SlideShare une entreprise Scribd logo
1  sur  16
Sagar Sunkle and Vinay Kulkarni
Tata Consultancy Services Research, India
Toward a Holistic Method for Regulatory Change Management
1. Increasing spend on compliance (in US estimated at $15 Billion. Estimated to
increase 5 times more by 2018)
2. Demand for governance, risk management, and compliance (GRC) in US is most
high but Canada, Japan, India, Australia, South Africa, and members of EU have
started enforcing various regulations for some time now
3. Non-compliance is penalized severely
4. Largely document-oriented process with conservative interpretation of rules
5. Uncertainty about what constitutes compliance
6. Main challenges
a. Non-compliance identification + remediation + proof explanation
b. Regulatory change management with risk adjusted decision making
Motivation
Internal
Controls
Risk
Appetite
Key Objectives
Processes
Risks
Policies
Issues
Heat maps
Inquiries/Su
rveys
Governance
Compliance
Regulations and
Standards
Risk
define determine
use
contemplate
prevent,
detect,
correct,
track
associated
fulfill
identify risks
in
may be
ensure
compliance with
assessment
leads to
fulfill
are established
in
update
define
fulfill
Ideal- Integrated Governance, Risk, and
Compliance
Internal
Controls
Risk
Appetite
Processes
Risks Issues
Heat maps
Inquiries/Su
rveys
Governance
Compliance
Regulations and
Standards
Risk
determine
use
prevent,
detect,
correct,
track
associated
identify risks
in
may be
ensure
compliance with
assessment
leads to
update
define
fulfill
In reality- Industry GRC needs to be
improved
1. Informal
representation of
regulations-content
Management-based
2. Compliance proofs are
document-driven
3. Risk handling is expert-
reliant
Changes in
Internal
Controls
Changed
Processes
Change
Risks
Inquiries/Su
rveys
Business Process Modeling + Change Propagation
Formal Compliance Checking + Norm Change
Changes in
Regulations and
Standards
Risk Modeling + Change Risk
use
prevent,
detect, correct,
track
associated
Identify risks
in
ensure
compliance with
define
fulfill
enact in
In reality- Formal Research Needs to be Coordinated
Changes in
Internal
Controls
Formal Compliance Checking + Norm Change
Changes in
Regulations and
Standards
ensure
compliance with
fulfill
Formal Treatment of Changes in Regulations
• Distinction between legal and
count-as rules
• Distinction between norms
and their legal effects
• Distinction between Ex Tunc
and Ex Nunc norms
• Ways in which expansion and
contraction of legal effects is
achieved
Changes in
Internal
Controls
Formal Compliance Checking + Norm Change
Changes in
Regulations and
Standards
ensure
compliance with
fulfill
Formal Treatment of Changes in Regulations
To use norm change research,
formal representation of
regulations is necessary that is
capable of handling norm change
Changes in
Internal
Controls
Changed
Processes
Business Process Modeling + Change Propagation
Formal Compliance Checking + Norm Change
Changes in
Regulations and
Standards
ensure
compliance with
define
fulfill
enact in
Formal Treatment of Changes in Processes
• Considerable work in business
process compliance checking-
Enact regulations as rules in
business processes- One Size
Fits all solutions
• But do not take into
consideration where do
processes of enterprise lie along
the process rule continuum
Embedded Rules
Explicit Navigation Paths
Complex Navigation Analysis
Rule Guided Process Behavior
Rule-driven Process Composites
Rule-driven Services
Rule-Dynamic
Process-rule ContinuumLow Changeability High Changeability
Change in rules separate from
change in process model
Stable processes with no
frequent changes in process
model
Rules use process
context; frequent
changes in rules to adjust
to attribute values of
process elements
Rules use not only the process context but other
business data including historical data about attributes
of business objects
Domain-specific and meta-rules determine how to
evolve a process to optimize achievement of business
goals
Same as rule-driven process composites, but at a much
fine-grained level of services
Rules change dynamically leading
to dynamic composition of
business processes and services
Tailoring Propagation of Changes in Regulations to
Process Types
Changes in
Internal
Controls
Changed
Processes
Change
Risks
Inquiries/Su
rveys
Formal Compliance Checking + Norm Change
Changes in
Regulations and
Standards
Risk Modeling + Change Risk
use
prevent,
detect, correct,
track
associated
Identify risks
in
ensure
compliance with
fulfill
enact in
Risk Modeling in relation to Business Processes
Sizeable work in risk modeling
and some in risk aware
business processes
But risks and especially legal
risks are domain-specific=
probability of domain-specific
event evaluated by its domain-
specific consequences
Changes in
Internal
Controls
Changed
Processes
Change
Risks
Inquiries/Su
rveys
Business Process Modeling + Change Propagation
Formal Compliance Checking + Norm Change
Changes in
Regulations and
Standards
Risk Modeling + Change Risk
use
prevent,
detect, correct,
track
associated
Identify risks
in
ensure
compliance with
define
fulfill
enact in
Best of Both worlds- Integrated Formal GRC
BankType
IdentityProof
CustomerType DocumentType
AddressProof
obligatedTo
Perform
admits
1..*
hasRelated
obtain
1..*
1..*
DocumentSubmission
1..*
RiskProfile
hasRelated
1 hasRelated
Process
applicable
To
1..*Processes
Risk Regulations
BranchType
has
RiskPerception
isBasedOn
1..*
drives
1..*
DDDOfficer
DueDillegenceActivity
isCarriedOutBy
1..*
1..*
usedToMitigateA
MLRisk
1..*
Rules
customerType_data(Customer_ID,Conditions...)
customerType_KYC_document_data(Customer_ID,Conditions...)
Low < Medium < High
Prob(ML/FTevent, Consequence)
customerRiskProfile(
Customer_ID,
Risk_Status)
1..*
Early work I- Domain-specific Regulation Model
Early work II- Tie together Key Elements of
Business
Changes in
Internal
Controls
Changed
Processes
Change
Risks
Inquiries/Su
rveys
Business Process Modeling + Change Propagation
Formal Compliance Checking + Norm Change
Changes in
Regulations and
Standards
Risk Modeling + Change Risk
use
prevent,
detect, correct,
track
associated
Identify risks
in
ensure
compliance with
define
fulfill
enact in
Key
Objectives
define
fulfill
Early work II- Simulation of Regulatory Scenarios
1. Take into consideration business objectives of regulatee and regulation objectives
of regulator
2. Also represent actions of other important stakeholders such as regulatee’s
customers
3. Simulate core GRC components of processes, risk, and compliance along with
courses of action taken by regulatee, regulatee’s customers, and regulator
4. Early work with simulation machinery based on actor model of computation
5. Capable of representing propagation of changes triggered by changing
regulations
Conclusions
1. Regulatory compliance and regulatory change management are critical problems
and need to be solved with an integrated perspective
2. Best features of current industry GRC and formal solutions need to be put
together for a holistic treatment
3. Our proposal marries formal representation of regulations and changes therein to
a) business process and rule stage and b) risk in changes to regulation in GRC
context
Questions?
Please feel free to contact me at sagar.sunkle@tcs.com

