The Compliance Certification Board (CCB)® has approved this event for up to 15.6 Live CCB CEUs each based on a 50-minute hour, each.. Continuing Education Units are awarded based on individual attendance records. Granting of prior approval in no way constitutes endorsement by CCB of this event content or of the event sponsor.
Day 0: Tuesday, June 13, 2023
Workshop 1 (Orchid A & B)
Enterprise GRC by Design Workshop: Blueprint for an Effective, Efficient & Agile Enterprise GRC Management Program
Enterprise GRC by Design is something an organization does and not something an organization buys. GRC, done properly, is what is achieved throughout the business and its operations. By definition, GRC is “a capability to reliably achieve objectives [governance] while addressing uncertainty [risk management] and acting with integrity [compliance].” This requires that GRC needs to be understood in the context of enterprise strategy, objectives, architecture, and processes. GRC by Design requires an enterprise/organization architecture approach to the organization and how it operates.
Michael Rasmussen
GRC Analyst & Pundit, GRC 20/20 ResearchWorkshop 2 (Orchid C)
GRC at an Inflection Point: Practical Strategies and Approaches to Modern Risk and Compliance
There are a few industries and business practices that have changed as much in the last few years as risk and compliance management. Always relevant, always important, those who manage and lead risk and compliance programs have seen increases in risk volume, speed, and severity, as well as the migration of risks out their traditionally defined categories. Today, GRC professionals have their hands full as changes in the market continue to accelerate. Join GRC expert and educator, Chris Mandel, for a two-hour workshop, GRC at an Inflection Point, prior to the MetricStream GRC Summit, in Miami, on June 13, from 2:30 pm to 4:30 pm. Learn about new approaches to capture, manage, and mitigate risks from across your organization, trends in best practices, and how latest technologies are helping businesses like yours to adapt to a rapidly changing GRC landscape. You don’t want to miss this one!
Christopher E. Mandel
Founder & President, Excellence in Risk Management, LLCWorkshop 3 (Orchid C)
What’s on Your Roadmap for a “Next Generation” Third Party Risk and Cyber Risk Management Program?
Third-party/vendor risk management (3PRM) is a recurring agenda item for C-suite executives and board members, reflecting the increasingly complex extended enterprise and rapidly changing threat landscape. It’s also one of the top factors affecting cyber risk today. 3PRM is an enterprise-wide "team sport" and a fascinating risk discipline that affects business leaders, procurement, compliance, IT, risk specialists, senior leadership, audit, and the board of directors.
Most organizations today are actively seeking proven best practices that strengthen third-party risk management capabilities, drive more value, and improve efficiency. And its undeniable connection to cyber risk has made it even more topical, making it a must for you to master today.
This Advanced Workshop will prepare you to create your organization’s “3PRM Next Generation” Roadmap. Your questions about “what”, “why”, “how” and “when” will be answered by subject matter expert, practitioner, and third-party risk management guru Linda Tuck Chapman.
What You’ll Learn:
- Evaluating your current state vs best practices
- Identifying, prioritizing, and sequencing high impact opportunities
- Calibrating risk insight, risk oversight, and work effort across the portfolio
- Managing the intersection of 3PRM and cyber risk
- The critical elements for your “Next Generation” 3PRM roadmap
What is your takeaway?
Whether third-party risk management is new to you or you’re looking for ways to improve efficiency and effectiveness, this Advanced Workshop is guaranteed to deepen and broaden your knowledge about effective and efficient third-party risk management practices.
- Learning Objective 1 - Upon completion, participants will be able to develop a solid approach for evaluating their current state, identifying strengths and opportunities.
- Learning Objective 2 - Upon completion, participants will be able to integrate and apply information and awareness about proven tactics to improve the effectiveness of existing practices.
- Learning Objective 3 - Upon completion, participants will be able to demonstrate understanding how to build a 2-3 year roadmap to strengthen their organization’s 3PRM program.
