Is Governance, Risk & Compliance (GRC) Strategy same across all industries?

Is Governance, Risk & Compliance (GRC) Strategy same across all industries?

Organizations must see GRC as more than a tool or a technology when it comes to governance, risk, and compliance. It's not enough to have a vendor GRC software or a template to comply with the requirements. I feel that proper guidance and direction are critical components of any GRC strategy in any industry.

With that said, I am certain that each industry perceives GRC in its own, distinct way, and that this is how it should be. Every industry has its own set of regulatory and compliance standards, which is why it's critical to design a governance, risk, and compliance plan that meets those needs. The dedication to key stakeholders while also preserving customer trust is one of the most critical parts of any organization.

The following points will help you understand why every industry needs its own GRC approach.

1.Nature of the Business: Every organisation has its own manner of providing services and managing governance, which is why the first step in any risk assessment process should be to thoroughly understand the business before identifying assets. The organization's risk management methodology is determined by the nature of its company. Businesses that provide financial services are subject to different regulations than organizations that provide healthcare/pharmaceutical services, which is why both industries require their own GRC strategy.

2. Risk Appetite & Risk Culture: The best indicator of a firm's GRC strategy is how it manages risk, which can be deduced from the risk culture inside that organisation. The following are the three important characteristics of risk culture that can be used to understand an organization's risk culture.

  • Behavior towards taking the risk: how much risk does the organization is willing to take?
  • Behavior towards policy compliance: to what extent do employees within the organization comply with the policy?
  • Behavior towards negative outcomes: how does the organization deal with losses, missed opportunities and other negative outcomes?

3. Legal & Regulatory Requirements: One of the most important parts of any GRC approach is compliance. Distinct industries have different legal and regulatory obligations with which they must comply. Organizations that are publicly traded and provide financial services, for example, must comply with the Sarbanes-Oxley Act (SOX) , the Gramm-Leach-Bliley Act (GLBA) , the Payment Services Directive (PSD2) , and other regulations. Simultaneously, health-care firms must adhere to Health Insurance Portability and Accountability Act (HIPAA) regulations. As a result, each industry should develop its own GRC plan based on these regulations and requirements.

4. Geographical Location: The place where organizations have their businesses operating also plays an important role in determining the strategy. Different countries have their own set of laws and regulations that need to be complied with. For example, if an organization is headquartered in California and it is also having its corporate headquarters in different countries such as India or United Kingdom, then these countries will also have their own set of regulations to which the organization needs to comply. So, depending upon these regulations, the GRC strategy should be outlined to avoid non-compliance fines.

5. Customer Base: Organizations providing services to their customers, collect personal data and depending on where the customers are located, local authorities may require organizations to stay compliant to different laws and regulations. If an organization is collecting personal customer information from the European Union, it is important for the organizations to stay compliant with the European Unions' General Data Protection Regulation (EU-GDPR). On similar lines, if an organization is collecting information from citizens of California, then the organization should stay compliant to the California Consumer Privacy Act (CCPA). And that is why different organizations operating in different regions and collecting information should have a separate and a unique GRC strategy.

6. Availability of Resources: This is the most important point while outlining a GRC strategy. The GRC strategy is mostly dependent on the availability of resources to make sure that the strategy is executed. Availability of skilled talent, tools and technologies, investments made in IT and support from the senior management is an important factor in resource management. Depending upon how much resources are available within the organization, the GRC strategy will change respectively.

To conclude, I believe that the above points put forward the need of a different GRC strategy for every organization.?Please let me know your thoughts as well!

Akshay Bhalerao

Senior Analyst @ Fidelity Investments | CompTIA Security+ | CySA+ | Information Security | Infrastructure Security

2 年

Good article Chinmay Kulkarni, waiting for more!

要查看或添加评论,请登录

Chinmay Kulkarni的更多文章

  • Issue #3 Clarity with Chinmay

    Issue #3 Clarity with Chinmay

    What's Next in Access Control Testing? Welcome to another edition of Clarity with Chinmay! Last time, we kicked off our…

  • Issue #43

    Issue #43

    Understanding IT Application Controls (ITAC): My Key Learnings In the world of IT audit, IT Application Controls…

    5 条评论
  • Audit - Fault Finding or Issuing Opinion?

    Audit - Fault Finding or Issuing Opinion?

    One question I hear often is, "Is audit just about finding mistakes?" It’s a common misconception. From my experience…

    4 条评论
  • Top 10 Questions for Access Control Walkthroughs - Part 1

    Top 10 Questions for Access Control Walkthroughs - Part 1

    Let's discuss the ten essential access control questions you should ask during your next audit. Access control is a…

    5 条评论
  • How to Conduct Effective IT Audits?

    How to Conduct Effective IT Audits?

    In this newsletter, we're diving into a topic critical for both seasoned auditors and those just starting their audit…

    1 条评论
  • The #1 Habit That Separates Top Auditors

    The #1 Habit That Separates Top Auditors

    Today's newsletter is one of the most important I've written on any topic. Understanding this topic will set you for…

    1 条评论
  • Top 3 Considerations when evaluating IT Application Controls

    Top 3 Considerations when evaluating IT Application Controls

    Do you know the top three key considerations when evaluating IT application controls? This newsletter dives into the…

    2 条评论
  • ITGC - Job Scheduling & Monitoring

    ITGC - Job Scheduling & Monitoring

    Remember the satisfaction of receiving your paycheck on time, every other Friday? It might seem like magic, but a…

    4 条评论
  • The Two-Step Secret for Control Assessment

    The Two-Step Secret for Control Assessment

    What is the 2-step approach for evaluating a control? A large part of IT Auditor's job involves assessing the…

    3 条评论
  • Top 10 Audit Interview Questions You Shouldn't Miss (Part 1)

    Top 10 Audit Interview Questions You Shouldn't Miss (Part 1)

    Can you walk me through your resume? We've all been there: staring at a blank page, trying to craft the perfect…

    1 条评论

社区洞察

其他会员也浏览了