Now Accepting 2015 GRC Innovation Award Nominations

2015-GRC-Innovation-Award

GRC 20/20 is accepting nominations for the 2015 GRC Innovation Awards!

It has been stated that:

Any intelligent fool can make things bigger, more complex and more violent. It takes a touch of genius – and a lot of courage to move in the opposite direction. 

A primary directive of innovation is to provide experience that is simple yet complete. Like Apple with its innovative technologies, GRC solutions must approach solutions in a way that re-architects the way it works as well as the way it interacts. The goal is simple; it is itself Simplicity. Simplicity is often equated with minimalism. Yet true simplicity is more than just absence of clutter or removal of embellishment. It’s about offering up the right context, in the right place, when needed. It’s about bringing interaction and engagement to GRC process and information. GRC solutions should be intuitive.

2015 GRC Innovation Award nominations will be accepted through July 12th (no exceptions, nomination form closes down at midnight CDT on July 12th).

NOTE: the 2015 GRC Value Award process (our other award process) will begin on August 1st. Nominations have to be in before the end of August.  Recipients will be determined by end of October with announcements in November.

To establish a proper perspective, please understand what the GRC Innovations Awards are NOT:

  • It is NOT to recognize how one product has a better feature or feature set than a competitor
  • It is NOT to recognize competitive differentiators
  • It is NOT like a comparison or endorsement of solutions overall (like a Forrester Wave of Gartner Magic Quadrant)

The GRC Innovation Awards are to recognize innovations in GRC related solutions that are revolutionizing Governance, Risk Management, and Compliance (GRC).  GRC Innovation Awards are to recognize  solutions that show something truly unique, game changing, revolutionary, and new. If what you are proposing has been in your feature set for more than 12 months – it is not new and fresh.

The 2015 GRC Innovation Awards are considered across 17 categories of GRC functional areas and from two perspectives in each.  The two perspectives awards can be submitted from are:

  • User Interface & Experience. GRC 20/20 is putting specific focus on the fact that GRC solutions do not have to be ugly and cumbersome.
  • Other Innovation. Any innovation that is not tied to user interface & experience.

The seventeen categories for submission are:

  • Audit Solutions
  • Automated / Continuous Control Management
  • Business Continuity Solutions
  • Compliance Management Solutions
  • Enterprise GRC Architecture & Platforms
  • Environmental, Health &; Safety Solutions
  • Information & Technology GRC Solutions
  • Internal Control Management Solutions
  • Issue Reporting & Case Management Solutions
  • Legal Management Solutions
  • Physical Security Solutions
  • Policy & Training Solutions
  • Quality Management Solutions
  • Reputation & Responsibility Management Solutions
  • Risk Management Solutions
  • Strategy & Performance Management Solutions
  • Third Party Management Solutions

To be innovative requires that the submission be game changing and completely unique from what the competition is doing. Any submission that is just another “me too,” or “we are better than the rest” type of submission will not cut it and will quickly go to the digital trash bin.  We want to recognize vendors that are thinking outside of the box to boldly take GRC where no solution provider has gone before.

Please submit nominations before midnight on July 12, 2015.  Nomination forms will be reviewed in July, finalists selected and deeper dives in August, with recipients selected by end of August and announced in early September.  Award recipients will be announced to vendors at the end of August so that coordinated announcements/press releases can go out in the beginning of September.

[button link=”http://grc2020test.cloudaccess.host/2015-grc-innovation-award-nomination-form/” color=”default”]NOMINATION FORM[/button]

2014 GRC Technology Innovation Award: ACL Integrates Automated GRC Monitoring with Proactive Surveys & Questionnaires

The 2014 GRC Technology Innovation Awards was filled with competition.   Nominations increased to 62 over last year’s awards, and fifteen winners were selected.  GRC 20/20 looked through all of the submissions, asked for clarification where needed, and selected 15 recipients that demonstrated outside the box thinking in taking GRC in new directions to receive this year’s award.

ACL Integrates Automated GRC Monitoring with Proactive Surveys & Questionnaires

In November 2013, ACL delivered an innovation that combines the concepts of management assurance and audit assurance to structurally shift what is considered “data” in the context of measuring risk and control activities in assurance activities. They have created an intuitive and elegant approach to combine data analytics with surveys and questionnaires to provide stronger assurance and automation.

