SlideShare une entreprise Scribd logo
1  sur  19
Investing in the “Front End” of Compliance:
Policy Management & Training

David Houlihan
Principal Analyst
Blue Hill Research

©2014 Blue Hill Research. All Rights Reserved.

©2014 Blue Hill Research. All Rights Reserved.
About Me:

Research:
Ethics & Compliance Management
Governance, Risk, and Compliance
Legal Technology
Background:
United States Attorney’s Office
Boston University
GTC Law Group
David Houlihan
Principal Analyst

©2014 Blue Hill Research. All Rights Reserved.

Aberdeen Group
What I Do:

How does this help our business?

Answer
Technology
Questions

Finance:
Information Technology:
Line of Business:

©2014 Blue Hill Research. All Rights Reserved.

What’s the ROI & TCO?

How do I implement & manage this?

Does it improve my performance?
Compliance & Non-compliance Costs
0%

Overall Average

Per capita per employee

25%

50%

$3,529,570

75%

$9,368,351

$222

$820
Compliance

100%

$2.65 lost for every
$1 spent on compliance

$3.69 lost for every
$1 spent on compliance

Non-compliance

Source: The True Cost of Compliance, Ponemon Institute January 2011
©2014 Blue Hill Research. All Rights Reserved.
In other words. . .

What you spend on compliance represents only
~21% of what compliance costs you.
(. . .per employee)
©2014 Blue Hill Research. All Rights Reserved.
Cost Sources

Compliance

Non-Compliance
27%

60%

Direct

Direct

Indirect

Indirect

Opportunity

30%

40%
43%

©2014 Blue Hill Research. All Rights Reserved.

Source: The True Cost of Compliance, Ponemon Institute January 2011
Compliance Cost Map
Compliance
Operations
Staff

Implementation

Regulatory
Action

Full time Employees

Cost to implement

Attorney Costs

Services

Consultants

Compliance
Business
Operations
Function

Risks

Penalties

Attorneys

Time lost to
implement

Lost Opportunities

Productivity Loss

Auditors

Resources

Reputation

©2014 Blue Hill Research. All Rights Reserved.

To information
acquisition

Attorney Costs

Technology
Content

Private Legal
Action

Reduced Revenue
Reduced Stock Value

To monitoring

Damages /
Settlements

To incident
management
The Challenge:

If you only had $1 to spend on compliance. . .
. . . how could you use it to get $4.69 in savings?

©2014 Blue Hill Research. All Rights Reserved.
Compliance Management

©2014 Blue Hill Research. All Rights Reserved.
Spend on Compliance Activities

13.8%

17.7%

Policy management

11.9%

74.3% of what organizations
spend on compliance goes to
“firefighting.”

Communications
Program management
Compliance monitoring
Enforcement
25.5%
31.1%

©2014 Blue Hill Research. All Rights Reserved.

Data: The True Cost of Compliance, Ponemon Institute January 2011
Analysis: Blue Hill Research
My Recommendation:

©2014 Blue Hill Research. All Rights Reserved.
Why Fire Prevention?

Employee action creates
compliance risk.

©2014 Blue Hill Research. All Rights Reserved.
What about the “Bad Apple”?

“Good Luck.”

©2014 Blue Hill Research. All Rights Reserved.
But the Bigger Problems are. . .

????????????

(1) Confusion regarding
requirements.
(2) Lack incentive to act
differently.

©2014 Blue Hill Research. All Rights Reserved.
Policy Management:

Policy Management
Areas for improvement:

Investment Impact:

Stakeholders collaboration

“Agency/organization” alignment

Management of changes

Efficiency of stakeholders

Removal of outdated policies

Clarity of requirements

Communication of changed to organization

©2014 Blue Hill Research. All Rights Reserved.
Training:

Training
Areas for improvement:

Investment Impact:

Employee engagement

Efficiency of acknowledge acquisition

Information retention

Reduce risk of noncompliance

Sense of consequence

More “red flags”

Guidelines of ambiguous situations

©2014 Blue Hill Research. All Rights Reserved.
Build Your Business Case
Compliance
Operations
Staff

Implementation

Regulatory
Action

Full time Employees

Cost to implement

Attorney Costs

Services

Consultants

Compliance
Business
Operations
Function

Risks

Penalties

Attorneys

Time lost to
implement

Lost Opportunities

Productivity Loss

Auditors

Resources

Reputation
Reduced Revenue

©2014 Blue Hill Research. All Rights Reserved.

