A haphazard department and document centric approach for third party GRC compounds the problem and does not solve it. It is time for organizations to step back and mature their third party GRC approaches with a cross-functional and coordinated strategy and team to define and govern third party relationships. Organizations need to mature their third party governance with an integrated strategy, process, and architecture to manage the ecosystem of third party relationships with real-time information about third party performance, risk, and compliance, as well as how it impacts the organization.
GRC 20/20 has developed the Third Party GRC Maturity Model to articulate maturity in the Third Party GRC processes and provide organizations with a roadmap to support acceleration through their maturity journey.
There are five stages to the model:
1. Ad Hoc
2. Fragmented
3. Defined
4. Integrated
5. Agile
Today we look at Stage 2, the Fragmented level of Third Party GRC
The Fragmented stage sees departments with some focus third party GRC within respective functions — but information and processes are highly redundant and lack integration. With siloed approaches to third party GRC, the organization is still very document-centric. Processes are manual and they lack standardization, making it hard to measure effectiveness.
Characteristics of the Fragmented Maturity stage are:
Key elements that identify an organization is at the Fragmented stage are:
Organizations in the Fragmented stage of maturity answer many of the following questions affirmatively:
After reflecting on these points, it is time to next ask: is your organization at the Fragmented stage of Third Party GRC Maturity?
Aravo, leveraging the GRC 20/20’s Third Party GRC Maturity Model: A New Paradigm in Governing Third Party Relationships research report, Aravo has built the Third Party Risk Management Maturity Calculator that takes this deeper and provides insight on how to improve your organization’s maturity and approach.
Aravo, leveraging the GRC 20/20’s Third Party GRC Maturity Model: A New Paradigm in Governing Third Party Relationships research report, has built the Third-Party Risk Management Maturity Calculator that takes this deeper and provides insight on how to improve your organization’s maturity and approach.
Share with Your Friends: