Risk Management Fails and Where Risk Management Fails, I now turn my attention to my biggest soapbox, Where Policy Management Fails . . .

First it is essential to understand that policies are critically important to governance, risk management, and compliance. Through policies organizations can have reliable processes, transactions, and behavior so it can reliably achieve objectives [governance]. Policies are risk documents, the very fact that there is a policy means there is uncertainty/risk that needs to be governed and controlled [risk management]. Through policies, and their adherence, the organization maintains integrity to its values, ethics, conduct, ESG commitments, regulatory commitments, and contractual commitments [compliance].

HOWEVER, policies also set a legal duty of care and liability on the organization. A policy that is not followed can be used against the organization in a civil, criminal, and/or regulatory matter. What is shocking is how badly policies are managed in the organization given their critical nature to enable the organization to reliably achieve objectives, address uncertainty, and act with integrity. 

I teach Policy Management by Design workshops around the world and have a variety of research papers on policy management. I have also partnered with OCEG in developing PolicyManagementPro.com and the Certified Policy Management Professional certification. Here is where I see policy management fails in many organizations . . .

  • Not knowing what policies the organization has. Policies often are scattered across departments and many organizations do not even know what policies are out there. I was keynoting at a conference and asked a few hundred people in the room who has a master list of all their official policies, only two people raised their hands.
  • Policies scattered on different portals. Too often the organization does not have a singular portal for policies. One insurance company came to me moving into pandemic lockdowns in March of 2020 in a panic as they discovered they had 27 different policy portals from policy file shares to SharePoint sites, to commercial software. It was a maze of confusion and there was no singular point for employees to access policies.
  • Different writing styles and processes. Organizations often do not have a consistent template and writing style for policies, not a standard process to write and approve policies. Basically, they do not have a Policy on Writing Policies (also called a Metapolicy) nor a style guide on how to write policies in consistent grammar, use of active voice, punctuation, formatting, and how to approach gender neutral language. 
  • No standard template for a policy. Yes, I brought this out in the previous point, but it deserves to be mentioned again. Anyone should be able to recognize a policy by the template/formatting of the document (digitally or in print). It should be easily recognizable as an official policy.
  • Not addressing rogue policies. This is a HUGE issue. Too often managers across the organization are opening word processors and writing documents and calling them policies. They communicate this to employees, customers, and partners. Policies, as stated, establish a legal duty of care. If a manager is writing a document and calling it a policy, it exposes the organization to legal liability if it is not followed. 
  • Out of date policies. Organizations struggle with the number of policies that exist indefinitely and are not updated, lack an owner, and are no longer needed . . . or desperately need revision. 
  • Not keeping up with legal, regulatory, and business change. There is a variety of legal, regulatory, risk, and even business change that impacts policies. One bank had a policy that was being revised because of a regulatory change that went through 75 reviewers in a linear fashion of document check in and check out and took six months to get updated. In an industry where there are 257 regulatory change events every day this certainly is not agile and behind the game. Another organization, this one in healthcare, discovered they had 21,000 policy and procedure documents because of all the consolidation and acquisition of hospitals over a few decades. 
  • Not keeping up with employee change. Employees come into the organization, they change roles and departments, they leave the organization. Organizations need to ensure that employees are aware of the policies that apply to their role as they move to different functions and roles, particularly high-risk areas. 
  • Lack of audit trail and system of record. This is another HUGE issue. The legal and regulatory environment demand that the organization have a clear defensible history of what policies were communicated to employees, did they understand it, were they trained, how they were reminded. Look at the latest U.S. Department of Justice Evaluation of Compliance Programs where it focuses on the audit trail and system of record of the policy portal and employee interactions. Having a defensible audit trail on policies and awareness gets the organization out of hot water, ask Morgan Stanley.
  • Outdated policy portals and training. Every month I am getting inquiries from organizations looking for that next generation policy portal that brings together policies and training into one portal. Think about it, employees go out to Facebook and can watch a YouTube video in Facebook. They do not have to click on a link and go out to YouTube and come back to Facebook to comment on it. The same thing NEEDS to happen with the policy portal that brings policies and training on policies into one portal. Millennials and Gen Z expect this. And, mobility access to policies and training is also critical. 