Linda Tuck Chapman
CEO, Third Party Risk Institute LtdDay 1: Wednesday, June 14, 2023
Registration & Networking Breakfast
(Lower Promenade)
Welcome Note
(Jasmine)
Introduction and Welcome
Patricia McParland
AVP, Head of Product Marketing, MetricStreamOpening Keynote
Experience the Power of Connection
Gaurav Kapoor
CEO and Co-Founder, MetricStreamDavid Anthony Storey
Vice President Health, Safety, Security & Environment, dnataRobert Foster
Chief Information Officer, National Credit Union AdministrationEileen Fahey
Chief Risk Officer, Fitch GroupFireside Chat
Moving from Risk to Resilience: The Future of Risk Management
The recent banking crisis, along with the economic slowdown, complex risk landscape, and market conditions, have forced risk leaders to rethink their risk strategies and approach to resilience. A strong operational risk management program backed by data and analytics will help organizations take a forward-looking approach towards risk, reward outcomes, and enable the organization achieve operational resilience.
George Smirnoff
Managing Director, Group Head of Operational Risk, BarclaysGaurav Kapoor
CEO and Co-Founder, MetricStreamProduct Session
Preparing You for What’s Next With Connected GRC
Prasad Sabbineni
Co-CEO, MetricStreamJoy Bhowmick
Senior Vice President, Product Development, MetricStreamRaghuram Srinivas
Head of Product, MetricStreamNetworking Break
(Lower Promenade)
Track 1 (Jasmine)
Track 2 (Orchid A, B & C)
Panel
Building Agile Programs for Enterprise, Operational, and Cyber Resilience in Today's World
In today's fast-moving world, organizations need a proactive approach to manage high-velocity, high-impact risks and strengthen resilience effectively. Agility is key. What are the best practices to boost agility in your enterprise, operational, and cyber risk management programs? Join this expert panel to understand how to develop a framework that enables organizations to quickly adapt to the rapidly evolving risk landscape, the benefits of implementing an agile approach, the role played by technology, and more.
Manesh Shah
Vice President, Enterprise Risk Management, CBRECynthia Klimaszewski
Head of Technology Risk, Silicon Valley Bank, a division of First CitizensLadd Muzzy
Global Director, Strategic Risk Advisory, Aon
Expert Talk
Unlocking Cloud Compliance: Optimizing Audits with Automation
As businesses adopt cloud in multiple ways, from single to hybrid setups, the task of maintaining a robust control environment for compliance and audit teams becomes increasingly intricate. In this session, we will discuss how control testing of cloud infrastructure can be automated and explore how Governance, Risk and Compliance (GRC) professionals can effectively leverage the results to bolster overall security and compliance efforts.
Neha Singh Rajpurohit
Senior Product Manager – Technical, AmazonAnil Kumar
AVP, Product Manager - IT and Cyber Security, MetricStreamPanel
Effectively Managing Operational Risks Through Control Rationalization for Improved Decision-Making
Effective management of operational risks requires an understanding of the various risks faced by an organization and setting up appropriate controls to manage those risks. Control rationalization -- evaluating the control environment to eliminate redundant and unnecessary controls -- can enable organizations to quickly identify areas that need immediate attention and make changes to streamline and optimize control frameworks. This panel discussion will explore the benefits of control rationalization for managing operational risks and provide insights and best practices for implementing effective control rationalization programs.
Kellie Bickenbach
Head of Control Assurance, First Citizens BankPatricia Catharino
SVP, Head of Risk Management & Internal Controls, Itaύ U.S. and CaribbeanVarun Agarwal
Director - Enterprise Risk, Western Alliance BankSeth Rosensweig
National Integrated Risk Technology & Enterprise GRC Leader, PwC
Product Session
Power What's Next in Enterprise & Operational Risk Management
In today’s connected world, managing enterprise and operational risks requires a complete, collaborative approach – across the organization and across the extended enterprise, including your third parties. In this session, we will explore the importance of holistic enterprise and operational risk management strategies to identify and manage risk. Learn how MetricStream enables you to manage risk with structured approach with best practice risk assessment methodologies and standards, accurate understanding of risk exposure across your organization, and ultimately, to thrive on risk.
