×
Blogs

GRC Resilience at the front line of new and emerging world events

MS_ResilienceSpotlight_805x489_08
5 min read

Introduction

As health risks due to COVID-19 dominate the headlines, many parts of the world are also experiencing an explosion of natural disasters, from hurricanes to heat waves and deadly wildfires in my home state of California. Instead of stay-in-place orders, these are forcing evacuations, and reminding us that there will always be risk.

As a provider of integrated risk management and business continuity solutions, this is the time for MetricStream to step up. Since the pandemic was first declared, more than 150 days ago, I’ve reached out to at least 100 customers to see how they are responding and have come away inspired.

Part of what I’ve learned is that most are on a multi-step journey:
 

  1. The Immediate: The first 1-3 months were about doing whatever it took to get set up in a reasonably stable situation. For some, it was a mad scramble to get there.
  2. The Intermediate: Most companies now find themselves in this second phase and looking at their governance, risk and compliance (GRC) priorities in this changing world.
  3. The New Normal: This is about “How do I optimize?” Organizations are re-building real-time risk  processes to respond effectively in a constantly evolving risk universe.

During the intermediate phase, businesses are wrestling with daily decisions of what to prioritize:  Should we bring people back into the office or wait until there’s a vaccine? How do we ensure it’s a safe environment? Do we bring them in on different shifts? And how do we “contact trace” and make sure we don’t knock out entire departments? Risk factors for not bringing people back into facilities for a manufacturing company could loom large. For a social media company, or a technology company, there’s low risk.

We used to take for granted that going into the office wasn’t a health risk. Now that it is, it has spurred a tremendous shift to working from home (WFH) and companies are moving to cloud-based solutions more and more. This is truly a shift in how our customers are working; for example, they’re moving to conducting audits on a largely remote basis without ever showing up at locations to examine physical surroundings.

Many customers needed to quickly edit and re-publish their WFH policies and standards. Those who are using a Policy Management solution from MetricStream are better able to target their policies to meet the needs of specific business units, functions and roles, to provide access and who needs to attest. For example, many traders who work from home likely don’t have a needed “secured and recorded line”. MetricStream, too, continues to serve our customers with a workforce that’s working remotely. That means ensuring the cyber security of systems and executing on business continuity plans for an extended period of time in that environment.

The pandemic has also heightened the value of technology to help get work done. Our new MetricStream Platform makes it easier to work from home. Customers who were lagging on upgrades are now pushing these projects forward. They realize the new functionality and user interface are critical for staff who need to work with little training. MetricStream's embedded help and re-designed input screens have made it easier to get more employees engaged in recording risk events and potential solutions.

Greater visibility into the supply chain has also become more critical for many customers and their partners, who are looking for better tools to collaborate with vendors and suppliers. Customers have used MetricStream to better link suppliers to products and business units. This information helps each business unit understand how supply chains impacted by the pandemic directly impact the business unit’s goals. While most Vendor Management solutions stop at the link between vendor and product, MetricStream takes the relationship further by linking to business units and business objectives.

Going forward in the “new normal”, risk findings and metrics will be aligned much more closely to resilience and strategic objectives to better prepare for the next crisis. While there has been an elevation of health and safety as a priority area for companies worldwide, there is uncertainty around which regulations will apply and which to be concerned about. Generally speaking, this is a broader trend that is likely to continue.

We’re also seeing a fresh wave of innovation with AI, machine learning, robotic process automation (RPA) and analytics to keep pace with the high volume and velocity of data and to keep the cyber health of the extended enterprise secure. Forms and collection of data are great, but businesses need to integrate it with other data and include it in their monthly reports and dashboards. At one of our banking customers, GRC reduced policy research from an average of 50 hours to 50 mins.

COVID is accelerating change for our customers in a world that will only become much more digital in the aftermath of the crisis. As Microsoft CEO Satya Nadella put it in an earnings call in late July, “We’ve seen two years’ worth of digital transformation in two months. Customers every day adapt and stay open for business in a world of remote everything.”

Overall, our customers are taking a broader view of work and processes than they used to. And even as the pandemic fades in the rear-view mirror, 2020 can still be a year of clarity and a time of people coming together with a clear purpose to change society for the better.

The human experience is about overcoming adversity through resilience and that is certainly on display across the world. With the right approach, this crisis can become an opportunity to move forward and create even more value and positive societal impact. GRC practitioners will be on the front line of this new normal just as healthcare workers are on the front line in the fight against COVID and fire fighters are on the front line battling California’s wildfires. A big thank you to all our fire fighters who are willing to risk their lives to save others!