As you can see, this is a soapbox of mine. I am passionate about policies and policy management. They are critical to the organization. Without policies, and policies that are adhered to and enforced, the organization’s behavior is like leaves blowing in the wind. Can you imagine an organization with no policies? What a mess of transactions and behavior. I am literally scratching the surface on all the areas of where policy management fails today. 

Organizations need to address the back-office of policy management, and the front-office of policy engagement . . .

  • Back-office policy management. This is the enterprise-wide consistent process to write, approve, monitor, enforce, manage, maintain, and audit policies in the organization. They key here is collaborative authoring and cooperation across departments supported by strong technology in this space to ensure nothing slips through the cracks and adheres to the Policy on Writing Policies.
  • Front-office policy engagement. This is the portal, training, awareness, and engagement to employees (and third parties) on policies. There should be a singular portal for all the official policies of the organization. Employees should have regular reminders and are properly aware and trained on policies that impact their role/function in the organization.

There are a variety of solutions for policy management in the market. Some focus on certain departments (e.g., EH&S, information security, privacy, HR), others focus on specific industries (e.g., healthcare, banking), and others are broad. Some solutions focus on back-office policy management, others excel in front-office policy engagement. Few do both well. 

Ask GRC 20/20 about our market research and coverage of policy management best practices and the range solutions in the market and what differentiates them and fits your particular need . . . 

Also, register for one of these upcoming webinars on Effective Policy Management . . .

3 GRC Priorities for Your Organization in 2022

The past two years have been a trial for organizations as they have been required to respond to the complications, risks, and intricacies of the pandemic and its impact on business strategy, operations, and objectives.

The focus has been on resiliency with the ability to recover quickly to changing risk conditions to keep the organization moving forward.

GRC, by definition, is a capability to reliably achieve objectives (governance), address uncertainty (risk management), and act with integrity (compliance) (source: OCEG GRC Capability Model).

The organization must be constantly aware of objectives and their achievement. Those objectives can be at the entity level or down into the division, department, process, project, relationship, or asset level. In this context, the organization needs insight into the risk and uncertainty in achieving those objectives and ensure that the organization acts with integrity in their achievement in a distributed, dynamic, and disrupted business environment.

As we head into 2022, this focus on . . .

[THE REST OF THIS ARTICLE CAN BE FOUND ON THE MITRATECH BLOG WHERE GRC 20/20’S MICHAEL RASMUSSEN IS A GUEST AUTHOR]

Tale of Two Futures: Blade Runner or Star Trek?

It was the best of times, it was the worst of times, it was the age of wisdom, it was the age of foolishness, it was the epoch of belief, it was the epoch of incredulity, it was the season of Light, it was the season of Darkness, it was the spring of hope, it was the winter of despair, we had everything before us, we had nothing before us, we were all going direct to Heaven, we were all going direct the other way – in short, the period was so far like the present period, that some of its noisiest authorities insisted on its being received, for good or for evil, in the superlative degree of comparison only.

Charles Dickens, A Tale of Two Cities (1859)

I love good literature and Charles Dickens is a favorite, particularly in the Christmas season. However, my thoughts right now are not on A Christmas Carol but on the haunting intro to A Tale of Two Cities. Charles Dickens’s evocative words come to mind as I think about enterprise risk management programs in organizations. We are at a nexus of paths right now that can lead to two very different outcomes for the future of the world, our organizations, and our personal lives.

My question for you: are we focused on the right risks?

The truth is that we are at a critical point in history, a point that can lead to two very different outcomes. In our age of technology advancement and knowledge will this be defined as the ‘age of wisdom?’ Or will it be seen as the ‘age of foolishness?’ The decisions we make and our organization’s make will lead us to a ‘season of light’ or a ‘season of darkness,’ either a ‘spring of hope’ or a winter of despair.’

