A Framework for Assessing Organisational IT Governance, Risk and Compliance
نویسندگان
چکیده
Today, enterprises have reached to understanding that Information Technology (IT) is more than just a technical issue. Disciplines such as IT governance, (IT) risk management and (IT) compliance have been established to steer it. Though, there has been some improvements, these domains are usually focused separately in silos, which raises a problem of performance and efficiency, where less business value is created due to complexity of the process flows. In order to cure it, there has been an adoption from business world, referred as “GRC” which covers all the three disciplines of governance, risk management and compliance. The paper conducts a systematic review on the discipline of IT GRC, taking out best practices. Researching what has been done to integrate them and proposing an synthesized framework from the review results. The framework, unifying the disciplines is supposed to ease the adoption of IT GRC in an enterprise, providing a structure to manage the IT and business together, thereby improve business performance. In addition to proposing an IT GRC framework, the paper presents a web application to support the framework adoption. The proposed model is based on the scientifically proven best practices of the state of the art which would give a certainty of its value. The empirical study will help to contribute to improving the effectiveness IT GRC compared to traditional approach which is commonly practiced in enterprises.
منابع مشابه
Relationship between Corporate Governance and Risk Management
Corporate governance of banks is one of the most important structures required by banks to maintain the health and stability of banks, which can play an important role in managing banks' risk. This paper examines the effect of corporate governance on liquidity risk management, credit risk management, and total bank risk management. We used board structure effectiveness, transparency, and respon...
متن کاملAssessing the Performance of Dehyari Representatives in the Framework of good Rural governance. Case Study: Villages of Zanjan City
Introduction and Background: In recent years, attention has been paid to governance, especially in rural studies. The good governance is about the ability of the government to serve the Citizens, referring to laws, processes and behaviors that express interests, manage resources and exercise power in the Community. Aims: The purpose of this study was assessing the performance of Dehyari represe...
متن کاملEnterprise Risk Management and Performance of Financial Institutions in Iraq: The Mediating Effect of Information Technology Quality
Enterprise risk management represents a process of assessing exposure to risks in an institution. It is a systematic mechanism and a comprehensive tool for predicting events, including unexpected events, and their impacts. This paper is a conceptual study. It aims at designing a model for testing the mediation effect of information technology (IT) quality on the relationship between the enterpr...
متن کاملThe Governance of National Community Health Worker Programmes in Low- and Middle-Income Countries: An Empirically Based Framework of Governance Principles, Purposes and Tasks
Background National community health worker (CHW) programmes are increasingly regarded as an integral component of primary healthcare (PHC) in low- and middle-income countries (LMICs). At the interface of the formal health system and communities, CHW programmes evolve in context specific ways, with unique cadres and a variety of vertical and horizontal relationships. These programmes need...
متن کاملEvaluation of Corporate Governance Practices in Emerging Markets (A case study of Nigerian Banking Industry)
This study explores corporate governance practices within the context of the Nigerian banking industry using instances of corporate governance lapses that resulted in part to the Nigerian banking crises. We present multiple case analysis of publicly available documents and court papers (in the United Kingdom and Nigeria) to document instances of breach and areas of weakness in the existing Nige...
متن کامل