Please feel free to reach out to me at Gunjan@MetricStream.com with your own stories and comments.

Jump to Topic
Gunjan

Gunjan Sinha Executive Chairman, MetricStream

Gunjan Sinha, Executive Chairman, MetricStream, helps lead the overall direction and vision of the company. His focus in on building MetricStream into a global GRC leader with strong teams that are excited about new markets, disruptive technologies and social impact.

 
Blogs

Effective Policy Management Through the Crisis and Beyond

Blog Image
4 min read

Introduction

The COVID-19 pandemic is challenging organizations across the globe to operate in a new paradigm that is changing almost on a daily basis. Business leaders are having to make decisions to best deliver on customer commitments without compromising on employee well-being. Whether it’s banks, hospitals, manufacturers, or retailers, they are all relooking into their policies and procedures and making changes to them to help deal with the crisis.

Some policies that top the list are work from home policies, travel policies, information security policies, health and safety policies, expense policies, etc.

How are the compliance and ethics teams dealing with this? How are they rapidly updating the policies? What impact are these updated policies having across the board? Is the change communicated to the applicable employees? Are the policies being followed?

Given the current, fluid situation, the need for a robust policy management program is amplified.

Listed below are some policy management strategies that compliance and ethics leaders can follow to address these concerns and sail through the current disruption and beyond.

Collaboration is key

Most organizations follow a siloed approach to policy management in which different teams within the organization work independently and follow different templates and guidelines. While there may be a dedicated owner for each policy while creating or updating the policy, the owner needs to collaborate with other business functions. For instance, while updating the work from home policy in these times of the pandemic, the information security policy, or the expense reimbursement policy, will also be impacted. A policy management technology platform can be of great help.

  • It can have streamlined workflows where multiple people across the globe can easily collaborate on different sections of a policy to provide comments and feedback.
  • Proper version control can be maintained.
  • You can get a clear defensible audit trail on the changes made to policies.

Keep it contextual.

Take a contextual view of the policies when you are creating or updating them. It will help to have answers to the following questions.

  • What is the risk associated with a policy?
  • What are the regulations or standards tied to each policy and what are the processes that they may impact when a policy gets updated?
  • How many exceptions are raised against a specific policy?

All exceptions carry some amount of risk which has to be taken into account. Many organizations are also not aware of the violations of policies or if these violations or cases are tracked, if they are not linked to policies. Linking policies to cases gives a lot of insight to compliance professionals on the policies they need to rework, and whether they should invest in new training programs or put additional controls in place.

Communicate, communicate, communicate!

With the current COVID-19 situation, some policies are getting updated on a weekly basis and there could be compliance implications if the policies are not adhered to by the employees. While most companies use email as a mechanism to communicate policies, there is a probability that policies get lost in the many emails that one receives. Some best practices could be:

  • Post policy updates on your intranet or any other operational or internal social platforms.
  • Focus on sticking to the most important messages and keep them short, engaging and empathetic.

Simplify Policy Access

In addition to email, announcements regarding the policy can be made available on a centralized policy portal. Whichever channel is chosen for the communication of policies, it really helps to be clear about what the change is, why the change is required, and what measures need to be taken by employees to make sure they adhere to the new requirements. MetricStream Policy and Document Management has a centralized state of the art policy portal that only shows the latest relevant policies applicable to each employee, relieving the employee from having to search through multiple databases.

Get policies to where employees are

Consider a case where the employee has to search for policies in multiple portals, not knowing which one is the latest and which one is applicable to him/her. It makes sense for the policies to pop up in the intranet, in the chatbot, customer relationship tool, or any other operational system that is frequently used by employees. For example, if the loan processing agent needs to refer to the updated policy on loans it makes sense for him/her to access the latest updated policy quickly on the intranet rather than referring to the old outdated policy and thereby violating norms.

Assess Policy Awareness

Policies can be deemed effective only if they are adhered to. Most organizations invest in quizzes and surveys to gauge how well employees have comprehended the policy. This is more prevalent for training on the FCPA, Information Security and Sexual Harassment policies. With policy management technology, employees can be allowed to attest to a policy only upon a minimum passing score and the questions can be designed to be engaging and interactive.

In summary

While the given situation has compounded the need for an effective policy management program, businesses understand that policies are an integral part of the overall compliance program. There is no doubt that policies, procedures and other compliance-related documents are the foundation for a successful compliance program. It helps to have a technology solution like MetricStream Policy and Document Management that can automate, streamline and integrate policy change management so that you can mitigate compliance related risks and stay ahead of the curve.