In my keynotes and presentations, I ask the question: what is our future? 

Are we, as a global society that our organizations are part of, headed toward a Blade Runner future or a Star Trek future? In Blade Runner, you have a dark dystopia of social, ethical, and environmental disasters. In Star Trek, you see a green and prospering world where the environment and society thrive, and there is great social diversity and cooperation across galactic races.

My issue is that many of the enterprise risk management and GRC programs I interact with are limited in scope. If you look at these programs you would think that IT/information risk (e.g, cyber risk, digital risk) are the greatest concern. These are significant concerns, I am not trying to deny that. I cut my teeth in risk management in the 90’s in information security. My point of view is that IT/information risk is a great concern, but environmental risks are a GRAVE concern. And I mean that term literally. But environmental risk seems to be missing from the agenda of the organization’s enterprise risk, operational risk, integrated risk, and GRC agendas.

Look at the World Economic Forum’s Global Risks Landscape 2019. The most significant risks, and there are many, are environmental in focus. Where is this on the organization’s risk management agenda? Fortunately, we are seeing some changes here. I applaud the United Kingdom’s FCA/PRA that is now requiring banks and insurance companies, under the Senior Manager’s Regime/Certification Regime (UK SMCR), to have a senior management function defined and accountable to manage the firm’s risk from climate change.

It is disappointing that the leading analyst firms, Gartner and Forrester, do not cover environmental, health and safety risks in their IRM and GRC research. They are ostriches with their heads in the sand. Both of these firms talk about environmental risk and climate change in other parts of their organization, but it does not appear to be on the radar of their core research in IRM and GRC. Reading IRM and GRC reports from these analysts would leave one to think that environmental risk and climate change are not even on the radar and what we only need to focus on is IT/information risk. While Verdantix, in their Green Quadrant on Operational Risk, has a completely different set of solutions, with only two that appear on the Forrester reports and one on the Gartner report. Fortunately, with OCEG and GRC Capability Model, we have taken a true enterprise view of risk that includes environmental, health and safety, quality, and other risks that Gartner and Forrester do not see as part of their IRM and GRC research. How can a research organization in 2020 have a risk management strategy that does not include these areas? How can organizations themselves not be covering environmental risk in their enterprise and operational risk management programs?

CALL TO ACTION: it is time that our GRC/ERM programs include and integrate with ESG (environmental, social, governance), EHS (environmental, health and safety), CSR (corporate social responsibility), and sustainability initiatives. 

The reality is that organizations do need a true enterprise view of risk, and this view must include environmental risk and climate change impact on the business as well as health and safety risks. IT/information risk is critical, but it is time to ensure that environmental risk is on the radar as well in enterprise risk management programs. If we do not address this now our future will be Blade Runner and not Star Trek as we head to a ‘winter of despair’ and not a ‘spring of hope.’

Have You Hugged Your CECO/CCO Today?

Today is the official National Compliance Officer today! This is a very challenging role in organizations and one that is in the midst of a lot of change. Below is a link to my SWOT Analysis of the CECO role on this topic. I am presenting on this next week at Converge19 as well.

Here is a link with Tom Fox on his podcast discussing my upcoming presentation on the SWOT Analysis of the CECO

Understanding Third Party GRC Maturity: Defined Stage

A haphazard department and document centric approach for third party GRC compounds the problem and does not solve it. It is time for organizations to step back and mature their third party GRC approaches with a cross-functional and coordinated strategy and team to define and govern third party relationships. Organizations need to mature their third party governance with an integrated strategy, process, and architecture to manage the ecosystem of third party relationships with real-time information about third party performance, risk, and compliance, as well as how it impacts the organization.

GRC 20/20 has developed the Third Party GRC Maturity Model to articulate maturity in the Third Party GRC processes and provide organizations with a roadmap to support acceleration through their maturity journey.

