Governance, Risk, and Compliance

Take a look at the big picture
Thrive > Compliance & Regulatory Services > Managed GRC Programs > Governance, Risk, and Compliance

A Unified Outlook

Governance, risk, and compliance is an approach that unites your internal policies, risk assessments, security technologies, and compliance requirements. It is easy for each of these teams to operate independently, but that introduces the possibility of lack of ownership of compliance requirements, misaligned objectives, or inadequate security tools.

Overwhelmingly, business leaders say that they cannot confidently track or verify that their compliance program is effective – 63% according to Gartner surveys. This is the problem that a GRC program is designed to solve. GRC encourages collaboration, visibility, and clear ownership and alignment.

Seeing GRC as Process - People - Technology

“People, process, technology” has existed as an operating model for organizations since 1965. An organizational psychologist, Harold Leavitt, defined the model to describe how to introduce change withing an organization. This simple model still resonates today because of how clearly it identifies relationships, even hidden dependencies, within an organization or team.

The GRC framework follows that familiar pattern:

  • Governance, or policies, relates to process
  • Risk relates to people (including vendors and your supply chain)
  • Compliance relates to technology

Achieving a compliance certification for the first time – or trying to maintain certification after a major change – requires buy-in from across your organization. GRC takes a holistic approach and works as change management function encouraging cross-team communication, visibility into systems, and clear reporting.

Having a partner to help establish and run a GRC program can help. A compliance advisory service brings impartiality and experience to help your teams effectively navigate change and achieve your objectives.

Meeting, woman and collaboration with colleagues, boardroom and discussion for stats, team and company. Corporate, employees and people with info for business, planning and communication for updates
Meeting, woman and collaboration with colleagues, boardroom and discussion for stats, team and company. Corporate, employees and people with info for business, planning and communication for updates

Phases of a GRC Program

A mature GRC program is built through consistency and collaboration. Thrive’s GRC consultants follow a pattern for all of our compliance clients to ensure that the details within the security requirements, controls, and organizational objectives are visible and managed. Each phase emphasizes communication, co-ownership of tasks, and transparency.

Assessment: Find Your Starting Point

  • Perform a current gap analysis
  • Outline organizational goals and priorities
  • Evaluating process and control frameworks (6-8 working sessions)
  • Create a security plan
  • Set up a regular meeting cadence

Office Network icon

Implementation: Realign Your Technology and Policies

  • Create a compliance portal, including user training
  • Create a plan of action and milestones (POAM)
  • Set up activities, tasks, and user assignments in the compliance portal
  • Update or create necessary policies

Helpdesk and Support icon

Audit Liaison: Provide Clear Communication and Advice

  • Validate evidence to submit to the auditor and assist with the reporting
  • Communicate with the auditor in advance of and during the audit
  • Review the auditor’s information request list and prepare any additional tasks or evidence

 

Assessment icon

Continuous Compliance: Maintain Your Compliance Posture

  • Shift to monthly meetings for the compliance team
  • Set up quarterly reviews for the POAM (if necessary) and security plans
  • Set up annual reviews for:
    • Processes and controls
    • Risk assessments
    • Policies

Insight at Your Fingertips

One of the keys of an effective GRC program is the ability to maintain visibility across your IT infrastructure. Thrive has a complete suite of tools to give insight into the current state of your compliance landscape:

  • Compliance dashboards and reporting (through the compliance portal)
  • Security issues, vulnerabilities, and status (through the Client Portal)
  • Co-managed ticketing (through TransformIT)

Better insights help you track your maturity against any security or risk-based standard.

Modern technology studio employees using computers to develop new graphics

What Sets a GRC Program Apart

A GRC program is much more than a checklist. The focus should be on visibility, integration, and monitoring to ensure that compliance standards are being maintained and can be checked at any time.

As a technology foundation, a good GRC program incorporates:

  • Continuous monitoring
  • Automatic controls validation
  • Managed compliance portal, with evidence collection, documentation, policies, and other tasks
  • Evidence organization and accessibility for audit review

For process management:

  • Gap assessments and baselines
  • Project roadmaps, priorities and timelines
  • Integration with security tools and teams

And, arguably most important, people and team support:

  • Consultants with experience in policy development, framework controls, and audits
  • Liaisons and support during the audit and attestation processes
  • A broader ecosystem of security, infrastructure, and advisory teams to augment your IT project teams