To information
acquisition

Attorney Costs

Technology
Content

Private Legal
Action

Reduced Stock Value

To monitoring

Damages /
Settlements

To incident
management
Key Factors to Consider in Solutions

Policy Management
• Support for content development
• Ability to centrally manage and
distribute content
• Flexibility of content types incorporated
• Security of solution
• Support for retiring and archiving
content
Factors to Consider • Ability to link policy to training and
insight into compliance operations

Training
• Expense of communication
• Scalability of communication
• Time required to obtain
mastery
• Employee engagement in
training
• Degree of internalization and
retention
• How closely supplied content
supports objectives

Potential integration with enterprise GRC suite to align policies and training
with other compliance management and monitoring capabilities.

©2014 Blue Hill Research. All Rights Reserved.
Thank you!
To join the conversation, contact me:
dhoulihan@bluehillresearch.com
New research starts by the end of the month

. . .or follow us:

©2014 Blue Hill Research. All Rights Reserved.

1

Contenu connexe

Tendances

Are You a Smart CAAT or a Copy CAAT
Are You a Smart CAAT or a Copy CAATAre You a Smart CAAT or a Copy CAAT
Are You a Smart CAAT or a Copy CAATJim Kaplan CIA CFE
 
Brown Edwards: The Future-Ready CPA Firm
Brown Edwards: The Future-Ready CPA FirmBrown Edwards: The Future-Ready CPA Firm
Brown Edwards: The Future-Ready CPA FirmBill Sheridan, CAE
 
Reinventing Insurance
Reinventing InsuranceReinventing Insurance
Reinventing InsuranceKevin Pledge
 
Project Analysis on reason for attrition in an IT/ ITes industry
Project Analysis on reason for attrition in an IT/ ITes industryProject Analysis on reason for attrition in an IT/ ITes industry
Project Analysis on reason for attrition in an IT/ ITes industryvinyas87
 
2015 SOA Annual Meeting - Beagle Street and Teachers Life
2015 SOA Annual Meeting - Beagle Street and Teachers Life2015 SOA Annual Meeting - Beagle Street and Teachers Life
2015 SOA Annual Meeting - Beagle Street and Teachers LifeKevin Pledge
 
Developing an integrated technology for the enhancement of insurance penetration
Developing an integrated technology for the enhancement of insurance penetrationDeveloping an integrated technology for the enhancement of insurance penetration
Developing an integrated technology for the enhancement of insurance penetrationSamwel Kanda
 
The evolving role of IT managers and CIOs
The evolving role of IT managers and CIOsThe evolving role of IT managers and CIOs
The evolving role of IT managers and CIOsIBM Rational software
 
Blacksmith Law Link April 2011
Blacksmith Law Link April 2011Blacksmith Law Link April 2011
Blacksmith Law Link April 2011Blacksmith
 

Tendances (9)

Are You a Smart CAAT or a Copy CAAT
Are You a Smart CAAT or a Copy CAATAre You a Smart CAAT or a Copy CAAT
Are You a Smart CAAT or a Copy CAAT
 
Brown Edwards: The Future-Ready CPA Firm
Brown Edwards: The Future-Ready CPA FirmBrown Edwards: The Future-Ready CPA Firm
Brown Edwards: The Future-Ready CPA Firm
 
Reinventing Insurance
Reinventing InsuranceReinventing Insurance
Reinventing Insurance
 
Project Analysis on reason for attrition in an IT/ ITes industry
Project Analysis on reason for attrition in an IT/ ITes industryProject Analysis on reason for attrition in an IT/ ITes industry
Project Analysis on reason for attrition in an IT/ ITes industry
 
