CSO - Does governance, risk and compliance (GRC) really pay off? It's a valid question for any organization that's looking to formulate a corporate strategy and implement software for managing GRC.
Leaders at financial services company Fiserv say the answer for their organization is an emphatic "yes," citing a number of concrete benefits. Let's dig into the details of their GRC business case.
In this Fiserv GRC case study:
Fiserv was founded in 1984 and currently has about 19,000 employees operating out of some 200 locations worldwide.
Fiserv is a global provider of information management and electronic commerce systems for the financial services industry, and offers integrated technology and services for clients. It provides technology solutions in five areas: payments, processing services, risk and compliance, customer and channel management, and transforming data into actionable business insights.
The company has more than 16,000 clients worldwide, including banks, credit unions, mortgage lenders and leasing companies, brokerage and investment firms, and other businesses. Fiserv helps these clients address challenges such as attracting and retaining customers, preventing fraud and meeting regulatory requirements.
[Also read 12 tips for implementing GRC]
In 2008, Fiserv decided to embrace a formal GRC strategy "because it was the best way to manage through a thicket of simultaneously occurring changes in our business and regulatory environment," says Murray Walton, senior vice president and chief risk officer.
The company's business strategy has evolved in recent years from a holding company to an integrated operating model, creating greater complexity in the organization and the solutions it provides to clients, Walton says.
"The external environment has also changed, and today we face more government regulation and non-government standards, such as [PCI DSS]," Walton says.
"Navigating all these challenges at the same time required a much more structured approach to governance, risk and compliance than our previous spreadsheet-driven methods."
Before deploying Agiliance's GRC software, called RiskVision, "I would have characterized our environment as diversity on steroids," Walton says. "We had diversity of understanding about what risk assessment and monitoring means. We had diversity of understanding about what was required or expected, and diversity of methods and practices. As a result, we had an absolutely enormous challenge to try to develop a picture of our enterprise risk and enterprise compliance."
There was no common understanding or vocabulary or process related to risk, Walton says. "The good news is that, with enough effort, we were able to manage risk, but there was a challenge of being able to document that to our board of directors or regulators, and to look beyond the horizon. All of a sudden, our diversity had become a risk itself."
- Learn More About Peer 1 Hosting's Mission Critical Cloud Mission Critical Cloud from Peer 1 Hosting is enterprise-ready, creating a perfect point of adoption whether you need an off-premise solution for development
- What Makes a Cloud Solution Truly Enterprise-Grade? Future enterprise cloud capabilities will evolve from five core elements...
- Securing Mobile App Data - Comparing Containers and App Wrappers Analysts agree that Mobile Device Management (MDM) is not enough when it comes to securing app data. Although it remains a critical component...
- PCI 3.0 Compliance In this white paper, learn how PCI-DSS 3.0 effects how you deploy and maintain PCI compliant networks using CradlePoint devices.
- Cloud and Collaboration: Driving Your Business Value Mission Critical Cloud from Peer 1 Hosting is enterprise-grade.
- Peer 1's Mission Critical Cloud: Your Cloud, Your Way Peer 1 Hosting's Mission Critical Cloud offers the ultimate in flexible customization of infrastructure, resources and support. All Security White Papers | Webcasts
Our new bimonthly Internet of Things newsletter helps you keep pace with the rapidly evolving technologies, trends and developments related to the IoT. Subscribe now and stay up to date!