Corporate Governance Risk And Compliance Management
Corporate governance risk and compliance management is often treated as an operational function. The reason it sits at board level is that directors carry duties personally.
Australian directors owe duties including care and diligence, and those duties are not discharged by delegation alone. A director who receives no information about a risk is not thereby relieved of responsibility for it.
What a board needs is line of sight. Not every detail, but confidence that material risks are identified, that someone owns each one, that failures reach the board rather than stopping two levels below, and that assurance comes from somewhere other than the people running the process.
A board that receives only good news usually has a reporting problem rather than an unusually well run organisation underneath it.
ASIC publishes guidance on directors’ duties. This is general information rather than legal advice, and obligations vary by state and territory.
See Sentrient’s GRC system and incident reporting software.
5 Keys to Effective (Governance Risk And Compliance) GRC Management For Australian Businesses
Quick Answer: Effective GRC management rests on five practices, not on a platform. Start with an honest risk assessment rather than a purchase. Use compliance training that has been legally endorsed rather than merely informative. Build governance that creates accountability rather than process. Run risk management continuously rather than annually. Then choose software built for […]