At a tactical level, this innovation revolutionizes the way a GRC professional is able to address problems around control monitoring, compliance violations, and policy violation. It meaningfully blends the capabilities of data analytics with surveying to provide the analyst with a simple, integrated toolkit for monitoring and remediation.

At a strategic level, this innovation structurally shifts and aligns “human data” with “systems data”, effectively allowing the GRC analyst to treat populations of people as a data source. With the ability to seamlessly blend “human data” with “systems data”, a new world of analysis is possible to identify red flags, as well as serve as the basis for rich visualization of blended data.

Prior to this innovation, control monitoring and other data analytics were loosely integrated into broader GRC risk & control platforms and GRC architecture. Results of analytics were often simply attached as files to serves as control evidence. This new approach fully integrates into a unified GRC architecture with analytics so GRC evaluations, assessments, and decisions can be made seamlessly in real-time using the most up-to-date information available in the organization. Introducing the surveying/questionnaire piece allows ACL users to feed the same control monitoring engine with survey data (“human data”) and drive the same remediation actions as could be done from transactional data.

The core functionality of the technology is to take the results of control monitoring analytics and bring those into a centralized, easy-to-use web environment where it is integrated into the overall GRC information and process architecture. It provides an intuitive questionnaire builder to develop questionnaires when a “trigger” condition happens that allows for automatic triggering of questionnaires based on data analysis criteria. It blends data analysis records with the questionnaire results to provide a consolidated dataset that the organization may use to drive remediation, act as control evidence, or provide executive reporting.

The key technical functionality is the “Big Data” engine that lies at the heart of the ACL GRC Results Manager module. This data engine uses an innovative data store that is capable of storing unstructured and arbitrary data. This is critical for several reasons but primarily because 1) organization need to analyze different types of data that a traditional database system cannot effectively ingest the “arbitrary” data needed for analysis, 2) these organizations need to be able to “blend” a transaction record with a survey response on the fly without doing traditional database table joins, and 3) the ability operate at cloud scale to drive the fastest performance and response times. Layered on top of the big data engine is ACL GRC’s development stack and intuitive user interface built in HTML5, CSS3, and high performance JavaScript. The overall solution is not just functional on a new level but brilliant in its intuitiveness and ease of use.

To learn more about the GRC 20/20 2014 GRC Innovation Awards and other recipients, please visit this post: GRC 20/20 Announces 2014 GRC Innovation Award Recipients

2014 GRC Technology Innovation Award: ACL Goes Mobile with the Most Complete and Intuitive Mobile Interface for GRC

The 2014 GRC Technology Innovation Awards was filled with competition.   Nominations increased to 62 over last year’s awards, and fifteen winners were selected.  GRC 20/20 looked through all of the submissions, asked for clarification where needed, and selected15 recipients that demonstrated outside the box thinking in taking GRC in new directions to receive this year’s award.

ACL Goes Mobile with the Most Complete and Intuitive Mobile Interface for GRC

ACL has brought end-to-end audit management functionality to Apple mobile devices in the form of a native mobile app, used in conjunction with their cloud-based GRC and audit management platform. The ability to leverage a native app (not mobile web or low-fidelity “hybrid” type applications) enables ACL to make full use of the hardware capabilities of Apple mobile devices including:

  • User Interface.  Touch, gestures, responsiveness, hardware rotation, etc.
  • Multimedia evidence capture. Create and attach photos, videos, sound recordings, geo-location, etc. from within an audit procedure, control walkthrough, control test, etc.
  • Scan to PDF. Use the app to “scan” hard copy documents directly into the system without leaving a given audit step or control test by taking a picture of the document. The app’s PDF generation engine will automatically convert to a document-quality PDF.
  • Cloud connected. Built to enable connectivity and integration to their native multi-tenant software as a service ACL GRC platform so that none of the typical connectivity challenges to on premise server infrastructures impede easy access and use.

This is the first GRC mobile app to bring the full power of design delivered through powerful and capable devices, to the problem of audit management. GRC 20/20 sees a major shift beginning occurring where document, spreadsheets, and paper binders are being replaced by multimedia including audio, video, photo, data visualization, geo-location, etc.

