SAN RAMON, CA, June 13, 2012 - Ventana Research has released its latest Benchmark Research, Governance, Risk & Compliance (GRC), which investigates how companies approach and execute their governance, risk and compliance management efforts. The business activities collectively known as GRC are naturally linked. Effective corporate governance ensures compliances with laws, regulations and company policies. Without it, there is no way to reliably control risk. Ventana Research undertook this benchmark research to acquire information about levels of maturity, trends and best practices in organizations' risk and compliance practices and technology.
The latest research found that a sizable majority of companies (63%) are in the bottom half of our maturity distribution in their management of governance, risk and compliance, despite the widespread (94%) recognition of the importance of GRC. Companies recognize the need to improve their operational risk management because they are not able to monitor these risks well. About two-thirds (64%) say they can keep track of few, if any of these risks. Despite having tighter financial controls in place because of Sarbanes-Oxley, companies lag in contingency planning for financial and operational risk. Additionally, IT risk management continues to be a work in progress, with only 23 percent having automated controls for change management, a key pillar to IT security.
The research shows that legal compliance and regulatory requirements have increased costs in workloads in companies. Two-thirds (65%) say that it's difficult or very difficult to meet requirements and one-third have had to increase their financial controls over the past five years. Addressing GRC issues is difficult for companies because they have not allocated money or employee time to these requirements. In particular, the research shows that a major driver of companies' lack of maturity is their lack of attention to the information and technology aspects of GRC.
"Companies haven't invested in readily available technology to cut the cost of meeting their financial and operational compliance requirements," observed Robert Kugel, Senior Vice President and Research Director. "They don't always have the data that would improve the effectiveness of their financial and operational risk management. And, they haven't employed controls that can ensure the integrity of their IT systems and reduce the cost of internal and external audits."
There is some good news from the research. Senior executives' attitude toward ethical behavior is an important influence on the compliance policies an organization establishes and how people and groups behave within it. For that reason, Congress emphasized the "tone at the top" in the Sarbanes-Oxley Act of 2002. The research shows that the tone is positive: Two-thirds of participants said that their company's senior management is very active in advocating ethical behavior and practicing what they preach.
Ventana Research will expand on the key findings of this benchmark research during a live webinar on Thursday, June 21 @ 11am PST. To participate in the webinar, or view it after it has taken place, visit: http://www.ventanaresearch.com/grcwebinar.
Those interested in learning more about this benchmark research can find additional information in Governance, Risk and Compliance Research. As a part of your registration you will receive insights and education from Ventana Research on using technology effectively in business. Ventana Research thanks those that participated in the benchmark, helping to make this industry benchmark research a reality. Ventana Research provides guidance to organizations in business and IT in information technology through its Ventana On-Demand and with its assessment and educational services offerings.
About Ventana Research
Ventana Research is the most authoritative and respected benchmark business technology research and advisory services firm. We provide insight and expert guidance on mainstream and disruptive technologies through a unique set of research-based offerings including benchmark research and technology evaluation assessments, education workshops and our research and advisory services, Ventana OnDemand. Our unparalleled understanding of the role of technology in optimizing business processes and performance and our best practices guidance are rooted in our rigorous research-based benchmarking of people, processes, information and technology across business and IT functions in every industry. This benchmark research plus our market coverage and in-depth knowledge of hundreds of technology providers means we can deliver education and expertise to our clients to increase the value they derive from technology investments while reducing time, cost and risk.
Ventana Research provides the most comprehensive analyst and research coverage in the industry; business and IT professionals worldwide are members of our community and benefit from Ventana Research's insights, as do highly regarded media and association partners around the globe. Our views and analyses are distributed daily through blogs and social media channels including Twitter, Facebook, LinkedIn and Google+.
To learn how Ventana Research advances the maturity of organizations' use of information and technology through benchmark research, education and advisory services, visit www.ventanaresearch.com.
Media: Copies of benchmark research report and interviews are available upon request.