|
Day 4/ Power Breakfast
Emerging trends in unifying Governance Risk and Compliance
The Express Group organized a roundtable for Wipro to discuss
Governance Risk and Compliance which is becoming a hot topic amongst organizations

Manohar Ganshani, practice partner, Wipro Consulting Service having a
chat with the CIOs on Emerging Trends in Unifying Governance Risk and
Compliance
|
The discussion which was initiated by Indian Express editorial
about how seriously the organization took this subject and if the CISOs played
a role in influencing their management about GRC. Wipro Consulting Service took
up the lead to give certain insights into this subject, with CIOs making it
an interesting interactive session.
Giving a 360 degree overview of GRC, Manohar Ganshani, practice
partner, Wipro Consulting Service maintained that GRC as a policy is followed
in three areas which included IT -GRC, ERM (enterprise risk management) GRC
and in financial matters.
This is possible, he said, using processes and tools required to demonstrate
in a clear, concise and integrated fashion, compliance with the various authoritative
sources to which companies are bound to comply.
To a question from Burgess Cooper, GM-IT security of Vodafone as how GRC could
be measured, Ganshani maintained that GRC centre of excellence could lead to
reduction and effective management of risk, increases assurance reliability,
increased information quality, decrease operational cost by reducing complexity
etc.
The challenges that the CISOs gathered at the round table found was that each
department in the organization had their own risks and compliance issues. The
challenge was also about CISO or CIOs playing the board room role to influence
the top management in evolving a matrix on GRC.
Ganshani suggested that a single window of capturing information and building
the right frame work to take the risk management is critical for any organization
where only the CIO played a major role. Some of the frameworks he recommended
were to have integrated GRC, ITRO outsourcing, threat and vulnerability modeling,
unified compliance, maturity assessment advisory services, operational risk,
IT GRC automation and so on.
N Geetha
|