<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/risky_business_enterprise_grc_platforms_essential.php" />
  <link rel="self" type="application/atom+xml" href="http://www.readwriteweb.com/atom.xml" />
  <id>tag:,2009:/1/tag:www.readwriteweb.com,2009://1.15599-</id>
  <updated>2009-07-05T19:04:34Z</updated>
  <title>Comments for Risky Business: Enterprise GRC Platforms Essential, Says Forrester</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.23-en</generator>
  <entry>
    <id>tag:www.readwriteweb.com,2009://1.15599</id>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/risky_business_enterprise_grc_platforms_essential.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.readwriteweb.com/cgi-bin/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=15599" title="Risky Business: Enterprise GRC Platforms Essential, Says Forrester" />
    <published>2009-07-03T22:39:00Z</published>
    <updated>2009-07-04T04:28:41Z</updated>
    <title>Risky Business: Enterprise GRC Platforms Essential, Says Forrester</title>
    <summary>In a new report issued on the first of the month, Forrester Research has asserted the importance of enterprise platforms for governance, risk management, and compliance (GRC). Pointing to big name corporate failures in the last decade, they argue that the value proposition for GRC software is clear, and they identified leaders in this growing...</summary>
    <author>
      <name>Steven Walling</name>
      
    </author>
    
    <category term="Enterprise" />
    
    <category term="Trends" />
    
    <content type="html" xml:lang="en" xml:base="http://www.readwriteweb.com/">
      <![CDATA[<p><img alt="danger_workingonline.jpg" src="http://www.readwriteweb.com/assets_c/2009/07/danger_workingonline-thumb-150x112-6361.jpg" />In a <a href="http://www.forrester.com/rb/Research/wave%26trade%3B_enterprise_governance%2C_risk%2C_and_compliance_platforms%2C/q/id/47911/t/2">new report</a> issued on the first of the month, <a href="http://www.forrester.com/">Forrester Research</a> has asserted the importance of enterprise platforms for governance, risk management, and compliance (GRC). Pointing to big name corporate failures in the last decade, they argue that the value proposition for GRC software is clear, and they identified leaders in this growing market. </p>

<p>The open question from the research is whether enterprises will really see the need as being so desperate. Fear may be a great motivator, but GRC platforms have yet to prove that they're a piece of IT that businesses require to succeed.</p>]]>
      <![CDATA[<h2>GR What?</h2>
Governance, risk management and compliance platforms take a broad and complex series of business tasks and whittle them down to a central point of focus for the enterprise. 

<p>Basically, they're a technological solution for keeping track of programs of corporate governance, managing known and potential risks for a business, and staying in compliance with regulatory requirements. All these platforms incorporate varying degrees of workflow management, data visualization, content management, and reporting on related performance metrics. </p>

<h2>The Leaders</h2>
Forrester examined 14 vendors of enterprise GRC platforms, and picked <a href="http://www.axentis.com/">AXENTIS</a>, <a href="http://www.bwise.com/">BWise</a>, <a href="http://www.metricstream.com/">MetricStream</a>, <a href="http://www.bwise.com/">OpenPages</a>, and <a href="http://thomsonreuters.com/">Thomson Reuters</a> as leaders in the space. 

<p>It might surprise you that GRC platforms from enterprise software giants like SAP have been beaten out by much smaller vendors. But in an emerging market, it makes perfect sense that agile young companies can dominate big players who have come late to the game. </p>

<center><img alt="Forrester The Forrester Wave Enterprise Governance, Risk, And Compliance Platforms, Q3 2009.pdf (page 8 of 17).jpg" src="http://www.readwriteweb.com/assets_c/2009/07/Forrester The Forrester Wave Enterprise Governance, Risk, And Compliance Platforms, Q3 2009.pdf (page 8 of 17)-thumb-550x357-6363.jpg" /></center>

<h2>Close, But No Cigar</h2>
Integrated governance, risk management and compliance platforms present a new way to handle these business processes. Forrester itself published a <a href="http://www.forrester.com/Research/Document/Excerpt/0,7211,46512,00.html?src=47911pdf">report</a> that predicted GRC would first "hit the big time" just this year. All the leaders in the market thus far have sold a respectable amount of customers on the notion that they decrease risk, boost overall efficiency, and make strategy and decision making easier. 

<p>But platforms for governance, risk and compliance still come off as a specialist product for large enterprises in volatile markets, rather than a core business tool. The ever-growing pack of GRC vendors have clearly defined the value they deliver, but not that they're something the enterprise cannot do without during a period of belt tightening. </p>

<p><em>Image courtesy Forrester Research, Photo credit Gill Wildman</em></p>]]>
    </content>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.15599-comment:145363</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.15599" type="text/html" href="http://www.readwriteweb.com/archives/risky_business_enterprise_grc_platforms_essential.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/risky_business_enterprise_grc_platforms_essential.php#c145363" />
    <title>Comment from Paul Dandurand on 2009-07-04</title>
    <author>
        <name>Paul Dandurand</name>
        <uri>http://www.piematrix.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.piematrix.com">
        <![CDATA[<p>Steven,<br />
I agree that GRC is not at the core. I think many companies see GRC as a special focus for selected individuals rather than integrating GRC best practices into everyone's day-to-day work. Aside from staying out of jail with certain requirements (i.e. Sarbanes-Oxley), adoption may come when business departments find ROI from implementing best practices that lead to lower cost or increased revenue. However, we are all guilty of spending too much time putting out fires rather than taking a breather to build processes that make our lives better with less risk. The killer app, is not the app, it's the discipline along with the process content that drives business ROI and keeps us out of trouble. Those serious about systematically avoiding fires will first need to make it a top priority. Then they would need to find process and project management platforms and GRC systems that are made for everyone. By that I mean it has to be simple for cross-enterprise user adoption. Only then I see GRC becoming a core function for business of all sizes.<br />
 </p>]]>
    </content>
    <published>2009-07-04T14:43:02Z</published>
  </entry>

</feed>