2015 SOA Annual Meeting - Beagle Street and Teachers Life
2015 SOA Annual Meeting - Beagle Street and Teachers Life2015 SOA Annual Meeting - Beagle Street and Teachers Life
2015 SOA Annual Meeting - Beagle Street and Teachers Life
 
Developing an integrated technology for the enhancement of insurance penetration
Developing an integrated technology for the enhancement of insurance penetrationDeveloping an integrated technology for the enhancement of insurance penetration
Developing an integrated technology for the enhancement of insurance penetration
 
The evolving role of IT managers and CIOs
The evolving role of IT managers and CIOsThe evolving role of IT managers and CIOs
The evolving role of IT managers and CIOs
 
Blacksmith Law Link April 2011
Blacksmith Law Link April 2011Blacksmith Law Link April 2011
Blacksmith Law Link April 2011
 
ROI On DLP
ROI On DLPROI On DLP
ROI On DLP
 

En vedette

201502 cmu portugal_highlights
201502 cmu portugal_highlights201502 cmu portugal_highlights
201502 cmu portugal_highlightsCMUPortugal_
 
Construyendo la reputacion corporativa desde el principio
Construyendo la reputacion corporativa desde el principioConstruyendo la reputacion corporativa desde el principio
Construyendo la reputacion corporativa desde el principioPedro Antonio García López
 
Why AWS's Redshift is a Game Changer
Why AWS's Redshift is a Game ChangerWhy AWS's Redshift is a Game Changer
Why AWS's Redshift is a Game Changer3Sixty Insights
 
Research Guides Tour
Research Guides TourResearch Guides Tour
Research Guides Tourlis02215
 
Presentation1 karen-mc-clintock
Presentation1 karen-mc-clintockPresentation1 karen-mc-clintock
Presentation1 karen-mc-clintockMilliCanada
 
The analytic hero's journey
The analytic hero's journeyThe analytic hero's journey
The analytic hero's journey3Sixty Insights
 
Library website features (February 2016)
Library website features (February 2016)Library website features (February 2016)
Library website features (February 2016)lis02215
 
Naperville north tech workshop day 1
Naperville north tech workshop day 1Naperville north tech workshop day 1
Naperville north tech workshop day 1joeewilson
 
The Analytic Hero’s Journey
The Analytic Hero’s JourneyThe Analytic Hero’s Journey
The Analytic Hero’s Journey3Sixty Insights
 
10 Things About the Library Website
10 Things About the Library Website10 Things About the Library Website
10 Things About the Library Websitelis02215
 
CMU Portugal inRes Initiative Presentation April 2014
CMU Portugal inRes Initiative Presentation April 2014CMU Portugal inRes Initiative Presentation April 2014
CMU Portugal inRes Initiative Presentation April 2014CMUPortugal_
 
Research guides tour (February 2016)
Research guides tour (February 2016)Research guides tour (February 2016)
Research guides tour (February 2016)lis02215
 

En vedette (20)

201502 cmu portugal_highlights
201502 cmu portugal_highlights201502 cmu portugal_highlights
201502 cmu portugal_highlights
 
Shopper insights Tracking
Shopper insights Tracking Shopper insights Tracking
Shopper insights Tracking
 
Presentation encuesta
Presentation encuesta Presentation encuesta
Presentation encuesta
 
Construyendo la reputacion corporativa desde el principio
Construyendo la reputacion corporativa desde el principioConstruyendo la reputacion corporativa desde el principio
Construyendo la reputacion corporativa desde el principio
 
Why AWS's Redshift is a Game Changer
Why AWS's Redshift is a Game ChangerWhy AWS's Redshift is a Game Changer
Why AWS's Redshift is a Game Changer
 
Research Guides Tour
Research Guides TourResearch Guides Tour
Research Guides Tour
 
Food Safety Webcast: Allergen Management
Food Safety Webcast: Allergen ManagementFood Safety Webcast: Allergen Management
Food Safety Webcast: Allergen Management
 