There are many GRC mobile solutions on the market – but they offer limited functionality and do not always take full advantage of the native mobile environment. ACL has now fully engaged the capability of the device to leverage multimedia capabilities of the devices as well as redesigned the application from the ground-up to take advantage of the incredible power available in the iOS SDK. The platform was expanded to enable complete enterprise risk assessment and reporting in a fully touch interactive environment.

The historic reality after fieldwork finished there would be an additional two weeks of work to be completed compiling notes, transcribing, documenting, etc. after leaving the field, then another two weeks of report writing and revisions. Progressively leveraging ACL GRC for iOS and its multimedia capability, the auditors can potentially walk out of the field completely done and documented with multimedia backing up a clean, engaging audit report. This enables users to work in an environment where they are able to create and capture both interactive media and structured data to accomplish existing audit goals while not relegating themselves to countless hours of tedious document preparation only to end up with all of their data forever “trapped” by documents.

The key innovation is that the app leverages the native iOS SDK to provide the most superior mobile GRC user experience that GRC 20/20 has encountered with deep integration with the device’s hardware capabilities including camera, microphone, GPS, touch gestures, hardware rotation, etc. This provides a faster, better, more beautiful, and more tightly integrated experience for the user than a mobile web app or a wrapper for the web that pretends to be an app.

To learn more about the GRC 20/20 2014 GRC Innovation Awards and other recipients, please visit this post: GRC 20/20 Announces 2014 GRC Innovation Award Recipients

2014 GRC Technology Innovation Award: Be Informed Empowers Organizations to be Agile in the Midst of Regulatory Change

The 2014 GRC Technology Innovation Awards was filled with competition.   Nominations increased to 62 over last year’s awards, and fifteen winners were selected.  GRC 20/20 looked through all of the submissions, asked for clarification where needed, and selected15 recipients that demonstrated outside the box thinking in taking GRC in new directions to receive this year’s award.

Be Informed Empowers Organizations to be Agile in the Midst of Regulatory Change

The Be Informed GRC-solution is based on the Be Informed business process platform, which is a platform using innovative semantic technology which can be understood as a shared vocabulary of business concepts describing the terminology of products, services, processes, activities, business knowledge and policies. It is fully model-driven, which means that requirements and specifications are expressed in semantic models, which can be directly executed, i.e. without transformation to another (programming) environment. This constraint-based process approach allows for dynamic processes, by which every individual transaction has its own process flow, depending on the data and context of that transaction.

The Be Informed semantic technology enables the dynamic management of regulations and changes in the GRC environment.  This allows organizations to stay current with the ever-continuing stream of new and changing regulations.  Organizations will find that regulatory change alongside business change and risk change becomes easier to manage, control, and traceable. Semantic models determine behavior of the business within rules. With Be Informed, the rules of business are modeled, not coded, in a visual and very comprehensible way for business users. This enables users to easily understand and change business rules, making the Be Informed business process platform an agile solution.

Be Informed through its semantics engine allows organizations to be in full control. In the GRC-space this means being able to handle complexity and change (e.g., regulatory change, business change, risk change), to provide a holistic integrated view of change, to enable transparency, and have complete insight and overview of accountability domains – on both content and process.  This is enhanced by audit trails that demonstrate accountability to customers, employees, shareholders and supervisory authorities.

By using the semantic models, you can define the requirements in an accurate, concise and machine executable format. Semantic models are used to make decisions, to classify what is applicable (and/or needed) and to calculate values. These outcomes are used to determine which controls are applicable, which data is needed to perform activities, how to drive the workflow process and even to determine which components of a report must be generated.

The Be Informed framework consists of three parts. The first part is the Definition part by using semantic models. Here Regulations and Policies are translated into regulatory and risk controls.  Second, once a control is defined it can be executed as a service in any of the core processes of the organization as represented. A transaction can only be completed if all necessary controls have resulted in a positive outcome. And third, Be Informed supports the review and evaluation of the effectiveness of the controls by planning, scheduling and executing of all kinds of assessments with the GRC-Workplace.