Admin_avatar_1498731489

BLOG ADMIN

Read more about the latest happenings in the GRC universe. MetricStream experts share their valuable insights on how organizations can turn risk into a strategic advantage and thrive on risk.

 
Blogs

Through the GRC Lens – February 2020

blog
4 min read

Building a Future of Trustworthy AI

The European Commission recently unveiled its long-awaited proposal to regulate artificial intelligence (AI). But will the new proposal stifle innovation? Find out more through the GRC Lens – February 2020 edition. 
_____________________________________________

On the 19th of February, the European Commission (EC) President, Ursula von der Leyen, Executive Vice-President, Margrethe Vestager and EU Commissioner for Internal Market, Thierry Breton, held a press conference at the European Commission headquarters in Brussels, unveiling their ideas and actions to regulate AI.  

Keen on building “a digital Europe that reflects the best of Europe,” the EC released a white paper on AI that defines an extensive framework under which AI can be developed and deployed across the EU. The paper includes considerations to govern high-risk use of AI like facial recognition used in public spaces, with an overall ambition to shape Europe’s digital future”.

The proposal still has a long way to go. For now, the EC plans to gather opinions and reactions from companies, countries, and other interested parties before they begin to draft the laws. And although the AI white paper is open for suggestions until May 19, lobbying has already begun.

Worried AI Vendors: Will Regulation Stifle Innovation?

Although many AI experts have said that the regulation of AI is necessary, especially due to ethical concerns, there is considerable worry around the consequences of regulation. Europe’s new proposal has already had far-reaching implications on the big tech brands that have invested in AI. After the EC declared a 12-week discussion period, several tech leaders from large organizations have journeyed to Brussels to meet with EU officials.

Their major concern – will tough laws hinder innovation?

AI vendors are worried that if the process of regulation, considered a slow process that can be subject to interference and distortion, is applied to a fast-moving field like AI, it can stifle innovation and divert the technology’s enormous potential benefits.

To illustrate this concern, a recent article in Analytics India Magazine, used the example of neural nets to explain how the regulation of AI could possibly hamper innovation. Neural networks work by finding patterns in training data and applying those patterns in new data, enabling researchers to solve problems that they couldn’t earlier.

For instance, CheXnet, an AI algorithm from Stanford, has an incredibly powerful ability to detect pneumonia among older patients through chest X-rays. But for technologies like these to work, they need a certain amount of creative and scientific freedom (within ethical boundaries, of course). If there is a ban on “black box” AI systems that humans can’t interpret, could AI innovation be impacted?

Another area of confusion revolves around the definition of “high-risk” applications of AI. The report seems to be unclear about high-risk applications in low-risk sectors, leaving companies uncertain on how to approach this issue.

The Need for AI Regulation: Consumer Protection

There is no doubt that AI has enormous potential to be used for good. But its accelerating adoption across industries comes with multiple ethical concerns.

According to a survey by KPMG, 80% of risk professionals are not confident about the governance in place around AI.

What happens when decisions are made by AI without human oversight? Recent instances have shown that automated decision-making can perpetuate social biases. In addition, deep fakes, surveillance technology, autonomous weapons, and discriminatory HR recruiting tools come with multiple serious risks. The focus of AI regulatory authorities is on developing frameworks to govern AI.

Like Anna Fellander, Co-founder of the AI Sustainability Center, said at the GRC Summit in London, “It’s no longer just about what AI can do, but what it should do.” In a similar vein, Andreas Diggelmann, “Office of the CEO,” Interim CEO and CTO at MetricStream said, “We need technology that serves humanity, not the other way around.”

Looking Forward to Trusted AI

AI expert Ivana Bartoletti, Technical Director, Deloitte – Cybersecurity and Privacy Division, speaking at Impact 2020 conference, said: “The reason why we’re talking so much about ethics in AI is over the last few years we have seen the best of technology – but also the worst.”

With its novel approach to AI regulation, the EC wants to promote the development of AI while respecting human fundamental rights and addressing potential risks that come with the technology. The EC wants a digital transformation that works for all, reflecting the best of Europe: open, fair, diverse, democratic, and confident.

The new AI proposal has already begun to receive acceptance in some industries. Ted Kwartler, Vice President, DataRobot, said the vendor welcomes calls for regulatory approaches that don’t stifle innovation. Christopher Padilla, VP, Government and Regulatory Affairs, IBM, also was reported saying in Protocol, “By focusing on precision regulation — applying different rules for different levels of risk — Europe can ensure its businesses and consumers have trust in technology.”