Chapter01
Chapter01Chapter01
Chapter01
 
Presentation1 karen-mc-clintock
Presentation1 karen-mc-clintockPresentation1 karen-mc-clintock
Presentation1 karen-mc-clintock
 
The analytic hero's journey
The analytic hero's journeyThe analytic hero's journey
The analytic hero's journey
 
Library website features (February 2016)
Library website features (February 2016)Library website features (February 2016)
Library website features (February 2016)
 
Naperville north tech workshop day 1
Naperville north tech workshop day 1Naperville north tech workshop day 1
Naperville north tech workshop day 1
 
The Analytic Hero’s Journey
The Analytic Hero’s JourneyThe Analytic Hero’s Journey
The Analytic Hero’s Journey
 
Ch4 1 v1
Ch4 1 v1Ch4 1 v1
Ch4 1 v1
 
Ch3 5 v1
Ch3 5 v1Ch3 5 v1
Ch3 5 v1
 
10 Things About the Library Website
10 Things About the Library Website10 Things About the Library Website
10 Things About the Library Website
 
CMU Portugal inRes Initiative Presentation April 2014
CMU Portugal inRes Initiative Presentation April 2014CMU Portugal inRes Initiative Presentation April 2014
CMU Portugal inRes Initiative Presentation April 2014
 
Research guides tour (February 2016)
Research guides tour (February 2016)Research guides tour (February 2016)
Research guides tour (February 2016)
 
Ch5 1 v1
Ch5 1 v1Ch5 1 v1
Ch5 1 v1
 
Ch3 1 v1
Ch3 1 v1Ch3 1 v1
Ch3 1 v1
 

Similaire à Investing in the Front End of Compliance

Legal ROI: Quality & Innovation, Incorporating Efficiency
Legal ROI: Quality & Innovation, Incorporating EfficiencyLegal ROI: Quality & Innovation, Incorporating Efficiency
Legal ROI: Quality & Innovation, Incorporating EfficiencyRon Dolin
 
Behavioural Economics & Financial Services: Improving Customer Outcomes
Behavioural Economics & Financial Services: Improving Customer OutcomesBehavioural Economics & Financial Services: Improving Customer Outcomes
Behavioural Economics & Financial Services: Improving Customer OutcomesPrime Decision
 
Corruption Risks Update 2009
Corruption Risks Update 2009Corruption Risks Update 2009
Corruption Risks Update 2009Stephen_Horne
 
In Focus: 2015 Compliance Trends Survey
In Focus: 2015 Compliance Trends SurveyIn Focus: 2015 Compliance Trends Survey
In Focus: 2015 Compliance Trends SurveyCenterRegStrategies
 
Corporate and Social Responsibility report iigi 2013 2014
Corporate and Social Responsibility  report iigi 2013 2014Corporate and Social Responsibility  report iigi 2013 2014
Corporate and Social Responsibility report iigi 2013 2014Independentgroup
 
The Evolving Role of the Chief Compliance Officer
The Evolving Role of the Chief Compliance OfficerThe Evolving Role of the Chief Compliance Officer
The Evolving Role of the Chief Compliance OfficerConvercent
 
Steve Bell - Lean IT @ 7. Kongres itSMF Polska 2014
Steve Bell  - Lean IT @ 7. Kongres itSMF Polska 2014Steve Bell  - Lean IT @ 7. Kongres itSMF Polska 2014
Steve Bell - Lean IT @ 7. Kongres itSMF Polska 2014Fundacja Governica
 
Stripping it back to behaviour. CRM for charity communicators conference, 2 D...
Stripping it back to behaviour. CRM for charity communicators conference, 2 D...Stripping it back to behaviour. CRM for charity communicators conference, 2 D...
Stripping it back to behaviour. CRM for charity communicators conference, 2 D...CharityComms
 
Conduct Risk – What Corporates Can Learn From The Financial Sector
Conduct Risk – What Corporates Can Learn From The Financial SectorConduct Risk – What Corporates Can Learn From The Financial Sector
Conduct Risk – What Corporates Can Learn From The Financial SectorEversheds Sutherland
 
