Governance Risk And Compliance Challenges
Governance risk and compliance challenges are usually described as complexity. In practice three ordinary problems account for most of the difficulty.
Nobody owns it. A risk assigned to a department is assigned to no one. Ownership has to be a named person who can actually influence the risk.
Definitions differ. One team’s high risk is another’s medium. Without a shared rating scale the register cannot be sorted, and sorting is the point of having one.
The register goes stale. It is built during a project, reviewed once, and then referred to only when something goes wrong. A register nobody has touched in eighteen months describes the organisation as it was.
None of these three is solved by buying software, though decent software makes each of them visible enough to be fixed.
The ASIC publishes governance guidance. This is general information rather than legal advice, and obligations vary by state and territory.
See Sentrient’s GRC system and risk management system.
5 Common Governance Risk And Compliance Challenges, And How To Overcome Them
Quick Answer: The five governance risk and compliance challenges that persist in Australian organisations are unclear ownership of the GRC process, no single framework, keeping pace with regulatory change, manual processes that cannot produce evidence, and a gap between stated culture and actual behaviour. None is a technology problem at root. Each is a decision […]
