In a new report issued on the first of the month, Forrester Research has asserted the importance of enterprise platforms for governance, risk management, and compliance (GRC). Pointing to big name corporate failures in the last decade, they argue that the value proposition for GRC software is clear, and they identified leaders in this growing market.
The open question from the research is whether enterprises will really see the need as being so desperate. Fear may be a great motivator, but GRC platforms have yet to prove that they're a piece of IT that businesses require to succeed.
Basically, they're a technological solution for keeping track of programs of corporate governance, managing known and potential risks for a business, and staying in compliance with regulatory requirements. All these platforms incorporate varying degrees of workflow management, data visualization, content management, and reporting on related performance metrics.
It might surprise you that GRC platforms from enterprise software giants like SAP have been beaten out by much smaller vendors. But in an emerging market, it makes perfect sense that agile young companies can dominate big players who have come late to the game.
But platforms for governance, risk and compliance still come off as a specialist product for large enterprises in volatile markets, rather than a core business tool. The ever-growing pack of GRC vendors have clearly defined the value they deliver, but not that they're something the enterprise cannot do without during a period of belt tightening.
Image courtesy Forrester Research, Photo credit Gill Wildman
TrackBack URL for this entry: http://www.readwriteweb.com/cgi-bin/mt/mt-tb.cgi/12036
Comments
Subscribe to comments for this post OR Subscribe to comments for all ReadWriteWeb posts
Steven,
I agree that GRC is not at the core. I think many companies see GRC as a special focus for selected individuals rather than integrating GRC best practices into everyone's day-to-day work. Aside from staying out of jail with certain requirements (i.e. Sarbanes-Oxley), adoption may come when business departments find ROI from implementing best practices that lead to lower cost or increased revenue. However, we are all guilty of spending too much time putting out fires rather than taking a breather to build processes that make our lives better with less risk. The killer app, is not the app, it's the discipline along with the process content that drives business ROI and keeps us out of trouble. Those serious about systematically avoiding fires will first need to make it a top priority. Then they would need to find process and project management platforms and GRC systems that are made for everyone. By that I mean it has to be simple for cross-enterprise user adoption. Only then I see GRC becoming a core function for business of all sizes.
Posted by: Paul Dandurand
|
July 4, 2009 7:43 AM