There are five stages to the model:

  1. Ad Hoc
  2. Fragmented
  3. Defined
  4. Integrated
  5. Agile

Today we look at Stage 3, the Defined level of Third Party GRC

The Defined stage suggests that the organization has some areas of third-party GRC that are managed well at a department level, but it lacks . . .

[this is a guest blog authored by Michael Rasmussen of GRC 20/20 that can be found at Aravo site, follow the link below to read more]

The Rhythm of Risk: Managing Risk Throughout the Context of Business

Writing about risk management is like trying to have an intelligent conversation today about religion or politics.

Individuals in the risk management community have polarized views and if someone does not agree with you 100% you end up in the crosshairs of an attack. It is sad. Instead of intelligent discussion where we can come together and learn, there are many ready to pounce if you do not express their exact ideology. Some view risk management as purely top-down from objectives and strategy, others are risk professionals down in the bowels of the organization looking bottom-up. Some feel that risk registers, risk appetite, and other aspects of traditional risk management are meaningless, others see this as the core part of how they have managed risk. Some hate heat maps and qualitative approaches, others live by them. Some, I feel, are simply trying to relabel corporate performance management to be risk management, instead of seeing that risk management is a part of performance management.

While I feel there is objective truth when it comes to matters of religion/theology . . . what if that was not the case for risk management?

  • What if the best approach to risk management brought together the top-down and the bottom-up?
  • Used both quantitative and qualitative methods?
  • Leverages risk registers but does not get locked into thinking only in their context?
  • Knew the weaknesses of a heatmap and how to overcome them while still using them as a visualization tool?

My view of risk management is that all sides of the debate have something valid to bring to the table. To truly do enterprise risk management requires a 360° contextual awareness of risk in the context of performance, objectives, and strategy as well as day to day operations and hazards of the business. Organizations need both a top-down view of risk management in the context of strategy and objectives as well as a bottom-up view of risk down in the weeds of operations and hazards. Good risk management requires both.

My favorite approach to risk management I have encountered in my research was with Microsoft when Brad Jewett was the ERM Director there from 2003 to 2008 (I cannot speak to Microsoft today as I have not interacted with them recently, Brad is now the CFO of Corel Corporation). I have served with Brad as an OCEG Fellow over the years and have a deep respect for him as a risk management professional. Brad defined his approach to risk management at Micorosft as ‘The Rhythm of Risk.’ This he defined by his desire to integrate risk management into daily decision making that would follow the corporate calendar for key processes such as multi-year strategic planning, annual planning, mergers and acquisitions, audit planning, SEC reporting, investor communications, product and service roadmaps, etc. It an aspirational agenda but it set the tone and expectation that risk management was a priority that should Influence and be integrated into the way things get done every day. This included the strategic as well as the operational. The top-down as well as the bottom-up

To maintain the integrity of the organization and execute on strategy, the organization has to be able to see the individual risk (the tree), as well as the interconnectedness of risk to strategy and objecrtives (the forest). Many organizations are asking for this to go even deeper, as they need to see the leaf and branch as it connects to the tree, and how it is part of the forest.

Risk management in business is non-linear. It is not a simple equation of 1 + 1 = 2. It is a mesh of exponential, and sometimes chaotic, relationships and impacts in which 1 + 1 = 3, 30, or 300. What seems like a small disruption or exposure may have a massive effect or no effect at all. In a linear system the effect is proportional with cause, in the non-linear world of business, risks are exponential. Business is chaos theory realized. The small flutter of risk exposure can bring down the organization. If we fail to see the interconnections of risk on the non-linear world of business, the result is often exponential to unpredictable.

Mature risk management enables the organization to understand performance in the context of risk. It can weigh multiple inputs from both top-down view of risk to objectives as well as a bottom-up view of risk within operations and processes. It can integrate internal and external contexts, and use a variety of methods to analyze risk and provide qualitative and quantitative modeling.