It appears now that big tech companies that want to tap into Europe’s market will have to play by the rules that come into force. Like the GDPR in 2018, will the new AI proposal inspire similar, tough regulatory action in other parts of the world? Read the MetricStream Blog to stay updated on more news.

Admin_avatar_1498731489

BLOG ADMIN

Read more about the latest happenings in the GRC universe. MetricStream experts share their valuable insights on how organizations can turn risk into a strategic advantage and thrive on risk.

 
Blogs

Through the GRC Lens – November-December 2019

Blog Image
3 min read

The Changing Winds of Compliance

As compliance teams strive to manage new regulations and technological advancements, here are some of the trends and headlines that made compliance news in November and December. 
 

In the face of changing business models, as well as new risks and dynamic global ecosystems, compliance as a discipline is rapidly evolving. Stakeholders rely on compliance teams to not only protect their organizations against regulatory penalties and legal liabilities, but to also strengthen reputation and credibility with customers. As compliance officers seek to demonstrate and enhance the value delivered to their organizations, the following are some key considerations.

New Regulations

While 2020 began with a focus on data privacy, here are some updates on other areas of compliance that made the headlines:

  1. Data Privacy: This month, the CCPA came into effect giving customers more control over their data. However, in a study by Ethyca, only 12% of 85 respondents believed they had achieved an adequate state of compliance readiness for the emerging regulated privacy landscape.An article in Forbes suggested that “Rather than looking at CCPA compliance as a chore, look at it as an opportunity to innovate your business practices and seek ways to regain a first-party relationship with your customers.”
     
  2. Payment Security: Payment security compliance declined for the second year in a row in 2019, according to Verizon’s 2019 Payment Security Report. The report also pointed out that a compliance program without proper controls to protect data has a more than 95% probability of not being sustainable and is more likely to be a potential target of a cyberattack.
     
  3. Banking and Finance – As the financial services industry continues to grapple with regulatory complexities, many are turning to regtech solutions to enable and support their compliance efforts. The goal isn’t just to avoid non-compliance penalties but to strengthen trust and credibility with customers. The report, ‘Hooked: RegTech Reliance in Capital Markets Compliance’ by Greenwich Associates states that 63% of firms recognize that reputation protection is the core purpose of compliance.  
     
  4. Communication – Compliance teams are also struggling to keep pace with electronic communication channels, with 45% saying they are in constant catch-up mode rather than proactive mode, when it comes to electronic communication compliance, according to a report by Smarsh.
     
  5. Technology: The use of AI in regulatory compliance is helping both regulators and businesses. A recent Deloitte poll stated that nearly half (48.5%) of C-suite and other executives at organizations that use AI expect to increase AI use for risk management and compliance efforts in the year ahead. But only 21.1% of respondents report that their organizations have an ethical framework in place for AI use within risk management and compliance programs.
     

Compliance is now a key topic of discussion at the executive level, and is also a strong part of core business strategy. Newer technologies like AI and advanced analytics are helping compliance teams deliver value to the business in the digital age.

Compliance Week’s second annual technology survey highlighted that, ‘’companies are moving along the technological maturity curve in qualitative and quantitative ways today’’. According to the survey, companies are willing to spend more in 2019 than they were even a few years ago to build a more robust technology-enabled compliance function. Nearly, a quarter (23%) of compliance practitioners said their technology budget is much larger today than it was three years ago.

As compliance teams strive to do more with less, the emergence of new technologies will not only improve efficiency and cost-effectiveness, but will also enable teams to derive quick, meaningful insights from data to make well-informed decisions.

Admin_avatar_1498731489

BLOG ADMIN

Read more about the latest happenings in the GRC universe. MetricStream experts share their valuable insights on how organizations can turn risk into a strategic advantage and thrive on risk.

 
Blogs

Through the GRC Lens – September 2019

Blog Image
4 min read

Rethinking Cybersecurity in a Disruptive Age

With an increasing number of attacks in the market, despite more sophisticated cybersecurity solutions, many cybersecurity reports and surveys highlight why organizations need to rethink their cyber strategy and what’s in store for the future. – Here is what the media headlined through the GRC lens in September.

As attackers get more relentless with the volume and speed of their attacks, cybersecurity defense must safeguard all possible points of the attack surface. A recent survey of internal auditors published in City AM, found – cybersecurity, regulatory change, and digitalization to be the top three risks faced by businesses across Europe. The shortage of cybersecurity talent exacerbates the cybersecurity problem in a complicated enterprise environment.