To learn more about the GRC 20/20 2014 GRC Innovation Awards and other recipients, please visit this post: GRC 20/20 Announces 2014 GRC Innovation Award Recipients

2014 GRC Technology Innovation Award: Convercent Delivers Agile Compliance Reporting

The 2014 GRC Technology Innovation Awards was filled with competition.   Nominations increased to 62 over last year’s awards, and fifteen winners were selected.  GRC 20/20 looked through all of the submissions, asked for clarification where needed, and selected15 recipients that demonstrated outside the box thinking in taking GRC in new directions to receive this year’s award.

Convercent Delivers Agile Compliance Reporting

Nearly every business function in today’s organization has benefitted from a transformational shift in how data is used to enable business agility – the ability to deliver meaningful intuitive information at a moment’s notice and enable accessibility across devices from computers, laptops, tablets, and mobile devices. However, compliance has struggled with systems in which information is neither agile nor mobile. The effect is a blurred or inaccurate picture of compliance risk. In today’s business, understanding a true picture of compliance at any point in time is critical. Compliance programs struggle with mountains of data in documents and emails or with expensive and non-intuitive solutions that create challenges to managing compliance effectively. Technology is a limiting factor to many ethics and compliance programs and is manifested in:

  • Increased exposure. Inability to make rapid decisions, and inability to draw historical benchmarks or predictive analysis based on integrated trends
  • Reduced efficiency. Time inefficiency to aggregate information into board/audit/executive reports
  • Increased cost. Utilizing manual processes to do what technology can streamline, centralize and automate.

Convercent is a cloud-based solution that delivers integrated reporting across key compliance functions, including policy management, learning management, hotline and investigations to enable effective compliance risk monitoring and mitigation. This is done through an elegant and intuitive user interface that delivers depth while minimizing technical acumen needed.  With Convercent it becomes easy to rapidly report on issues and understand what trainings and policies an employee has received and attested to at a moment’s notice. The ability to drill down to the individual level allows organizations to track and monitor developing compliance risks, and proactively analyzes and reports on information that highlights compliance efforts.

Convercent provides three layers of reporting and analytics, ranging from at-a-glance dashboards that enable program monitoring to effective oversight at the board level through the ability to use Microsoft Office tools to create a “two-click board report” in real time. Convercent allows for business agility within compliance departments and a reduction in costs associated with manual processes that is supported by three levels of reporting and analytics capabilities:

  • Dashboard Reporting provides the ability to understand performance at a glance. Compliance managers can monitor case management, policy and training health to get a high level overview on how the organization’s ethics and compliance program is performing.
  • Web-Based Reporting provides rapid understanding of issues that are occurring in real time. A variety of prebuilt case management reports are available for the compliance manager to present the information the way it needs it.
  • Convercent Data Services puts powerful and customizable reports at the organization’s fingertips. It provides the ability to collect real time ethics and compliance data in Convercent and immediately transfer it into Microsoft Excel and PowerPoint utilizing open standard oData technology.

To learn more about the GRC 20/20 2014 GRC Innovation Awards and other recipients, please visit this post: GRC 20/20 Announces 2014 GRC Innovation Award Recipients

2014 GRC Technology Innovation Award: Corl Mitigates 3rd Party Risk Through Ongoing and Proactive 3rd Party Intelligence

The 2014 GRC Technology Innovation Awards was filled with competition.   Nominations increased to 62 over last year’s awards, and fifteen winners were selected.  GRC 20/20 looked through all of the submissions, asked for clarification where needed, and selected 15 recipients that demonstrated outside the box thinking in taking GRC in new directions to receive this year’s award.

Corl Mitigates 3rd Party Risk Through Ongoing and Proactive 3rd Party Intelligence

Managing risk and compliance across 3rd party relationships has become a significant challenge to organizations. Surveys and questionnaires given to 3rd parties are necessary, but also prove unreliable and difficult to receive high quality responses containing accurate and fully completed information. The cost of follow up and inherit reliance on vendors to be responsive reduces effectiveness and increases the cost of due diligence. Many 3rd party risk and compliance approaches lack scalability as they are labor intensive and time consuming –the resource requirements of managing the “back and forth” and due diligence process typically results in less than 20% of vendors being properly vetted.  Surveys and questionnaires are can also be outdated and audit-based assessments are point-in-time evaluations. After-the-fact changes in risk may not be documented and factored into 3rd party risk scores.