Successful risk management requires the organization to provide an integrated process and information architecture. This helps to identify, analyze, manage, and monitor risk, and capture changes in the organization’s risk profile from internal and external events as they occur. Mature risk-management is a seamless part of governance and operations. It requires the organization to take a top-down view of risk, led by the executives and the board that is not an unattached layer of oversight. It also involves bottom-up participation where business functions at all levels identify and monitor uncertainty and the impact of risk down in the depth of the business.

Organizations striving to increase risk management maturity in their organization need to be:

  • Aware. They need to have a finger on the pulse of the business and watch for changes in the internal and external environments that introduce risk. Key to this is the ability to turn data into information that can be, and is, analyzed and shareable in every relevant direction.
  • Aligned. They need to align performance and risk management to support and inform business objectives. This requires continuously aligning objectives and operations of risk management to the objectives and operations of the entity, and to give strategic consideration to information from the risk management capability to affect appropriate change.
  • Responsive. Organizations cannot react to something they do not sense. Mature risk management is focused on gaining greater awareness and understanding of information that drives decisions and actions, improves transparency, but also quickly cuts through the morass of data to what an organization needs to know to make the right decisions. This requires that the organization have a bottoms-up view of risk as well as the top-down.
  • Agile. Stakeholders desire the organization to be more than fast; they require it to be nimble. Being fast isn’t helpful if the organization is headed in the wrong direction. Mature risk management enables decisions and actions that are quick, coordinated, and well thought out. Agility allows an entity to use risk to its advantage, grasp strategic opportunities, and be confident in its ability to stay on course.
  • Resilient. The best-laid plans of mice and men fail. Organizations need to be able to bounce back quickly from changes in context and risks with limited business impact. They desire to have sufficient tolerances to allow for some missteps and have the confidence necessary to rapidly adapt and respond to opportunities.
  • Efficient. They want to build business muscle and trim fat to rid expense from unnecessary duplication, redundancy, and misallocation of resources; to make the organization leaner overall with enhanced capability and related decisions about the application of resources.

My point is simple, there are many perspectives on risk management that brought together properly and in balance can really build an effective and mature risk management program. While there are issues with qualitative methods, heat maps, and risk registers, that does not mean they are useless. They need to be effectively used and their issues and weaknesses understood. The same goes for a complete top-down view of risk management that only focuses on objectives and misses the hazards and issues that lie in the depths of the weeds of the organization that can cause significant harm. The best world is one that brings the strengths of all of these together and avoided throwing the baby out with the bathwater.

I will be presenting my views on how risk management technology enables and mature risk management capabilities in the webinar tomorrow:

I will be presenting my views on how organizations can mature their risk management capability in the webinar this Wednesday:

GRC 20/20 also has the upcoming Risk Management by Design Workshops:

GRC 20/20 has also just updated it’s flagship research paper on this topic:

Michael Rasmussen on GRC value & creating your GRC RFP template

What do you need to include in a GRC RFP? We asked one of the experts in this interview.

Enterprise governance, risk, and compliance (GRC) strategies can help organizations across the board become more efficient and agile in navigating the ever-changing regulatory and risk environment. However, in order to maximize efficiency, effectiveness, and agility, organizations need to approach GRC with a collaborative, inter-departmental strategy.To make GRC software implementation as strong as possible, organizations should have a clear business case, strategy with defined goals, and detailed system requirements.

We sat down with Michael Rasmussen of GRC 20/20 to talk about the components of a successful GRC business case and strategy, how to understand the range of GRC capabilities, how to navigate selecting a solution, and what to include in a GRC RFP. Here are some of his responses.

The value of GRC

Eric Goldberg: How do we go about articulating the value, or the ROI, of a GRC strategy?

Michael Rasmussen: It starts with finding . . .

[This is an interview done with Galvanize, the rest of this post can be found through the button link below]

Step 2: Conditioning is Critical, Make Sure Your Team and Systems are Ready for 3rd Party GRC

This is the 2nd blog in a 5-part series on developing a strategic plan for Third Party Governance/Management in your organization.

