Why a GRC Framework? | Governance Risk and Compliance - YouTube

Channel: unknown

[0]
Please watch our new animation and demo
[6]
by clicking on the i in the top right corner
[12]
of this video
[17]
Governance is about how an organisation has to be run in an efficient and responsible manner
[22]
and how they report their policy towards all stakeholders. Processes and goals of the organisation have to be aligned.
[28]
Compliancy is an integral part of this: the organisation has to run here policy within the existing Rules and regulations that apply to them.
[37]
This sounds simple, but is often difficult, because products and services and rules and regulations are often subject to change.
[44]
Finally every organisation has to identify all risks through risk management
[50]
and register the related management measures and then report on these.
[54]
The importance of embedding GRC in an organisation can have to do with, that an organisation wants to:
[60]
Steer performances
[62]
Improve the quality of their products and services
[65]
Prevent damage
[67]
And eventually be in control!
[70]
The difficulty is that most organisations don't see the interrelation between governance, risk management and compliancy.
[77]
Because of the many internal and external reports, rules and regulations and all responsibilities that arise,
[83]
an organisation easily loses the overview.
[86]
Most of the time GRC continues to be three separate fields of study
[91]
By structuring and relating governance, risk management and compliance, their impact on the business operations becomes clear.
[98]
These three pillars are combined in Rules GRC. It offers insight in the interrelations and their relation with the business processes.
[105]
This way an organisation gets more insight and overview and reporting and communicating on GRC becomes easy.
[112]
Let's take a look at the steps we will go through to succesfully embed GRC in the organisation.
[118]
First of all you Inventorise all information around processes, rules and regulations, policy, risk and managementmeasures
[126]
and then structure this information and relate everything to each other using the Mavim Rules application.
[131]
Subsequently you analyse, quantify and report on this information
[135]
When this has been done, you can communicate this information to the rest of the organisation.
[140]
By creating a publication for your intranet or SharePoint portal
[144]
all stakeholders can find information that is important for them.
[148]
The stakeholders can give feedback on the published information
[152]
whereupon this feedback can be used to monitor and improve.
[156]
Let's take a look at a demonstration of step 3 till 5. The information has already been published to the intranet
[162]
where the stakeholders can find the information.
[165]
Here we see the GRC startpage. From this startpage we can navigate to the processes, rules and regulations,
[172]
risks and management measures and management reports.
[176]
Let's navigate to the processes of the organisation. Next we will go the the primary process closing agreement.
[189]
We can also visualise this process in a chart. Here we see the process visualised in a process chart.
[196]
When we click on one of the activities of the process,
[200]
the description screen on the right gives us extra information on this activity.
[204]
Furthermore in the bottom right corner we see the relationship screen
[207]
screen where we can find all related information to this activity.
[210]
For example you can see which officials are involved in this process, which applications are used,
[215]
which risks could occur and which iso norms are related.
[219]
If you would like more information on these related topics, you can easily click on these topics.
[224]
We can also click on the risk related to this activity.
[228]
Here we see a short description of the risk, the short and long term effects
[232]
and we can see what the chance, impact and management measures are of this risk.
[237]
We can also view extensive reports where we see which risks are related to which processes.
[246]
In this process/risk chart we see all the primary processes of the organisation with the related risks,
[252]
type of risk, the chance, the impact and the management measures.
[260]
If you would like more information about a certain topic you can easily click on this topic.
[265]
For example we can click on one of the risks and subsequently we get insight in all meta information around this risk.
[275]
When we go back to the start page we can also directly navigate to the risks.
[281]
We can also view extensive reports where we can see which risks could take place in our organisation and see which processe are related
[288]
with the gross chance and impact, management measures and the nett chance and impact, the action log and the action holder and the follow-up date.
[300]
Let's go back to the startpage.
[303]
We have just seen how the processes, risks and management measures and underlying rules and regulations have been connected to each other.
[310]
This gives us the possibility to create several extensive management reports in a dashboard.
[317]
This gives us insight in which risks are related to processes.
[321]
Here you can also see a total overview of the identified risks within the organisation.
[326]
From this report you can also easily navigate to the related processes.
[330]
Subsequently the stakeholders can give feedback on the published information.
[335]
Here we see several forms that the stakeholders can use, like a feedback form, a risk self assessment form or a control comment form.
[346]
The end users can give their feedback here. This feedback is sent back to the Mavim Rules database,
[352]
where the Rules administrator can improve and communicate this information.
[356]
We have now taken a short look at the Mavim Rules GRC Framework.
[360]
If you would like to see more in depth video's on for example IT governance, Qaulity and Process management,
[366]
please feel free to take a look at our other video's.