2014 SMP Audit Report Responsible Business Standards
2014 SMP Audit Report Responsible Business Standards2014 SMP Audit Report Responsible Business Standards
2014 SMP Audit Report Responsible Business StandardsClive Bonny
 
Ethics and Compliance and the Path to Creating Value: The First 2 Years
Ethics and Compliance and the Path to Creating Value: The First 2 YearsEthics and Compliance and the Path to Creating Value: The First 2 Years
Ethics and Compliance and the Path to Creating Value: The First 2 YearsCatherine (Cass) Mercer Bing
 
We Have Met The Enemy - He is Us - The human factor in project failure
We Have Met The Enemy - He is Us - The human factor in project failureWe Have Met The Enemy - He is Us - The human factor in project failure
We Have Met The Enemy - He is Us - The human factor in project failurePeter Salmon
 
Measuring Impact - Tying Learning to Strategic Business Outcomes
Measuring Impact - Tying Learning to Strategic Business OutcomesMeasuring Impact - Tying Learning to Strategic Business Outcomes
Measuring Impact - Tying Learning to Strategic Business OutcomesAxonify
 
An Identity Crisis: Organizations Grapple With Growing Consumer Expectation f...
An Identity Crisis: Organizations Grapple With Growing Consumer Expectation f...An Identity Crisis: Organizations Grapple With Growing Consumer Expectation f...
An Identity Crisis: Organizations Grapple With Growing Consumer Expectation f...Deloitte United States
 
aochs intern presentation (2)
aochs intern presentation (2)aochs intern presentation (2)
aochs intern presentation (2)Anna Ochs
 

Similaire à Investing in the Front End of Compliance (20)

Legal ROI: Quality & Innovation, Incorporating Efficiency
Legal ROI: Quality & Innovation, Incorporating EfficiencyLegal ROI: Quality & Innovation, Incorporating Efficiency
Legal ROI: Quality & Innovation, Incorporating Efficiency
 
Metrics for In-House Teams
Metrics for In-House TeamsMetrics for In-House Teams
Metrics for In-House Teams
 
Behavioural Economics & Financial Services: Improving Customer Outcomes
Behavioural Economics & Financial Services: Improving Customer OutcomesBehavioural Economics & Financial Services: Improving Customer Outcomes
Behavioural Economics & Financial Services: Improving Customer Outcomes
 
Corruption Risks Update 2009
Corruption Risks Update 2009Corruption Risks Update 2009
Corruption Risks Update 2009
 
In Focus: 2015 Compliance Trends Survey
In Focus: 2015 Compliance Trends SurveyIn Focus: 2015 Compliance Trends Survey
In Focus: 2015 Compliance Trends Survey
 
Corporate and Social Responsibility report iigi 2013 2014
Corporate and Social Responsibility  report iigi 2013 2014Corporate and Social Responsibility  report iigi 2013 2014
Corporate and Social Responsibility report iigi 2013 2014
 
The Evolving Role of the Chief Compliance Officer
The Evolving Role of the Chief Compliance OfficerThe Evolving Role of the Chief Compliance Officer
The Evolving Role of the Chief Compliance Officer
 
Legal Resource Group Presentation
Legal Resource Group PresentationLegal Resource Group Presentation
Legal Resource Group Presentation
 
Steve Bell - Lean IT @ 7. Kongres itSMF Polska 2014
Steve Bell  - Lean IT @ 7. Kongres itSMF Polska 2014Steve Bell  - Lean IT @ 7. Kongres itSMF Polska 2014
Steve Bell - Lean IT @ 7. Kongres itSMF Polska 2014
 
Stripping it back to behaviour. CRM for charity communicators conference, 2 D...
Stripping it back to behaviour. CRM for charity communicators conference, 2 D...Stripping it back to behaviour. CRM for charity communicators conference, 2 D...
Stripping it back to behaviour. CRM for charity communicators conference, 2 D...
 