Third-party breaches and regulations are increasing drastically, but effective third-party security risk management is expensive, time consuming, and resource intensive. As a result, many organizations have programs that do not provide full coverage, or provide a false sense of security.  Corl’s vendorsecurityRM provides organizations with the information they need to effectively focus their vendor due diligence efforts on those vendors who present the most risk.  Data breaches can be costly due to the cost of remediation, regulatory fines, and reputation damage. Corl’s risk-based approach helps organizations focus their vendor security risk management efforts where they will have maximum impact and value.

Corl’s vendorsecurityRM solution is an innovative approach to supplement surveys, questionnaires, and due diligence processes.  It enables organizations to intelligently understand and reduce risk attributable to a 3rd party relationship with a particular focus on data breaches. The vendorsecurityRM solution provides a vendor score and supporting information to effectively address the question of “can my organization have confidence in this 3rd party’s ability to protect sensitive data from an unauthorized breach?” The solution overcomes the traditional barriers of transparency, 3rd party collaboration, and resource capacity to effectively deliver 3rd party vendor security risk management.

The vendorsecurityRM solution is comprised of three primary components that combine to make it innovative: 1, a comprehensive and sophisticated patent-pending algorithm to assess vendor security confidence, which was developed by a PHD led team over two years in collaboration with Fortune 500 to small size organizations; 2, big data analytics of industry specific vendor behavior, benchmarks and best practices that encompass people, process and technology and supported by dedicated research teams; and 3, community/industry collaboration through Corl’s collaboration platform.

The vendorsecurityRM solution changes the paradigm for managing vendor security risk. It demonstrates that traditional risk assessment methods may be effective at gathering data but only go so far at rating confidence, managing risk and holding vendors accountable.  The solution delivers reliable indicators of risk in a significantly more timely and efficient manner than traditional approaches. Most importantly, these indicators are actionable for effectively mitigating and continuously managing vendor risk. The solution also reduces regulatory compliance exposure for organizations that do not consistently follow through on vendor assessment and remediation processes.

Corl’s vendorsecurityRM supports a comprehensive vendor security program comprised of 4 steps:

  1. Profiling. Identify and document information security risks for existing and prospective vendors (e.g. RFP respondents)
  2. Due Diligence. Corl’s vendorsecurityRM reports are the basis for an effective due diligence process, allowing organizations to focus efforts on vendors that present the least confidence to protecting sensitive information such as PHI.
  3. Risk Strategy. Corl’s vendorsecurityRM program monitors and reports on required or recommended remediation to be completed by the vendor based on due diligence findings.
  4. On-going Monitoring. Corl’s vendorsecurityRM program continuously monitors vendors for changes that affect information security risk, and provides clients with automatic alerts when such changes are detected.

Corl’s vendorsecurityRM solution is a multi-tenant SaaS-based solution built on Microsoft technology and is currently in production with some large healthcare firms, both providers (hospitals) and payers (health insurers), and plans to roll out additional industry solutions in the future.

To learn more about the GRC 20/20 2014 GRC Innovation Awards and other recipients, please visit this post: GRC 20/20 Announces 2014 GRC Innovation Award Recipients

2014 GRC Technology Innovation Award: Digital Reasoning Provides Intelligence on Communications, Relationships and Risks

The 2014 GRC Technology Innovation Awards was filled with competition.   Nominations increased to 62 over last year’s awards, and fifteen winners were selected.  GRC 20/20 looked through all of the submissions, asked for clarification where needed, and selected15 recipients that demonstrated outside the box thinking in taking GRC in new directions to receive this year’s award.

Digital Reasoning Provides Intelligence on Communications, Relationships and Risks

Financial institutions are seeking a more complete picture of the people and organizations that pose risks or promise opportunities. In some cases, financial institutions have decided not to service entire industries, because they’re concerned that they don’t know enough about the entities and individuals within these markets. The game-changing innovations delivered in Synthesys 3.8 provide real-time situational awareness for decision makers within financial services organizations, because they can rapidly examine human communication and uncover relationships and risks that may have been intentionally concealed.

