Questions to ask about GRC – #4 Fragmentation


Continuing the discussion from:

Questions to ask about GRC – Part 1
Questions to ask about GRC – Part 2, question 1: Goals and Strategies
Questions to ask about GRC – Part 2, question 2: Harmony
Questions to ask about GRC – Part 2, question 3: Integration




Norman Marks
Norman Marks
Here are the links to the next question (there will be 12 in Part 2). I am posting them separately so each can be discussed on their own merits.
Questions to ask about GRC – Part 2, question 5: Culture

=====================================================

4. Are functions/processes/systems fragmented, inhibiting performance?

One of the original drivers of “GRC” was the fact that most companies have multiple functions for risk management (the typical organization of size has seven) and compliance. These diverse groups are not coordinated, let alone integrated, with the result that some aspects of risk and compliance are covered by multiple groups (increasing cost) and other areas fall in between the gaps.

When multiple groups assess and manage risk in silos (such as just looking at IT-related risk, or only risk related to sourcing of key components), it is nearly impossible to gain a view of risk for the enterprise as a whole. Often, these groups use different language, different standards, different processes and systems, and report to management in different ways. They may even have significantly different assessments of the same risk. Not only is this inefficient, but the inter-relationship of risk is generally missed (such as how a failure in an IT process could impact recruiting, or supply chain affect an IT project), and management and the board may lack the risk information it needs to run the business.

Fragmentation in compliance is also very common. For example, I worked at a global manufacturing company that had five factories in China. Each had to comply with China’s export regulations, but instead of cooperating they handled the task independently. Rather than sharing a full-time expert in the regulations, they each made it a part-time task of an employee in the accounting function (with minimal training) and purchased different systems for the mandated reporting. As a direct result, all but one were soon out of compliance.

For another (similar) view of the problem of fragmentation, I recommend a piece by Michael Rasmussen on Inevitability of Failure: Managing GRC in Silos.

The problem of fragmentation is not limited to the risk management and compliance functions. It can be a problem in other disciplines (such as credit management). But the more common and arguably more significant issue is when systems and related processes are fragmented.

How can a company’s management make decisions in today’s fast-moving environment without timely, reliable information? Yet, companies still have multiple ERP and other systems and rely on spreadsheets to give them consolidated views of the enterprise. How can that provide decision-makers on the executive floor the information they need to run the business with confidence? I doubt they realize either the risk they are running or the ability of today’s technology to solve their problems.

A closely related problem occurs when multiple functions or groups have overlapping responsibilities. For example, information security at a division may be ‘audited’ or assessed by the internal audit group, the external auditor, the corporate information security function, an ISO auditor, and more. This is highly inefficient and disruptive to the operations of the audited area. The other side of the coin is that at the same time that there are overlaps and redundancies, there may also be gaps in coverage. When everybody only sees their assigned pieces of the jigsaw, it is quite possible for a piece to be missing and nobody notice because nobody sees the entire picture.


Norman Marks, CPA, is vice president, governance, risk, and compliance for SAP's BusinessObjects division, and has been a chief audit executive of major global corporations for more than 15 years. He is the contributing editor to Internal Auditor’s “Governance Perspectives” column.
normanmarks.wordpress.com/

Friday, September 14th 2012
Rate it




New comment:
Twitter
B i u  QUOTE  URL

ENGLISH
Articles & press releases are provided as is and have not been edited or checked for accuracy.
Any queries should be directed to the company issuing the press release or to the author issuing the article.
If you have a question for the author, or would like to comment on this article, use the box above. Your comment will be moderated before publication.
Your comment or question will appear below and the author or Finyear editor will be able to respond. Please note that your name will appear next to your comment (not your email).
Finyear does not offer financial advice of any kind and the opinions of authors are not necessarily those of Finyear.
By posting your comment, you agree to our acceptable use policy. If you read anything here that you consider inappropriate or offensive, please contact the adress : contact (at) finyear.com
Finyear: Daily News & Best Practices for the Finance Executives (CFO, Treasurer, Controller, Credit manager, accountant, financial executive, etc...).

The Financial Year by Finyear. Copyright Finyear 2007-2013. You may share using our article tools.
Please don't cut articles from Finyear.com and redistribute by email or post to the web without permission: contact (at) finyear.com

FRANCAIS
Les articles et les communiqués de presse sont fournis tels quels et n'ont pas été modifiés ou vérifiés.
Toute demande de renseignement doit être adressée à la société émettrice du communiqué de presse ou à l'auteur de l'article.
Si vous avez une question pour l'auteur, ou si vous désirez commenter cet article, utilisez la boîte ci-dessus. Votre commentaire sera modéré avant publication.
Votre commentaire ou question ci-dessous apparaîtra et l'auteur ou l'éditeur Finyear sera en mesure de répondre.
Veuillez noter, s'il vous plaît, que votre nom apparaîtra à côté de votre commentaire (pas votre adresse email).
Finyear n'offre pas de conseils financiers de quelque nature que ce soit et les opinions des auteurs ne sont pas nécessairement celles de Finyear.
En postant votre commentaire, vous acceptez notre politique d'utilisation et nos mentions légales.
Si vous lisez quelque chose ici que vous considérez inapproprié ou offensant, s'il vous plaît contacter l'adresse: contact (at) finyear.com
Finyear: actus quotidiennes et meilleures pratiques pour les cadres financiers (CFO, trésorier, contrôleur, gestionnaire de crédit, comptable, cadre financier, etc ..).

The Financial Year by Finyear. Copyright Finyear 2007-2013. Vous devez utiliser nos outils de partage situés sur les articles.
SVP ne coupez-pas les articles issus de Finyear.com, ne les reroutez-pas par message sur le web sans autorisation : contact (at) finyear.com

In the business world, everyone is paid in two coins: cash and experience. Take the experience first; the cash will come later. - Harold Geneen

Finyear Magazine


Finyear Research


Conferences & Webinars


White Papers / Livres blancs





Mo Tu We Th Fr Sa Su
    1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30 31