Why is Ethics and Compliance important
Why is Ethics and Compliance importantWhy is Ethics and Compliance important
Why is Ethics and Compliance important
 
Conduct Risk – What Corporates Can Learn From The Financial Sector
Conduct Risk – What Corporates Can Learn From The Financial SectorConduct Risk – What Corporates Can Learn From The Financial Sector
Conduct Risk – What Corporates Can Learn From The Financial Sector
 
Transforming under performing workers compensation schemes
Transforming under performing workers compensation schemesTransforming under performing workers compensation schemes
Transforming under performing workers compensation schemes
 
2014 SMP Audit Report Responsible Business Standards
2014 SMP Audit Report Responsible Business Standards2014 SMP Audit Report Responsible Business Standards
2014 SMP Audit Report Responsible Business Standards
 
Ethics and Compliance and the Path to Creating Value: The First 2 Years
Ethics and Compliance and the Path to Creating Value: The First 2 YearsEthics and Compliance and the Path to Creating Value: The First 2 Years
Ethics and Compliance and the Path to Creating Value: The First 2 Years
 
We Have Met The Enemy - He is Us - The human factor in project failure
We Have Met The Enemy - He is Us - The human factor in project failureWe Have Met The Enemy - He is Us - The human factor in project failure
We Have Met The Enemy - He is Us - The human factor in project failure
 
Metrus Group Presentation at EEA Networking Event.
Metrus Group Presentation at EEA Networking Event.Metrus Group Presentation at EEA Networking Event.
Metrus Group Presentation at EEA Networking Event.
 
Measuring Impact - Tying Learning to Strategic Business Outcomes
Measuring Impact - Tying Learning to Strategic Business OutcomesMeasuring Impact - Tying Learning to Strategic Business Outcomes
Measuring Impact - Tying Learning to Strategic Business Outcomes
 
An Identity Crisis: Organizations Grapple With Growing Consumer Expectation f...
An Identity Crisis: Organizations Grapple With Growing Consumer Expectation f...An Identity Crisis: Organizations Grapple With Growing Consumer Expectation f...
An Identity Crisis: Organizations Grapple With Growing Consumer Expectation f...
 
aochs intern presentation (2)
aochs intern presentation (2)aochs intern presentation (2)
aochs intern presentation (2)
 

Plus de 3Sixty Insights

The Future of Finance in a World of Global Digital Transformation
The Future of Finance in a World of Global Digital TransformationThe Future of Finance in a World of Global Digital Transformation
The Future of Finance in a World of Global Digital Transformation3Sixty Insights
 
Blue Hill Research: Managing Mobile Now and in the Future
Blue Hill Research: Managing Mobile Now and in the FutureBlue Hill Research: Managing Mobile Now and in the Future
Blue Hill Research: Managing Mobile Now and in the Future3Sixty Insights
 
The Analytic Hero's Journey
The Analytic Hero's JourneyThe Analytic Hero's Journey
The Analytic Hero's Journey3Sixty Insights
 
The Foundations of Social Media Risk Management
The Foundations of Social Media Risk ManagementThe Foundations of Social Media Risk Management
The Foundations of Social Media Risk Management3Sixty Insights
 
ROI of A Liberated Data Analyst
ROI of A Liberated Data AnalystROI of A Liberated Data Analyst
ROI of A Liberated Data Analyst3Sixty Insights
 
Achieving Better Credit and Collections with FinancialForce Accounting & Chatter
Achieving Better Credit and Collections with FinancialForce Accounting & ChatterAchieving Better Credit and Collections with FinancialForce Accounting & Chatter
Achieving Better Credit and Collections with FinancialForce Accounting & Chatter3Sixty Insights
 
Choosing AirWatch by VMware as a BYOD solution - A Blue Hill Research Case Study
Choosing AirWatch by VMware as a BYOD solution - A Blue Hill Research Case StudyChoosing AirWatch by VMware as a BYOD solution - A Blue Hill Research Case Study
Choosing AirWatch by VMware as a BYOD solution - A Blue Hill Research Case Study3Sixty Insights
 
