Governance is not the endgame

| 1 Comment | No TrackBacks
I was in Chicago last week as a guest speaker at a Gartner Risk Management and Compliance event. The event was well attended albeit somewhat down on numbers from previous years. However it is clear that interest in this topic remains high. One subject which came up for regular debate was the use, and the meaning, of the frequently used acronym GRC (governance ,risk, and compliance). I touched on this in my first blog a few weeks ago. As discussed in this earlier blog, the term itself is misleading as many regard the management of risk and the achievement of compliance as part of governance and not separate entities. Similarly where does the achievement of value sit within the GRC acronym? Gartner itself seems to be moving away from the acronym with some of their analysts supporting my view that the term has been hijacked by certain elements of the software vendor market to pigeonhole certain of their products. Hence, arguably, the term has not only become confused but also cheapened as a result. There is equal confusion over the meaning of governance, although this debate sometimes misses the point. In my view governance is the structure and processes through which enterprises gain assurance that IT achieves value, mitigates risk and achieves relevant compliance. The whole enterprise plays its part in this, including the CEO and the Boardroom, IT management, security and assurance specialists, business management and finance. Governance itself is not the endgame. What it should help to provide is trust in information systems and value creation from IT. That is the endgame not the process itself.

No TrackBacks

TrackBack URL: http://www.computerweekly.com/cgi-bin/mt/mt-tb.cgi/52564

1 Comment

  • Hi Paul,

    I couldn't agree with you more. What I find striking is that time and time again, value does not seem to be on the agenda.
    I used to think that value would play a role at (IT) Portfolio Management, but many companies don't look at value when talking about managing the portfolio of projects. So IT Governance software such as CA's Clarity, Compuware's Changepoint, Microsoft Executive Dashboard, are not the biggest help to drive value from IT. Then came indeed GRC, but again, and you are right, value is not included here. So despite the more than a million hits on google for 'GRC software', no help for value delivery there either.
    First, I personally belief that Value & IT is only adopted by the more mature companies. However, if a company would like to start with understanding the value of IT, where do you start?
    Second, how do you start the age of enlightenment, or have we slowly started already?

    CJ

Leave a comment

OpenID accepted here Learn more about OpenID

About this Entry

This page contains a single entry by Paul Williams published on May 8, 2009 1:05 PM.

The Meaning of Value was the previous entry in this blog.

Age of Enlightenment? is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.

Archives