Anand Hanchinamani
Senior Director Product Management , MetricStreamPanel
How AI, Automation, and Emerging Technologies are Impacting Risks and Opportunities
Artificial intelligence and machine learning aren't new. They've been helping us analyze large volumes of data for many years now in risk management. But with the viral advent of technologies like generative AI (ChatGPT as one headline-grabbing example) -- what's next? How can we put AI to ethical, powerful use in cyber risk management while understanding and managing the all-new risks it opens up? How do policies play in? How do we proactively safeguard against an always-learning technology that we're also using to learn? Join our experts to delve into the AI/ML revolution -- a risk for sure, but also a tremendous opportunity.
Brian Fricke
Managing SVP, CISO, City National Bank of FloridaAlex Gacheche
Global Head of Information Security, Technology Infrastructure & Emerging Technology Audit, Meta
Panel
Reimagine Your Compliance Program with a Risk-Based Approach
A risk-based approach to compliance can reap multiple benefits including increased efficiency, cost-effectiveness, and improved alignment with business goals. Hear from experts as they explore how businesses can assess and prioritize risks and tailor their compliance efforts accordingly. The panelists will also discuss how businesses can build a culture of compliance and risk awareness, and the importance of the role of technology in facilitating risk-based compliance.
Ramsey Kazem
Regional Compliance Officer - North America, AndritzHemma Lomax
VP, Compliance, ZendeskMaxim Soltanov
Head of ESG Compliance, Norilsk Nickel USANick Malhotra
Associate Vice President, Global Compliance & Ethics, Royal Caribbean GroupNetworking Lunch
(Lower Promenade)
Guidewire Case Study
How to Build and Scale a Business Relevant Risk and Compliance Capability
Risks today are highly interconnected and moving fast. A siloed approach to managing governance, risk, and compliance (GRC) processes is no longer tenable in today’s hyper-digitized business environment. Organizations need to adopt an integrated and connected approach to GRC to gain a 360-degree view of their risk and compliance posture, and contextual risk information for better-informed decisions.
Grace Beason
Director of Governance, Risk and Compliance, Guidewire Software
Panel
The Future of Internal Audit: Harnessing the Power of Continuous Automation and Analytics
Organizations are increasingly shifting towards using technology to improve efficiency and accuracy in auditing processes. By utilizing tools such as artificial intelligence, continuous automation and data analytics, auditors can identify patterns and trends that may have been missed with traditional auditing methods. Hear from our expert panelists as they explore the benefits and challenges of implementing continuous automation and analytics in internal auditing, and discuss how this approach can shape the future of the industry.
Christopher Geiger
Vice President of Internal Audit and Enterprise Risk, Lockheed MartinGuillermo Finck
Sr. Vice President - Corporate Audit Services , FiservIleana Canlas
CEO, COO, Ileana Canlas & AssociatesApple Bank Case Study
Jonathan Ruf
First Vice President - Head of Cyber and Information Risk, Apple Bank
Blue Cross Blue Shield of Michigan Case Study
Nicholas Cannon
Manager, Blue Cross Blue Shield of MichiganJason James
Senior Business Systems Analyst, Blue Cross Blue Shield of MichiganProduct Session
AiSPIRE
GRC professionals, from risk leaders to compliance officers, auditors, and security managers, need a more dynamic and "just in time" approach to keep up with the fast-evolving risk and regulatory landscape. There is an urgent need to move beyond automation and embrace cognitive technologies that not only perform mundane, repeatable tasks but also provide intelligent recommendations to address any issues. In this session, we will deep dive into MetricStream’s latest AI-based innovations that will enable you to enhance your GRC program and strategy by improving efficiency, optimizing recurring cost, and freeing up team’s bandwidth for new and more critical activities.