Increasing cybersecurity resources

According to CISO Magazine, cybersecurity has emerged as a primary investment priority for financial firms in the United Kingdom. Reports from a survey conducted by Lloyds Bank states that cybercrimes have jumped to the fourth position from the eighth place since 2018. Banks in UK are increasing their budget allocation to enhance cybersecurity capabilities at their organization, Computer Business Review reported.

In another survey conducted by Infosys, targeting 867 senior executives representing 847 firms from 12 industries, with annual revenues over US$500 million across US, Europe, Australia and New Zealand (ANZ), reported that almost half (48%) of corporate boards and 63% of business leaders of surveyed enterprises are actively involved in cybersecurity strategy discussions.

While organizations have started to invest in building an efficient cybersecurity management and mitigation program, they still continue to face difficulty juggling priorities.

The Cyber Roadblock

A recent study conducted by BitSight, revealed that every two in five (38%) companies stated that they’ve lost their businesses due to lack of cybersecurity capabilities. An article by Forbes, ‘The Gap Between Strong Cybersecurity And Demands For Connectivity Is Getting Massive’, states, “…More devices and less adequate resources mean the attack surface continues to grow. “Every second that it takes to respond to an attack after it’s been deployed can have a huge impact on the business, be it in terms of man hours spent or sales, and reputation lost.”, states SC Magazine.
 

Even as enterprises invest in resources and tools to strengthen cybersecurity, why does it continue to be an Achilles heel for so many? The month of September revealed a few of the reasons:

  1. Human error is a big risk99% of email attacks rely on victims clicking links

Proofpoint’s Annual Human Factor Report, states that out of the vast majority of attacks, 99%, require some level of human input to execute – making individual users the last line of defense.

2. Businesses haven’t made it as much of a priority as it should be – Businesses are bypassing security to get to market quicker

A recent article by ITProPortal, highlights a research from Outpost24 which concludes that 34% of organizations bypass security to get products out to market faster. Almost two thirds (64%) of the respondents said they believe their customers could easily be breached, as a result of unpatched vulnerabilities in their organization’s products.

3. Third parties aren’t being monitored sufficiently

This month, thousands of resumes were exposed in a third-party breach that originated from monster.com, but the company denied any responsibility, saying – the client “owns the data.” According to CPO Magazine, “Though Monster.com’s denial of responsibility is legally acceptable under United States federal law, it puts the company at odds with the standard data protection requirements of a number of other nations.” This is yet another example of third-party risks being a great cybersecurity risk multiplier.

Cybersecurity is a complex problem with no easy solutions. Enterprises need to act quickly as the costs of data breaches are increasing at an alarming rate. According to Dark Reading, “The cost of breaches will rise by two-thirds over the next five years, exceeding an estimated $5 trillion in 2024, primarily driven by higher fines as more jurisdictions punish companies for lax security.” Juniper predicts that data breach costs will grow at 11% each year. The Ponemon Institute’s “Cost of a Data Breach” report, sponsored by IBM, pegs growth at 12% between 2014 and 2019.

Stepping up the cyber game

Unfortunately, 2019 was the year of data breaches with some record setting fines faced by companies like Equifax, British Airways and Marriott. The good news is that progress is being made:

1. Cybersecurity decisions involving the C-Suite:

Companies are fortifying their cyber strategies in alignment with business objectives. Defending threats requires the C-suite support, more than ever now. According to CPO Magazine, it’s important for security teams to make business leaders aware of the quickly shifting threat landscape.

2. Companies Are Forming Cybersecurity Alliances:

Over the last few years, cybersecurity alliances are being formed between tech-focused companies to support each other aimed at changing the ways companies deal with cybersecurity vulnerabilities and renegotiating the social contract between states and their citizens. The exchange of information is an effort to raise the collective level of cybersecurity, shape overall security practices, and speed the adoption of security technologies.

3. Artificial Intelligence Is Changing the Cyber Security Landscape and Preventing Cyber Attacks:

New advances in tech hold great promise to build cyber resilience. An article in Entrepreneur highlights how AI is a boon in cybersecurity, by stating, “Developers are using AI to enhance biometric authentication and get rid of its imperfections to make it a reliable system… AI-ML can detect and track more than 10,000 active phishing sources and react and remediate much quicker than humans can… AI-based systems proactively look for potential vulnerabilities in organizational information systems.”

Rethinking cybersecurity strategies has become imperative. With the changing landscape of cyber defense and new tools in the market, enterprises need to focus on building a holistic cybersecurity approach to deliver an effective awareness training and layered defense strategy. A strategy that provides enterprise wide visibility to better protect the company and its customers in a more efficient and proactive manner.

