Upcoming Events . . .

Latest Pontifications & Thoughts . . .

  • GRC 3.0 – A History of GRC

    GRC is “a capability to reliably achieve objectives while addressing uncertainty and acting with integrity."  The reliable achievement of objectives is the governance piece, addressing uncertainty is about risk management,… Continue reading GRC 3.0 – A History of GRC

  • 3rd Party Management in Financial Services

    Regulators such as the OCC, FDIC, CFPB, and NCUA are honing in on the financial services industry and, specifically, their oversight of 3rd party relationships – including vendors. Given the changes in the… Continue reading 3rd Party Management in Financial Services

  • GRC 20/20 is Clarity of GRC Vision

    This is the busiest I have ever been as a GRC analyst and market researcher.  Lot's of RFPs and projects happening, in fact tracking several dozen current RFP and GRC… Continue reading GRC 20/20 is Clarity of GRC Vision

  • Compliance & Ethics in the Year 2020

    Compliance and ethics is not the same today as it was a few years ago, and it’s safe to say that it will continue to evolve in 2020. In the… Continue reading Compliance & Ethics in the Year 2020

  • Michael Rasmussen, The GRC Pundit

    Michael Rasmussen is an internationally recognized pundit on governance, risk management, and compliance (GRC) – with specific expertise on enterprise GRC strategy and processes supported by robust information and technology… Continue reading Michael Rasmussen, The GRC Pundit

  • 2013 GRC Drivers & Trends

    With March upon us, 2013 is well underway. GRC related activities – process and technology – is increasing as organizations look for better ways to do things while they face… Continue reading 2013 GRC Drivers & Trends

  • Defining a GRC Strategy and Blueprint that Bridges GRC Silos

    Governance, risk, and compliance (GRC) is not a single role in the organization. Effective GRC requires collaboration across business areas that have historically operated as introverted silos. This comprehensive three-hour… Continue reading Defining a GRC Strategy and Blueprint that Bridges GRC Silos

  • Wrapping Up Effective Policy Management Loose Ends

    Many of you have closely followed my commentary over the past few years on Effective Policy Management and its role in a broader GRC architecture. It is apparent that I… Continue reading Wrapping Up Effective Policy Management Loose Ends

  • 2013 GRC Technology Innovation Awards

    GRC and technology. Every organization does GRC, not every organization does GRC well.  You will not find an organization that states it lacks governance, does not care about risk, and… Continue reading 2013 GRC Technology Innovation Awards

  • 1 – The GRC Marketplace: the Force.com of GRC, MetricStream’s Zaplet

    The 2013 GRC Technology Innovator awards was filled with competition.  The number of submissions more than doubled over 2012.  With 57 submissions there were only twelve slots for winners.  GRC… Continue reading 1 – The GRC Marketplace: the Force.com of GRC, MetricStream’s Zaplet

  • 2 – Risk collaboration: socializing risk in the enterprise, Riskflo’s Discovery™

    The 2013 GRC Technology Innovator awards was filled with competition.  The number of submissions more than doubled over 2012.  With 57 submissions there were only twelve slots for winners.  GRC… Continue reading 2 – Risk collaboration: socializing risk in the enterprise, Riskflo’s Discovery™