SMAC talk for the enterprise
SMAC talk for the enterpriseSMAC talk for the enterprise
SMAC talk for the enterprise3Sixty Insights
 
Microsoft, Innovation, and its HR Failure
Microsoft, Innovation, and its HR FailureMicrosoft, Innovation, and its HR Failure
Microsoft, Innovation, and its HR Failure3Sixty Insights
 

Plus de 3Sixty Insights (10)

The Future of Finance in a World of Global Digital Transformation
The Future of Finance in a World of Global Digital TransformationThe Future of Finance in a World of Global Digital Transformation
The Future of Finance in a World of Global Digital Transformation
 
Blue Hill Research: Managing Mobile Now and in the Future
Blue Hill Research: Managing Mobile Now and in the FutureBlue Hill Research: Managing Mobile Now and in the Future
Blue Hill Research: Managing Mobile Now and in the Future
 
The Analytic Hero's Journey
The Analytic Hero's JourneyThe Analytic Hero's Journey
The Analytic Hero's Journey
 
The Foundations of Social Media Risk Management
The Foundations of Social Media Risk ManagementThe Foundations of Social Media Risk Management
The Foundations of Social Media Risk Management
 
ROI of A Liberated Data Analyst
ROI of A Liberated Data AnalystROI of A Liberated Data Analyst
ROI of A Liberated Data Analyst
 
Achieving Better Credit and Collections with FinancialForce Accounting & Chatter
Achieving Better Credit and Collections with FinancialForce Accounting & ChatterAchieving Better Credit and Collections with FinancialForce Accounting & Chatter
Achieving Better Credit and Collections with FinancialForce Accounting & Chatter
 
Choosing AirWatch by VMware as a BYOD solution - A Blue Hill Research Case Study
Choosing AirWatch by VMware as a BYOD solution - A Blue Hill Research Case StudyChoosing AirWatch by VMware as a BYOD solution - A Blue Hill Research Case Study
Choosing AirWatch by VMware as a BYOD solution - A Blue Hill Research Case Study
 
GRC Fundamentals
GRC FundamentalsGRC Fundamentals
GRC Fundamentals
 
SMAC talk for the enterprise
SMAC talk for the enterpriseSMAC talk for the enterprise
SMAC talk for the enterprise
 
Microsoft, Innovation, and its HR Failure
Microsoft, Innovation, and its HR FailureMicrosoft, Innovation, and its HR Failure
Microsoft, Innovation, and its HR Failure
 

Dernier

A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CVKhem
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?Igalia
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdfhans926745
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)wesley chun
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024The Digital Insurer
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Enterprise Knowledge
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?Antenna Manufacturer Coco
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 

Dernier (20)