Raghuram Srinivas
Head of Product, MetricStream
Panel
Managing the 4 Cs of Compliance: Corporate, Culture, Conduct, and Communication
The 4 Cs of compliance: Corporate, Culture, Conduct, and Communication are critical for effective compliance within an organization. From establishing policies that align with regulatory requirements to promoting a compliance-focused culture within the organization, monitoring and enforcing compliance policies and effectively communicating compliance expectations to employees and stakeholders the four Cs play a vital role. Hear from the expert panelists as they provide valuable insights on how to manage these four elements of compliance.
Emily Wall
VP, Global Ethics & Compliance, Live Nation EntertainmentCarlos Pereira
Head of Governance & Policy, MetaJerry Storey
Principal, Regulatory Compliance & Business Strategy , FedEx LogisticsJennifer D Newton
Chief Compliance & Ethics Officer, CaddipayNetworking Break
(Lower Promenade)
Expert Talk
(Jasmine)
2023 GRC Trends and Strategies: Aligning GRC Efforts with Business Priorities to Deliver Forward-looking Insights
Join this session to hear industry experts discuss the latest Governance, Risk Management, and Compliance trends and strategies for the year 2023, and how to align GRC efforts with business priorities. Learn more about the challenges businesses face when implementing GRC strategies, how to overcome them and best practices for integrating GRC into strategic planning, risk management, and performance management processes.
Alla Valente
Senior Analyst, ForresterPanel
Modernizing Governance, Risk, Compliance, Cyber and Audit to Enable Resilience
Be part of this C-level discussion that focuses on how modernizing governance, risk, compliance, cyber and audit functions can enable organizational resilience. Learn how to build a true resilience strategy, and how to use proactive processes with a centralized approach. The speakers will also be discussing on how best to leverage the latest tools and technologies, including automation and artificial intelligence, to streamline GRC and audit processes.
Brian Fricke
Managing SVP, CISO, City National Bank of FloridaMarcelo Cruz
Managing Partner, Yacamy AdvisorsEileen Fahey
Chief Risk Officer, Fitch Groupdnata Case Study
David Anthony Storey
Vice President Health, Safety, Security & Environment, dnataClosing Keynote
Future-Proofing Your Organization: Turning Risk into a Strategic Advantage
Future-proofing your organization is the process of preparing for potential changes and disruptions in the future. Embarking on future-proof strategy can also help organizations stay ahead of the competition, attract and retain top talent, and maintain customer loyalty. Hear from Gunjan Sinha, Executive Chairman, MetricStream and Harit Talwar, Board Member, Mastercard, on how organizations can become more resilient and adaptable and thrive in changing market conditions.
Gunjan Sinha
Executive Chairman, MetricStreamHarit Talwar
Board Member, MastercardGRC Summit Happy Hours
(Riverwalk Terrace)
GRC Journey Awards & Dinner
(Jasmine)
Day 2: Thursday, June 15, 2023
Networking Breakfast
(Lower Promenade)
Welcome Note
(Jasmine)
Patricia McParland
AVP, Head of Product Marketing, MetricStreamKeynote
Experience the Power of Connection
Prasad Sabbineni
Co-CEO, MetricStreamMichael Cover
Director, Blue Cross Blue Shield of MichiganBeth Rudofker
Risk and Control Executive & Senior Executive Advisor, PwC, Former - Citigroup, GEGavin Anthony Grounds
CEO & Co-Founder, Mercury Risk and Compliance, Former - Meta & VerizonPanel
Three Lines Model - Trends & Strategies to Drive Efficiency & Growth
The Three Lines Model is used to define roles and responsibilities for effective governance and risk management within organizations. In this panel discussion, experts will explore the latest trends and strategies to drive efficiency and growth through the three lines of defense model. Learn new ways to improve coordination and communication between the different lines of defense, as well as how to effectively use technology and data analytics to enhance risk management and decision-making.
