240 likes | 450 Views
Building a Foundation For Unified Grasp of GRC. Shaheen Javadizadeh , Vice President, Strategic Markets , Datacert Kathleen Edmond, Chief Ethics Officer , Best Buy Tim Strong, Managing Director , Duff & Phelps. Nov. 16, 2012. I wish it was this easy.
E N D
Building a Foundation For Unified Grasp of GRC Shaheen Javadizadeh, Vice President, Strategic Markets, Datacert Kathleen Edmond, Chief Ethics Officer, Best Buy Tim Strong, Managing Director, Duff & Phelps Nov. 16, 2012
I wish it was this easy You’ll feel much better afterward.
From culture to action to automation Interact Measure Respond Detect Proact Assess Organize Context Content by OCEG Redbook v2.0
Continual Alignment Interact Measure Respond Detect Proact Assess Organize Context Content by OCEG Redbook v2.0
Reward desired behavior • Cash Rewards • Vacations • Acknowledgement
Building a Foundation For Unified Grasp of GRC Tim Strong Managing director, Duff & Phelps Nov. 16, 2012
Foundation for a Unified Grasp of GRC • How we see it working in organizations • Unified vision, direction, and approach is infrequent • GRC programs and solutions are often event-driven • Event-driven reactive solutions can be the facilitator • Avoid hodgepodge solutions
Foundation for a Unified Grasp of GRC • Avoiding the hodgepodge • Issue-driven and high-profile/risk areas • Program initiation • Solution implementation • Process and technology
Foundation for a Unified Grasp of GRC • Controls & Audits Investigations: Internal, Inquiries, External • Questions • Checklists • Surveys • Interviews • Immediate/Tactical • Strategic Vision • Enterprise v. Subsidiaries • Prioritized by: • Effort • Risk • Reward Execution of Policies & Procedures
Foundation for a Unified Grasp of GRC Centralized Framework - Ideal Identify, Evaluate and Advise Embed Policy & Controls Internal and External Reporting Compliance Function Investigate Issues and Incidents Communicate, Educate, and Automate Monitor and Measure Effectiveness
Foundation for a Unified Grasp of GRC Decentralized Framework - Reality Legal Identify, Evaluate and Advise Internal Audit IT Embed Policy & Controls Monitor and Measure Effectiveness Compliance Function Internal and External Reporting Communicate, Educate, and Automate Investigate Issues and Incidents Operations HR/Training Compliance
Sample FCPA Checklist Sample – not all information displayed
Sample FCPA Checklist Sample – not all information displayed
Sample FCPA Checklist Sample – not all information displayed
Sample FCPA Checklist Sample – not all information displayed
Sample AML Checklist Sample – not all information displayed Checklist adapted from IRS, SEC, NASD, IMOLIN, Egyptian Financial Services Authority
Sample AML Checklist Sample – not all information displayed Checklist adapted from IRS, SEC, NASD, IMOLIN, Egyptian Financial Services Authority
Sample AML Checklist Sample – not all information displayed Checklist adapted from IRS, SEC, NASD, IMOLIN, Egyptian Financial Services Authority
Sample AML Checklist Sample – not all information displayed Checklist adapted from IRS, SEC, NASD, IMOLIN, Egyptian Financial Services Authority
Sample AML Checklist Sample – not all information displayed Checklist adapted from IRS, SEC, NASD, IMOLIN, Egyptian Financial Services Authority
Thank you Nov. 15, 2012