Admin_avatar_1498731489

BLOG ADMIN

Read more about the latest happenings in the GRC universe. MetricStream experts share their valuable insights on how organizations can turn risk into a strategic advantage and thrive on risk.

 
Blogs

A Look Back at the GRC Summit 2019

Blog Image
5 min read

Introduction

Now in its seventh year, the GRC Summit hosted by MetricStream is one of the biggest and most anticipated events for GRC practitioners around the world. This year, the summit was held on June 2-5 in Baltimore, Maryland, bringing together over 450 GRC and business leaders to talk about the latest trends and opportunities in GRC. It was an incredible four days of learning, discovery, and collaboration—topped off by an exclusive cruise, as well as a glittering awards ceremony.

Here are some of the top highlights from the summit:

  • Integrity Front and Center

In keeping with the theme of the summit—”Perform with Integrity™”—many of the speakers pointed out that financial performance is no longer the sole indicator of success. Trust is what really drives business today, and integrity is what drives trust.

MetricStream CEO, Mikael Hagstroem talked about building integrity by fostering a sense of compassion in the way we approach customers, the way we treat employees, and the way we shape the future of technology. “Successful performance—be it an individual level, an organizational level, or a global level—begins with a spark of passion that, when guided by integrity and compassion, helps us improve the human condition, and enable a higher quality of life,” he said.

MetricStream Chairman, Gunjan Sinha, emphasized the need to build purpose-driven organizations where doing good is as much of a priority as doing well. A strong sense of purpose, he predicted, is what will define the successful organizations of the future, along with a commitment to diversity, inclusion, empowerment of the front line, ethical data, and social conscious AI.

  • Tony Scott on the Key Transformation Drivers of the Next Five Years

The former Chief Information Officer of the United States government (2015-17) described how “relentless digitization” is rapidly upending traditional analog business models. And with it, the notion of security and privacy by design is becoming more important than ever. Technology is moving faster than we’re prepared for, he cautioned. Do we understand the risks of new tools like AI and machine learning? How do we build good governance, accountability, and transparency around these new technologies? How do we keep humanity at the center of innovation? All key questions to consider.

  • Jim Quigley: Coping with the “Knowns” and “Unknowns” of Business

Drawing on his experience as a member of the board and risk committee at Wells Fargo, as well as CEO Emeritus of Deloitte, Jim Quigley talked about why the work of GRC practitioners is so critical in helping boards and management teams make better strategic decisions in the midst of escalating “known unknowns” and “unknown unknowns.” He also emphasized the importance of building sustainable risk cultures. “The biggest driver of culture in any organization is observable behavior,” he said, quoting a colleague. “We want people to raise their hands and identify problems as quickly as possible.”

  • The Power of Innovation

MetricStream’s Chief Technology Officer, Andreas Diggelmann, along with Chief Innovation and Cloud Officer, Vidyadhar Phalke, delved into the new technology innovations that are emerging across the whole chain of GRC. Chatbots, for instance, are being used to capture issue data from the first line of defense in a manner that is simple and engaging. Predictive analytics are being used in the second and third lines to anticipate and respond to potential emerging risks proactively. Machine learning tools are enabling executive teams to detect risk patterns, and understand optimal mitigation practices based on historical evidence. Essentially, the possibilities with technology are endless.

 

  • Anna Felländer on Being Vigilant to the Ethical Risks of AI

Co-founder of the AI Sustainability Center, Anna Felländer pointed out that in a data-driven world, AI is key to helping organizations build better operational efficiency and deeper client relationships. Yet, it also introduces many ethical risks around the misuse/ overuse of the technology as well as multiple biases. If we want to avoid these pitfalls, we need to start investing as much in the humanistic side of AI as the engineering side, she said. We need to shape a future where humans lead AI, not the other way around. We need to find ways of ensuring that technology doesn’t get ahead of regulation.

  • Risk Management Is Everyone’s Responsibility

Many of the speakers emphasized the need to strengthen risk awareness at every level of the organization, right from the front lines to the boardroom. “Risk needs to be something that companies walk, talk, eat, and breathe every day,” said Kenneth Bacon, Member of the Board, Comcast, and Co-founder and Managing Partner, RailField Realty Partners. We need to have more risks and issues self-identified by the business rather than by internal audit or regulators, pointed out Sarah Dahlgren, Head of Regulatory Relations – Corporate Risk, Wells Fargo & Company. The more proactive the first and second lines of defense are in reporting risk data, the better informed and more confident the board and management team can be in their strategic decision-making processes.