Martin Froelick
Senior Vice President - Risk Manager, First Citizens BankMichael Cover
Director, Blue Cross Blue Shield of MichiganMichelle Melendez
Vice President - Head of Integrated Security Risk Management, AonNational Credit Union Administration Case Study
Designing Your GRC Program to Manage Interconnected Risks, Regulatory Changes, and Audit Requirements
Amber Gravius
Director and Chief Data Officer, National Credit Union AdministrationRobert Foster
Chief Information Officer, National Credit Union AdministrationExpert Talk
The Interconnected Crisis - Financial, Health, Political and Climate
Today, Governance, Risk, and Compliance (GRC) technologies are an essential part of modern business operations. These technologies are designed to help organizations manage their risks, comply with regulations and standards, and govern their operations effectively. With the rapid evolution of technology, GRC solutions have also evolved to keep pace with changing business needs and regulatory requirements. Join this session to explore the current trends and future prospects of GRC technologies.
Paul Shotton
CEO & Chairman, Tachyon Aerospace & White Diamond Risk Advisory, Former - Goldman Sachs, JP Morgan, UBSNetworking Break
(Lower Promenade)
Expert Talk
(Jasmine)
No Company is an Island: How a Connected World Creates New Risk Management Challenges
In this expert talk, the speakers will delve into the interconnectedness of modern businesses and the new risk management challenges that arise as a result. With the advent of globalization and technological advancements, companies are now part of a larger ecosystem that is constantly evolving and expanding. The session will explore the impact of supply chain disruptions, cybersecurity threats, and regulatory changes on businesses, and offer strategies for companies to mitigate these risks in a connected world.
Michael Rasmussen
GRC Analyst & Pundit, GRC 20/20 ResearchTrack 1 (Jasmine)
Track 2 (Orchid C)
Expert Talk
Incorporating Risk Quantification, AI, and Automation into Your Cyber Risk Strategy
How can cyber technologies help you accelerate and advance your cyber risk strategy -- from the front line to the board? Manual risk processes are reactive and no longer enough to protect your organization from today’s fast-moving risks, threats, and vulnerabilities. Emerging technologies are enabling proactive, autonomous work “done by machines” that free you up to focus on strategic decision-making while alerting you to and protecting you from risk.
Gavin Anthony Grounds
CEO & Co-Founder, Mercury Risk and Compliance, Former - Meta & Verizon
Autodesk Case Study
Clyde Tsai
Security GRC Lead, AutodeskPanel
Mitigating Cyber Risk and Ensuring Data Privacy in an Interconnected World
Join our panel discussion on mitigating cyber risk and ensuring data privacy in an interconnected world. Explore effective strategies for safeguarding sensitive information, balancing security with convenience, and addressing emerging threats. Our expert panelists will delve into topics like encryption, secure communication protocols, employee training, and regulatory compliance. Gain insights into protecting your digital assets in today's rapidly evolving cyber landscape. Don't miss this crucial conversation.
Oded Anderman
Program Manager, Anti Scraping & Threat Intelligence, Meta Platforms, Inc.David N Patariu
Attorney, Venable LLP
Product Session
Power What's Next in IT & Cyber Risk, Compliance Management
Cyber risks and attacks are escalating sharply, with data breaches at an all-time high cost of $4.4M – putting your organization at business, financial and reputational risk. In addition, new cyber regulations are being introduced, creating the need for fast disclosure time and robust compliance and risk management. Multiple standards and frameworks demand harmonization and automated controls testing. How can your organization meet these evolving risk management and compliance needs – across IT, security and the business? Join this session for practical advice and tips on how MetricStream can help.
Anil Kumar
AVP, Product Manager - IT and Cyber Security, MetricStreamNetworking Lunch
(Lower Promenade)
Expert Talk
Real-World Case Studies: Delivering Business Value and Operational Excellence Through Enterprise, Cyber Risk, and Compliance Management
As digital and cyber risks explode, a holistic approach to managing them is essential. The principles that apply to governance, risk, and compliance also apply to IT risk and compliance, especially as risks become more and more interconnected and attack surfaces expand. In this session, a practitioner will describe building a connected IT GRC/risk/compliance program from the ground up and the results generated.
