12.07.2015 Views

Integrity-Driven Performance. New Strategy for ... - GRC Resource

Integrity-Driven Performance. New Strategy for ... - GRC Resource

Integrity-Driven Performance. New Strategy for ... - GRC Resource

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Envision <strong>Per<strong>for</strong>mance</strong> <strong>Driven</strong> by <strong>Integrity</strong>Set Objectives, Assess, PlanS T R A T E G YOrganisationalStructure, Roles &Responsibilities&Vision, Values,Ethical Culture& PoliciesA S S E S S M E N TDefinedObjectives,Risk Appetite &Risk ToleranceCapability, Cost& Value AnalysisStakeholderAnalysis &BenchmarkingEvent Identification,Risk Assessment& ResponseStrategiesEnvisionAssessImproveDeployOperateMonitorSustainReviewVision &BusinessObjectivesSet ObjectivesIn<strong>for</strong>mation &CommunicationPlanDevelopIn<strong>for</strong>mation &CommunicationChangeExecuteIn<strong>for</strong>mation &CommunicationRespondReportIn<strong>for</strong>mation &CommunicationAdaptPeopleProcessTechnologyThe starting point, or frame of reference, <strong>for</strong> the model is within the organisation’s overall strategyand business objectives. These have to be aligned with the mission, values and ethical cultureobjectives of the organisation. Moreover, business strategy cannot be properly contemplated orexecuted without examining business risks. Many organisations fully think through this processand are subsequently well positioned to address <strong>GRC</strong> requirements. Others have not linked riskmanagement and compliance to business objectives and need to take a more structured enterprise riskmanagement approach. This can be achieved by applying proven risk management approachesand methods, such as the COSO Enterprise Risk Management framework.Once the business objectives and risk universe are understood (<strong>for</strong> example, there is a clearunderstanding of risk appetite, risk definition and control activities) <strong>GRC</strong> requirements can beproperly examined, assessed, prioritised and addressed. Compliance risk relating to productdevelopment testing, <strong>for</strong> instance, has a completely different meaning in the pharmaceuticalindustry than in other industries where testing failures have much less severe significance.40

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!