Governance. Risk. Compliance. These are areas of concern that touch all industries. Stakeholders demand to know more than how much revenue a company earned last quarter — they want to know how it was generated.
With those demands in mind, SAS is rolling out an enterprise governance, risk and compliance (GRC) program to help companies stick to laws and regulations, as well as understand and manage risk exposures and share information with stakeholders.
Dubbed SAS Enterprise GRC, the platform works to let companies track risks based on trends in various operational systems. The goal is to identify emerging exposures more quickly, then manage them and make continual policy updates according to regulatory changes to yield an audited, consolidated risk profile.
Integrating Business Strategy with Compliance
Integration is the key word with SAS Enterprise GRC. The platform integrates business strategy with risk and compliance in hopes of driving better performance. The solution also promises better collaboration through a common framework and automates control management and monitoring to drive more transparency, consistency and efficiency.
Charles King, principal analyst at Pund-IT, said the market is seeing more GRC solutions. SAS’s twist is to set up an automated system for governance and compliance policies and then embedding GRC notations or organizational issues and policy issues.
“SAS Enterprise GRC automates the process of creating reports to alert administrators that are tracking policy issues to where the data lies, whether or not the information that should be in compliance is in compliance, and so on,” King said. “What SAS is looking to do here is to create a set of tools that makes a very complex and tedious process that can be potentially expensive for a company much easier to manage through automation.”
Aligning Risk-Management Capabilities
Cubillas Ding, research director in Celent’s Securities and Investments Practice, said forward-thinking firms look to align upstream…