Synthesys reads and understands vast volumes of data at blazing-fast speeds. It reads through data and highlights important people, places, organizations, events and facts. It takes those highlighted points and determines what’s important, connecting the dots together.. Synthesys is a machine-learning platform, which understands human communication (emails, social media, chat, documents, etc.) on a massive scale and identifies and visualizes complex relationships. In its most recent release, version 3.8, Digital Reasoning has introduced innovations that allow financial services institutions to aggregate and visualize knowledge in real time. Specifically, it identifies and aggregates knowledge about people and organizations to make relevant predictions about future behavior of employees, customers or bad actors.

The platform is designed to identify relationships and risks that are being intentionally concealed. Without the use of keywords and/or fragile rule engines, Synthesys schematically analyzes data and determines what relationships and activities are risky. This approach significantly decreases risk and compliance based false positives while increasing the potential of identifying true positives (real risks), as Synthesys continually learns from business and data context, allowing Synthesys to stay one step ahead of evolving risks within the financial institution.

In addition to its core analytics, Synthesys provides real-time query capabilities, which allows organizations to explore a wealth of aggregated, categorized and prioritized knowledge on employees, customers and market information from news, social media and many other public sources of information. Using Digital Reasoning’s new web application, called Synthesys Glance™, analysts can interactively browse and analyze various profiles of people and organizations to discover valuable patterns and relationships.

Synthesys has a surprising understanding of human language. It understands time and place, learns the meaning of words based on how they’re used and can read and understand different languages. It determines how people, places and organizations are connected. It understands not just the words being said, but what they actually mean in context. It’s always on the lookout for information related to the answers. It can provide answers to questions an organization never thought to ask, or tip you off to relationships you never knew existed. It delivers data insights to your organization in an easy-to-digest format. Through app integration, data insights can be visualized for quick understanding and easy sharing. Alarms and alerts can also be set up to notify the organization when important findings turn up in data. Its knowledge graph gets smarter and grows with the organization. Synthesys teaches itself to draw conclusions based on what the organization has been looking for in its data.

For example, Synthesys can analyze suspicious activity reports (SARs), wire instructions and other unstructured descriptions and narratives. It reveals employees who have become ethically exposed, involved in bribery, unauthorized trading and fraudulent activities and other traffic for related behaviors and assertions. With the Digital Reasoning Synthesys platform, users can uncover relationships between employees that are on a restricted trading list, and examine their communications. This approach allows financial institutions to reveal intentionally concealed risks and relationships, before reputations are compromised or regulatory penalties are levied.

To learn more about the GRC 20/20 2014 GRC Innovation Awards and other recipients, please visit this post: GRC 20/20 Announces 2014 GRC Innovation Award Recipients

2014 GRC Technology Innovation Award: ERP Maestro Delivers Automated Security & Access Controls Through the Cloud

The 2014 GRC Technology Innovation Awards was filled with competition.   Nominations increased to 62 over last year’s awards, and fifteen winners were selected.  GRC 20/20 looked through all of the submissions, asked for clarification where needed, and selected 15 recipients that demonstrated outside the box thinking in taking GRC in new directions to receive this year’s award.

ERP Maestro Delivers Automated Controls Through the Cloud

Automated Segregation of Duty and Access Control solutions are known to be exorbitantly expensive and take a considerable amount of consulting resources and time to implement. Requiring large software fees, hardware costs, consultant fees and complex training projects, and being overcome by large organizations; they remain a challenge today for organizations of all sizes, particularly the small to medium sized organizations.

ERP Maestro’s Access Analyzer™ solution provides Segregation of Duty and Sensitive Access Analytics and reporting over a completely cloud based architecture.  Their unique utilization overlay reporting graphically identifies risks and remediation paths. With a cloud based delivery mechanism of an Access Controls solution, not a hosted solution technology, customers receive cost benefits of a multi-tenant environment and the exclusivity and security of a dedicated server. The cost savings associated with on demand allocation of servers is passed on to the subscribing customer, allowing small to medium enterprises to afford an enterprise Access Control solution.

The solution is truly innovative as it pools a massive amount of cloud resources to provide on demand server allocation as a dedicated server when needed by the client, while dormant servers are deactivated or recycled to other customers. The solution is contained within a deployment that dynamically grows and shrinks based on its demand (number of organizations using the system).