Grace Beason
Director of Governance, Risk and Compliance, Guidewire SoftwareGavin Anthony Grounds
CEO & Co-Founder, Mercury Risk and Compliance, Former - Meta & Verizon
Panel
Unleashing the True Value of RCSA: Put Your Risk and Control Assessment to Work
Operational risks are inherent to the banking and financial services industry. Effective management of these risks has been a fundamental challenge for companies. Sound internal governance forms the foundation of an effective risk management framework. An effective RCSA process not only provides early warnings, but also helps organizations take strategic advantage of the risks they face.
Martin Froelick
Senior Vice President - Risk Manager, First Citizens BankArindam Majumdar
Deputy Chief Risk Officer, Bank OZKLadd Muzzy
Global Director, Strategic Risk Advisory, AonSurya Natarajan
Vice President – GRC, Vivid Edge CorpPanel
Integrating Enterprise Risk, ESG, and Third-Party Risk Management to Manage and Mitigate Interconnected Risks
The scope of organizational risks today is not just limited to enterprise and third-party risks but also environmental, social, and governance risks. Managing them requires an integrated approach -- understanding the risk relationships and impact in a connected and holistic manner. ESG aspects, including the ESG performance of third parties, have become critical in assessing risks and opportunities. Join this panel discussion to understand why an integrated approach is an absolute must and how it can help organizations enhance their sustainability, resilience, and long-term success.
Rodney Campbell
Senior Vice President and Head of Third-Party Risk Management, Valley National BankSanjiv Sharma
Vice President and Chief Audit Executive, Wolfspeed Inc.
Product Session
Power What's Next in Operational Resilience
Today, it’s not a question of “if” an adverse event – a cyber breach or other business disruption – might happen, especially in banking and financial services. It’s when. The past few years have taught us that business continuity is critical, but not sufficient. It’s not enough to be ready – you also must be resilient and prepared to recover and rebound quickly. In this session, we will discuss how to enhance risk visibility across your organization with automated workflows, collaboration and real-time reporting, embedded in a single platform.
Anand Hanchinamani
Senior Director Product Management , MetricStreamAmerican Fidelity Assurance Case Study
Tice Morgan
Sr. Manager, Governance and Compliance, American Fidelity Assurance
Expert Talk
Innovation and Transformation in Cloud Security and Risk
Nick Dimtchev
Partner Sales Manager - Security, Compliance, and Governance ISVs, AWS Global Financial Services (GFS)Expert Talk
Connecting the Dots in ConnectedGRC
Nanda Ramanujam
VP, Customer Success and Services Customer Services Americas, MetricStreamDoug Montgomery
Associate Vice President, GRC Solutions, MetricStream
Product Session
Low Code No Code
The foundation of a strong GRC and risk management program is a flexible, integrated software platform – one that is cognitive and powered by artificial intelligence for smart decisions; continuous and always available through automation and mobile; and cloud-based for fast access and easy, low-code updating. Explore the basis of the next generation of GRC – the MetricStream platform. Uncover new opportunities and discover the power of low-code/no-code.
Kiran Kumar Nakhate
Senior Principal Product & Platform Development Manager, MetricStreamNetworking Break
(Lower Promenade)
Expert Talk
Addressing Today's Third Party Risk Management (TPRM) Challenges
With ever-expanding needs and pressures of containing costs, businesses are increasingly turning to third-party providers, creating a complex landscape. As the reliance on third parties grows, so does the exposure to associated risks. The business case of an Integrated Third-party risk management (TPRM) is more important than ever. However, most studies indicate that corporations are not ready to manage critical third-party risks. Technology is not yet fulfilling its promise and the challenge of limited resources is here to stay.
Sanjiv Sharma
Vice President and Chief Audit Executive, Wolfspeed Inc.
Product Session (continue)
Low Code No Code
The foundation of a strong GRC and risk management program is a flexible, integrated software platform – one that is cognitive and powered by artificial intelligence for smart decisions; continuous and always available through automation and mobile; and cloud-based for fast access and easy, low-code updating. Explore the basis of the next generation of GRC – the MetricStream platform. Uncover new opportunities and discover the power of low-code/no-code.
Kiran Kumar Nakhate
Senior Principal Product & Platform Development Manager, MetricStreamClosing Keynote
(Jasmine)