  • In a Fast-Changing World, GRC Must be Agile

Disruption is the only constant in business today, pointed out MetricStream’s Chief Operating Officer, Gaurav Kapoor. If we want to be prepared for the new risks around the corner, GRC programs have to be agile, he said. Other speakers talked about what agility entails. Raven Catlin, Former CAE and Industry Expert in Internal Audit and Risk Management, described how internal audit must be ready to embrace new tools, new skills, and new approaches to auditing. Michael Rasmussen, Chief GRC Pundit, GRC 20/20, highlighted the importance of integration and collaboration in building more agile GRC functions.

  • A Celebration of GRC Champions

The much-anticipated GRC Journey awards ceremony, held on day 1 of the summit, recognized and honored MetricStream’s business partners, individuals, and customer organizations that have made significant strides on their GRC journey towards strengthening business performance. This year, there were 17 award recipients across five categories.

  • Connecting and Collaborating

There were plenty of opportunities for attendees to connect, share with, and learn from with each other – be it the many interactive workshops and networking sessions, or the relaxed “happy hours.” Day 2 of the summit culminated in an exclusive cruise down Patapsco River which saw attendees letting loose and singing their hearts out at a Karaoke session.

Jump to Topic
Admin_avatar_1498731489

BLOG ADMIN

Read more about the latest happenings in the GRC universe. MetricStream experts share their valuable insights on how organizations can turn risk into a strategic advantage and thrive on risk.

 
Blogs

MetricStream’s Enterprise GRC Solution awarded GRC Product of the Year by Risk.net

blog
3 min read

Introduction

A few weeks ago, MetricStream was awarded “GRC Product of the Year” at the 2019 Risk Technology Awards hosted by Risk.net. It was a strong validation of MetricStream’s mission to help organizations “Perform with Integrity™”. Through our GRC platform and solutions, customers are able to effectively understand and manage the interconnectedness of their risk environment, while deriving actionable risk insights for business decisions.

Why GRC Matters More Today Than Ever Before

Over the past year, multiple financial services organizations have faced penalties and fines from regulators for facilitating money laundering, manipulating customer accounts, and mishandling security trading. Meanwhile, serious IT meltdowns and cybersecurity incidents have severely impacted brands and reputations. Added to that, operating markets and business models are continuously being disrupted.

To stay ahead of these risks—both “known” and “unknown”—in an increasingly hyperconnected, fast-changing world, organizations need timely risk insights that can help them make swifter and better business decisions. They need to be aware of how a potential incident enhance their risk exposure. These objectives are best achieved with a strong governance, risk, and compliance (GRC) foundation.

What Differentiates MetricStream’s GRC Offerings

We believe that there are several factors that led to us winning GRC Product of the Year:

1. Support for Multiple Evolving GRC Roles

Chief Risk Officers (CROs), Chief Compliance Officers (CCOs), Chief Information Security Officers (CISOs), Chief Sourcing Officers (CSOs), and Chief Audit Executives (CAEs)—once limited in their roles—are increasingly being given a seat at the table with the power to influence strategy and decision-making. With this new power comes new obligations and challenges. 

At MetricStream, we focus on addressing these challenges through our GRC platform, solutions, and apps. We thematically look at the core needs of each GRC persona—be it the CRO, CCO, CISO, CSO, or CAE—and provide tailored solutions to meet those needs. We also deliver specific content, workflows, and reports to help various personas make informed decisions that are aligned to their business objectives.

Our wide array of packaged apps, which can be enhanced with third-party applications, are designed to improve risk visibility and intelligence. Underlying these apps is our cloud-enabled, future-ready GRC platform that provides customers with long-term value throughout their GRC journey.

Our integrated GRC solution enables a high level of cohesiveness across core GRC components which, in turn, improves risk assessments, predictions, and mitigation. Organizations can effectively balance risks and rewards, make confident strategic decisions, and respond to the changes that occur within and outside their enterprise. 

2. Balance Between Autonomy and Aggregation

At MetricStream, we understand that while the core requirements of GRC are more or less consistent across organizations, the processes, priorities, and needs of each organization are unique. Therefore, we offer flexible product alignment which allows customers to choose from multiple best-in-class, out-of-the-box GRC products that can be used along with third-party applications. Our apps and solutions provide agile risk reporting capabilities, while advanced analytics empower GRC practitioners to visualize large datasets within intuitive and interactive dashboards in real time. 