Interestingly, this can also serve as a bridge for companies implementing SAP GRC10. Large companies want a stopgap solution for the complex implementation process that represents GRC10. Some companies are waiting for budget approvals and/or developing a business case. ERP Maestro’s solution price point allows it to serve as that stopgap solution to address SoD needs until the major SAP GRC solution is implemented.

The model is of particular interest to small and medium sized organization that can now afford the implementation of an enterprise Access Control Solution because of ERP Maestro’s model. The entire process is no longer expensive, complex and drawn out, allowing funds to be focused on remediation efforts. The simplicity of their subscription-based service empowers companies that traditionally would not pursue an Access Controls solution, to now proliferate the capability and manage the risk of Segregation of Duties more effectively.

End users have anywhere, anytime access to a web interface that allows them to connect to their ERP system (SAP is the only ERP currently supported by ERP Maestro). The data is securely analyzed using an on demand, dedicated server located in a server farm, then the results are compiled in to multiple reports for consumption. While cloud technology isn’t new, ERP Maestro’s ability to process analytics on hundreds/thousands of client simultaneously based on it’ analytics engine is indeed new and innovative technology which empowers them to offer a premium service, at a low subscription fee.

To learn more about the GRC 20/20 2014 GRC Innovation Awards and other recipients, please visit this post: GRC 20/20 Announces 2014 GRC Innovation Award Recipients

2014 GRC Technology Innovation Award: Integrc’s RouteONE Delivers Significant Efficiences in GRC Implementation

The 2014 GRC Technology Innovation Awards was filled with competition.   Nominations increased to 62 over last year’s awards, and fifteen winners were selected.  GRC 20/20 looked through all of the submissions, asked for clarification where needed, and selected 15 recipients that demonstrated outside the box thinking in taking GRC in new directions to receive this year’s award.

Integrc’s RouteONE Delivers Significant Efficiences in GRC Implementation

The cost and time to implement enterprise GRC solutions has been a barrier to many organizations, paritcularly those integrated with an ERP environment such as SAP. This often means that SAP GRC projects feel like necessary overheads that are difficult, costly and drag-on.  Integrc is an innovative service provider that enables organization to achieve the rich value of SAP GRC but in a way that is radically different. Their goal is to implement SAP GRC ten-times faster. With Integrc’s innovative RouteONE, many elements of an SAP GRC deployment have been reduced from weeks to minutes.

RouteONE is inspired by Michael Hewitt-Gleeson’s x10 thinking, which has been the mantra of Google CEO, Larry Page. Most companies would be happy to improve a product by 10%. But as Page sees it, a 10% improvement means that you’re basically doing the same thing as everybody else. That’s why Page expects Google employees to create products and services that are 10 times better than the competition. It works on the basis that ten heads are better than one, so rather than having top management provide inspiration, you enable your employees to do it. It’s a concept also referred to as ‘Bottom-up innovation’. X10 is one hundred times 10% – and that radical objective changes the approach from modify to re-design from scratch.

RouteONE has become a revolutionary way to deploy SAP GRC solutions faster and cheaper. For organisations with a SAP centric application strategy, this now brings an integrated technology solution within reach in a way that has not been affordable or manageable before. RouteONE unlocks GRC automation, enabling organisations to bring IT enablement to enhance their GRC business practices. RouteONE is centered around an innovative automated configuration engine combined with an accelerated methodology, a library of pre-built content and an award-winning end-user adoption framework – Engaging Risk (recognized last year in GRC 20/20’s 2013 GRC Innovation Awards). When used by experienced SAP GRC consultants, RouteONE typically halves thetime and cost of implementing SAP GRC but delivers the tailored outcomes expected from a traditional approach.

The core of the RouteONE capability is the QuickBuilder engine, which automates the necessary configuration components of the SAP GRC products. It also automates the configuration of the SAP suite using business design workshops based on the customers own environment. The Quickbuilder is supplemented with the Quickloader tools, which enable the related master and transactional data to be managed via Excel spreadsheets. When compared to either a templated or traditional approach to deploying SAP GRC, RouteONE provides significant gains in efficiency, effectiveness, and agility. Customers no longer have to compromise any of their requirements or accept a long and potentially expensive project. RouteONE is transformational in that it delivers a solution specific to their unique needs, but goes beyond accelerators and basic knowledge transfer materials and enables the automation of key tasks throughout the implementation. This means organisations wanting an integrated system, tailored to their exact GRC needs, now have a much faster, more manageable and more affordable option.