A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 

Investing in the Front End of Compliance

  • 1. Investing in the “Front End” of Compliance: Policy Management & Training David Houlihan Principal Analyst Blue Hill Research ©2014 Blue Hill Research. All Rights Reserved. ©2014 Blue Hill Research. All Rights Reserved.
  • 2. About Me: Research: Ethics & Compliance Management Governance, Risk, and Compliance Legal Technology Background: United States Attorney’s Office Boston University GTC Law Group David Houlihan Principal Analyst ©2014 Blue Hill Research. All Rights Reserved. Aberdeen Group
  • 3. What I Do: How does this help our business? Answer Technology Questions Finance: Information Technology: Line of Business: ©2014 Blue Hill Research. All Rights Reserved. What’s the ROI & TCO? How do I implement & manage this? Does it improve my performance?
  • 4. Compliance & Non-compliance Costs 0% Overall Average Per capita per employee 25% 50% $3,529,570 75% $9,368,351 $222 $820 Compliance 100% $2.65 lost for every $1 spent on compliance $3.69 lost for every $1 spent on compliance Non-compliance Source: The True Cost of Compliance, Ponemon Institute January 2011 ©2014 Blue Hill Research. All Rights Reserved.
  • 5. In other words. . . What you spend on compliance represents only ~21% of what compliance costs you. (. . .per employee) ©2014 Blue Hill Research. All Rights Reserved.
  • 6. Cost Sources Compliance Non-Compliance 27% 60% Direct Direct Indirect Indirect Opportunity 30% 40% 43% ©2014 Blue Hill Research. All Rights Reserved. Source: The True Cost of Compliance, Ponemon Institute January 2011
  • 7. Compliance Cost Map Compliance Operations Staff Implementation Regulatory Action Full time Employees Cost to implement Attorney Costs Services Consultants Compliance Business Operations Function Risks Penalties Attorneys Time lost to implement Lost Opportunities Productivity Loss Auditors Resources Reputation ©2014 Blue Hill Research. All Rights Reserved. To information acquisition Attorney Costs Technology Content Private Legal Action Reduced Revenue Reduced Stock Value To monitoring Damages / Settlements To incident management
  • 8. The Challenge: If you only had $1 to spend on compliance. . . . . . how could you use it to get $4.69 in savings? ©2014 Blue Hill Research. All Rights Reserved.
  • 9. Compliance Management ©2014 Blue Hill Research. All Rights Reserved.
  • 10. Spend on Compliance Activities 13.8% 17.7% Policy management 11.9% 74.3% of what organizations spend on compliance goes to “firefighting.” Communications Program management Compliance monitoring Enforcement 25.5% 31.1% ©2014 Blue Hill Research. All Rights Reserved. Data: The True Cost of Compliance, Ponemon Institute January 2011 Analysis: Blue Hill Research
  • 11. My Recommendation: ©2014 Blue Hill Research. All Rights Reserved.
  • 12. Why Fire Prevention? Employee action creates compliance risk. ©2014 Blue Hill Research. All Rights Reserved.
  • 13. What about the “Bad Apple”? “Good Luck.” ©2014 Blue Hill Research. All Rights Reserved.
  • 14. But the Bigger Problems are. . . ???????????? (1) Confusion regarding requirements. (2) Lack incentive to act differently. ©2014 Blue Hill Research. All Rights Reserved.
  • 15. Policy Management: Policy Management Areas for improvement: Investment Impact: Stakeholders collaboration “Agency/organization” alignment Management of changes Efficiency of stakeholders Removal of outdated policies Clarity of requirements Communication of changed to organization ©2014 Blue Hill Research. All Rights Reserved.
  • 16. Training: Training Areas for improvement: Investment Impact: Employee engagement Efficiency of acknowledge acquisition Information retention Reduce risk of noncompliance Sense of consequence More “red flags” Guidelines of ambiguous situations ©2014 Blue Hill Research. All Rights Reserved.
  • 17. Build Your Business Case Compliance Operations Staff Implementation Regulatory Action Full time Employees Cost to implement Attorney Costs Services Consultants Compliance Business Operations Function Risks Penalties Attorneys Time lost to implement Lost Opportunities Productivity Loss Auditors Resources Reputation Reduced Revenue ©2014 Blue Hill Research. All Rights Reserved. To information acquisition Attorney Costs Technology Content Private Legal Action Reduced Stock Value To monitoring Damages / Settlements To incident management
  • 18. Key Factors to Consider in Solutions Policy Management • Support for content development • Ability to centrally manage and distribute content • Flexibility of content types incorporated • Security of solution • Support for retiring and archiving content Factors to Consider • Ability to link policy to training and insight into compliance operations Training • Expense of communication • Scalability of communication • Time required to obtain mastery • Employee engagement in training • Degree of internalization and retention • How closely supplied content supports objectives Potential integration with enterprise GRC suite to align policies and training with other compliance management and monitoring capabilities. ©2014 Blue Hill Research. All Rights Reserved.
  • 19. Thank you! To join the conversation, contact me: dhoulihan@bluehillresearch.com New research starts by the end of the month . . .or follow us: ©2014 Blue Hill Research. All Rights Reserved. 1

Notes de l'éditeur

  1. .