With an understanding of where you are at and where you want to go with 3rd Party Governance, the next step is to make sure your team and systems are ready for the journey. The physicist, Fritjof Capra, made an insightful observation on living organisms and ecosystems that also rings true when applied to 3rd Party Governance, Risk Management, and Compliance (3rd Party GRC): 

“The more we study the major problems of our time, the more we come to realize that they cannot be understood in isolation. They are systemic problems, which means that they are interconnected and interdependent.”[1]

Capra’s point is that biological ecosystems are complex and interconnected and require a holistic understanding of the intricacy in interrelationship as an integrated whole rather than a dissociated collection of parts.  Change in one segment of an ecosystem has cascading effects and impacts to the entire ecosystem.  This is true in 3rd Party GRC. What further complicates this is the exponential effect of 3rd party risk on the organization.  Business operates in a world of chaos.  Applying chaos theory to business is like the ‘butterfly effect’ in which the simple flutter of a butterfly’s wings creates tiny changes in the atmosphere that could ultimately impact the development and path of a hurricane. A small event cascades, develops, and influences what ends up being a significant issue. Dissociated data, systems, and processes leaves the organization with fragments of truth that fail to see the big picture of 3rd party performance, risk, and compliance across the enterprise and how it supports the organization’s strategy and objectives.

The organization needs to have holistic visibility and situational awareness into 3rd party relationships across the enterprise. Complexity of business and intricacy and interconnectedness of third party data requires that the organization implement a third party management strategy. 

The primary directive of a mature 3rd Party GRC program is to deliver effectiveness, efficiency, and agility to the business in managing the breadth of 3rd party relationships in context of performance, risk, and compliance. This requires a strategy that connects the enterprise, business units, processes, transactions, and information to enable transparency, discipline, and control of the ecosystem of third parties across the extended enterprise.

Organizations need to ensure that the various departments and roles involved in governing 3rd party relationships are on board and willing to work together in a cohesive strategy. The goal is to provide the greatest balance in collaborative 3rd party governance and oversight to allow for some department/business function autonomy where needed, but focuses on a common governance model and alignment that the various groups in 3rd party governance utilize. A federated approach increases the ability to connect, understand, analyze, and monitor interrelationships and underlying patterns of performance, risk, and compliance across 3rd party relationships, as it allows different business functions to be focused on their areas while reporting into a common governance framework and architecture. Different functions participate in third party management with a focus on coordination and collaboration through a common core architecture that integrates and plays well with other systems.

The goal is to have centralized 3rd party governance oversight to create consistent and aligned strategy with a common 3rd party governance process, information and technology architecture. Organizations with this collaborative approach report process efficiencies reducing human and financial capital requirements, greater agility to understand and report on third party performance, risk and compliance, and greater effectiveness through the ability to report and analyze 3rd party risk and compliance data. The goal should not only to manage risk and compliance, but to integrate 3rd party governance in the context of performance, objectives, and strategy in relationships.

To achieve the full benefits from an 3rd party GRC strategy, GRC 20/20 recommends the following next steps:

  • Gain executive support and sponsorship of the third party governance strategy.The organization needs to work in harmony on third party governance. Different groups doing their own thing handicap the business. Executive support is critical to align the organization.
  • Develop harmonized systems and processes. Key to success is identification of shared processes and information for 3rd party GRC across the enterprise. This includes identifying technology and information solutions to support integrated information and process architecture.

This team needs to be aligned to share a common vision to move to an integrated approach to 3rd party GRC across the business that includes an understanding of risk and compliance in context of performance and objectives in third party relationships.

[1]Fritjof Capra, The Web of Life: A New Scientific Understanding of Living Systems (New York: Anchor Books, 1996), 3.

Supporting 3rd Party GRC Research . . .

GRC 20/20 has defined this in our key research paper (currently being revised):

GRC 20/20 is also presenting on how to build a business case for and evaluate the range of 3rd Party GRC solutions in the market:

GRC 20/20 is also facilitating several upcoming workshops on this topic as well:

Other Case Studies, Strategy Perspectives, and Solution Perspectives on Third Party GRC can be found here.