RouteONE is game-changing because it unlocks the potential of integrated SAP GRC, which for many SAP customers was previously out of reach. Now they can dismantle many of their technology, cost and time-related barriers, roll-out SAP GRC far more quickly and cost-effectively than ever before and focus more effort on business change and end-user adoption. In short, it makes GRC automation more possible for many more organisations.

RouteONE has a continual emphasis on benefits realisation and on ensuring business users embrace the new system.Automation not only reduces human error, enables Integrc’s clients to go faster and saves them money – it also frees up time for more value-added activities, which is where Integrc’s change management framework – EngagingRISK comes into play. RouteONE can also provide a draft build of the system within 24 hours of starting a project, giving customers the benefit of hindsight in advance. So all in all, not only can faster outcomes be achieved, these outcomes are often better as well.

To learn more about the GRC 20/20 2014 GRC Innovation Awards and other recipients, please visit this post: GRC 20/20 Announces 2014 GRC Innovation Award Recipients

2014 GRC Technology Innovation Award: Lexer Enables Organizations to Monitor and Manage Brand & Reputation in Moments of Crisis

The 2014 GRC Technology Innovation Awards was filled with competition.   Nominations increased to 62 over last year’s awards, and fifteen winners were selected.  GRC 20/20 looked through all of the submissions, asked for clarification where needed, and selected 15 recipients that demonstrated outside the box thinking in taking GRC in new directions to receive this year’s award.

Lexer Enables Organizations to Monitor and Manage Brand & Reputation in Moments of Crisis

Lexer’s innovation is a solution to integrate and visualize streams of data to manage reputation risk across social media content.  Lexer does this by producing highly accurate geographic insights used as the conduit between the various data sources such as census, socio-economic, transactional, CRM, and customer support.. This unified data set offers businesses a new perspective on reputation and brand risk since it offers a wealth of detail on data previously inaccessible.

In 2013, Lexer invested greatly in the enrichment process of the data it collects and, as previously outlined, the introduction of geographical enrichment as a highly accurate and reliable conduit between many external data sources. Using these new data sets, Lexer now has the ability to create complex personas based on behavioral, social and economic profiles – ensuring their data sets align with brand segments, key audiences and most importantly, stakeholders. Whether it’s in prediction, reaction or reflection, Lexer’s enriched data sources give businesses a new perspective on the way consumers react, engage and change in brand incidents. Moments of crisis regularly impact organizations, digital media has accelerated the speed at which information about a crisis can spread and during times of crisis, poor decisions are made due to inexperience, pressure and the lack of hard data. These poor decisions result in enhanced financial, reputational, health, safety and environmental risks.

Lexer uses integrated datasets to deliver routine reports on the details of incidents and the aftermath that includes influencer analysis, trend data and trajectories, topic and sentiment analysis – but most intriguingly, they are able to track the incident right to the root.

Lexer’s prime technical innovation is the ability to collect, process and unify unstructured data sources in real time. The technical focus for 2013 was to identify and develop into the core of the Lexer platform a common point of reference in which other data sources; such as CRM, Transactional and Socio-Economic data could integrate.

After extensive research and prototyping it was clear that geospatial detail was required to create a clear conduit between sources. As such, Lexer invested its efforts in being able to determine the location of social media users even when they didn’t share details such as longitude and latitude. Their enrichment process uses Machine Learning and Real-Time Data Processing infrastructure to analyze language, physical reference points and trends for each piece of data consumed by the Lexer platform. They are now able to obtain 3rd party data and integrate that geospatial data to map once abstract sources together, allowing more specific querying of data, clearer segmentation that’s relative to the organization’s segments, and insights that take in the whole picture. Their core ability is to help organizations understand the cost of making a wrong decision.

To learn more about the GRC 20/20 2014 GRC Innovation Awards and other recipients, please visit this post: GRC 20/20 Announces 2014 GRC Innovation Award Recipients