3. Leadership in Addressing the Interconnectedness of Risk

The hyperconnectivity of markets has created both known and unknown dependencies and interconnections within and outside the enterprise. This, in turn, has increased the interconnectedness across different types of risks.

The MetricStream GRC Platform has been built to comprehend these risk relationships and to deliver contextual insights though the aggregation and analysis of risk information. Our customers have adopted the platform along with built-in best practices and modifications to identify, understand, quantify, and predict the multiple points of impact for any risk event.

4. Focus on Long-term Partnerships Based on Value Delivery

MetricStream is focused on being a long-term strategic partner to customers as they grow and transform along their GRC journey. Our GRC advisory framework and methodologies help organizations build a multi-year GRC vision and roadmap that augments value realization based on a “true platform” strategy.

Through our value discovery workshops, we enable customers to identify key value propositions that can be measured as outcomes throughout the design and implementation of their GRC programs. Our GRC Journey initiative adds a further advantage by helping customers understand the current and future state of their GRC programs, so that they can then re-engineer existing GRC processes for optimal business benefits.

***

As we continue to find new ways of enabling and supporting our customers, we’re deeply grateful to Risk.net for the recognition and award received. We look forward to continuously raising the bar on innovation, and delivering products that truly empower our customers to Perform with Integrity™. 

Admin_avatar_1498731489

BLOG ADMIN

Read more about the latest happenings in the GRC universe. MetricStream experts share their valuable insights on how organizations can turn risk into a strategic advantage and thrive on risk.

 

Related Resources

Blogs

Through the GRC Lens: March 2019

blog
3 min read

Introduction

Google runs into trouble yet again with regulators in the EU, the SEC accuses Volkswagen of carrying out “a massive fraud,” and the FTC launches an inquiry into the privacy practices of large internet service providers — see March 2019 through the GRC lens.

Google Is Fined $1.7 Billion in the EU for Antitrust Violations

Google ran into fresh trouble with European regulators over its unfair advertising rules and was fined $1.7 billion in March, bringing the total cost of penalties incurred by the search giant in the continent to over $9 billion.

The latest enforcement action from the European Union (EU) relates to the unfair terms that the Silicon Valley titan imposed on companies that used its search bar on their websites in Europe, reported The New York Times.

According to The Guardian, the terms of the Google contract stopped publishers from placing search ads from the tech giant’s competitors on their results pages, and forced them to reserve the most profitable spaces for Google’s own ads. The contract also required companies to seek a written approval before making changes to how rival ads were displayed.

Volkswagen Is Accused of Large-Scale Fraud by the SEC

The US Securities and Exchange Commission (SEC) filed a lawsuit last month accusing the German carmaker and its former CEO, Martin Winterkorn, of defrauding American investors in the emissions test scandal that engulfed the company four years ago.

The lawsuit alleged that the company made misleading claims about its financial health and the environmental impact of its technology in order to sell securities to investors at inflated prices, reported CNN.

The German carmaker admitted in 2015 to cheating on emission tests with the use of special software in its vehicles and paid a hefty price of $33 billion in fines and other penalties.

The FTC Will Look into the Privacy Practices of Broadband Providers

In a surprise move last month, the Federal Trade Commission (FTC) announced that it would look into the privacy practices of large internet service providers (ISPs) such as AT&T, Verizon, T-Mobile, and others.

According to The Verge, the watchdog has asked broadband providers to share details about the kind of customer data they collect and the reason for doing so. The FTC was also said to be interested in knowing whether the data was shared with third parties, and if consumers could opt out of the data collection. 

The announcement of the inquiry into ISPs comes as privacy advocates raise concerns over the companies’ data collection practices that could lead to a new form of targeted advertising, similar to that of Facebook and Google.

The Perspective

Massive fines and other regulatory actions making headlines every other day only go to show that companies still seem to be floundering in their efforts to cope with heightened regulatory scrutiny targeted at their business practices.

Silicon Valley giants such as Google currently face a reckoning over their anti-trust practices in the EU which has established itself as an aggressive tech watchdog, influencing regulatory polices around the world. Meanwhile, the Volkswagen scandal is another reminder of the far-reaching consequences of compliance violations that could threaten a company’s brand reputation and market capitalization.

As privacy concerns escalate, the FTC’s move against broadband companies is only the beginning of a new era of intensifying scrutiny of data collection practices across industries.

Admin_avatar_1498731489

BLOG ADMIN

Read more about the latest happenings in the GRC universe. MetricStream experts share their valuable insights on how organizations can turn risk into a strategic advantage and thrive on risk.

 

Related Resources