Governance, risk and compliance: Applications in information systems
نویسندگان
چکیده
The importance of governance and associated issues of compliance and risk management is well recognized in enterprise systems. This importance has dramatically increased over the last few years as a result of numerous events that led to some of the largest scandals in corporate history. The governance, risk and compliance market is estimated to be worth over $32 billion. Tool support for governance, risk and compliance related initiatives is provided by over 100 software vendors, however, while the tools have on average tripled in price since 2003, they are often insufficient to meet organizational needs. At the same time, there is an increasing complexity in the facilitation of compliant business processes, which stems from an increasing number of regulations, frequent and dynamic changes, as well as shared processes and services executing in highly decentralized environments. In the age of outsourcing, dynamic business networks, and global commerce, it is inevitable that organizations will need to develop methods, tools and techniques to design, engineer, and assess processes and services that meet regulatory, standard and contractual obligations. Governance, Risk and Compliance (GRC) can be expected to play a significant part in several applications. This area is emerging as a critical and challenging area of research and innovation. It introduces, among others, the need for new or adapted modeling approaches for compliance requirements, extension of process and service modeling and execution frameworks for compliance and risk management, and detection of policy violations. In addition, it introduces questions relating specifically to the use of technology to support compliance management. For example, how auditors and regulators can put into use techniques like continuous monitoring and data analysis to assess whether an organization complies with relevant rules and regulations, or how technology can be used to support assessment of design and operational effectiveness of controls. This workshop will provide, for the fourth year running, a forum for researchers from diverse areas and make a consolidated contribution in the form of new and extended methods that address the challenges of governance, risk and compliance in information systems. Industry papers are also encouraged at this workshop.
منابع مشابه
Relationship between Corporate Governance and Risk Management
Corporate governance of banks is one of the most important structures required by banks to maintain the health and stability of banks, which can play an important role in managing banks' risk. This paper examines the effect of corporate governance on liquidity risk management, credit risk management, and total bank risk management. We used board structure effectiveness, transparency, and respon...
متن کاملExploring the contribution of information technology to governance, risk management, and compliance (GRC) initiatives
Information technology (IT) has a tremendous impact on the discipline of accounting by introducing new ways of retrieving and processing information about performance deviations and control effectiveness. This paper explores the role of IT for managing organizational controls by analyzing value drivers for particular accounting information systems that commonly run under the label of Governance...
متن کاملTowards a Reference Model for Integrated Governance, Risk and Compliance
More regulations are on the way, along with demanding transparency, accurate information about company operations, robust and comprehensive risk management, regulatory compliance and efficient governance. Consequently, organizations are seeking to improve their GRC activities, by implementing integrated GRC solutions that provide a holistic view of the organization and help in the automation of...
متن کاملIdiosyncratic Risk and Disclosure of Corporate Social Responsibility: Emphasizing the Role of Corporate Governance
In this study, the impact of corporate social responsibility (CSR ) disclosure on idiosyncratic risk has been investigated concerning three stakeholder theory, information asymmetry, and risk management. It also goes further and explores the impact of some corporate governance mechanisms such as ownership structure, board characteristics, and incentive contracts on this relationship. To achieve...
متن کاملMagic Quadrant for Enterprise Governance, Risk and Compliance Platforms
Governance, risk and compliance (GRC) as a marketplace can be broadly divided between GRC management (GRCM) products for the oversight and operation of risk management and compliance programs, and other GRC products for the automation and monitoring of controls. For a comprehensive description of the GRC marketplace, see "A Comparison Model for the GRC Marketplace, 2011 to 2013," which addresse...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- Information Systems Frontiers
دوره 14 شماره
صفحات -
تاریخ انتشار 2012