Contenu connexe

Tendances

Vendor Management - PCI DSS, ISO 27001, E13PA,HIPPA & FFIEC
Vendor Management - PCI DSS, ISO 27001, E13PA,HIPPA & FFIECVendor Management - PCI DSS, ISO 27001, E13PA,HIPPA & FFIEC
Vendor Management - PCI DSS, ISO 27001, E13PA,HIPPA & FFIECControlCase
 
Governance, Risk, and Compliance Services
Governance, Risk, and Compliance ServicesGovernance, Risk, and Compliance Services
Governance, Risk, and Compliance ServicesCapgemini
 
What is GRC – Governance, Risk and Compliance
What is GRC – Governance, Risk and Compliance What is GRC – Governance, Risk and Compliance
What is GRC – Governance, Risk and Compliance BOC Group
 
6 benefits of internal auditing
6 benefits of internal auditing6 benefits of internal auditing
6 benefits of internal auditingSALIH AHMED ISLAM
 
CMLGroup - What is GRC?
CMLGroup - What is GRC?CMLGroup - What is GRC?
CMLGroup - What is GRC?CML Group
 
Governance Risk and Compliance - in Higher Education - Australia
Governance Risk and Compliance - in Higher Education - AustraliaGovernance Risk and Compliance - in Higher Education - Australia
Governance Risk and Compliance - in Higher Education - AustraliaMarissa McCauley
 
Governance risk and compliance
Governance risk and complianceGovernance risk and compliance
Governance risk and complianceMagdalena Matell
 
Governance, Risk, Compliance & Trust (OCEG graphics removed)
Governance, Risk, Compliance & Trust (OCEG graphics removed)Governance, Risk, Compliance & Trust (OCEG graphics removed)
Governance, Risk, Compliance & Trust (OCEG graphics removed)Alex Todd
 
Foundations Of Control
Foundations Of ControlFoundations Of Control
Foundations Of ControlRasha Shawoosh
 
The Vision, Highlights and Implementation Benefits of GRC STACK
The Vision, Highlights and Implementation Benefits of GRC STACKThe Vision, Highlights and Implementation Benefits of GRC STACK
The Vision, Highlights and Implementation Benefits of GRC STACKGRC Stack Pvt. Ltd,
 
Why businesses need to integrate their GRC now!
Why businesses need to integrate their GRC now!Why businesses need to integrate their GRC now!
Why businesses need to integrate their GRC now!GRC Stack Pvt. Ltd,
 
A Best Practices Guide to Quality Management
A Best Practices Guide to Quality ManagementA Best Practices Guide to Quality Management
A Best Practices Guide to Quality ManagementVERSE Solutions
 
Architecting the Framework for Compliance & Risk Management
Architecting the Framework for Compliance & Risk ManagementArchitecting the Framework for Compliance & Risk Management
Architecting the Framework for Compliance & Risk Managementjadams6
 
conroling slides by sohar bakhsh
conroling slides by sohar bakhshconroling slides by sohar bakhsh
conroling slides by sohar bakhshSohar Bakhsh
 
Control Self Assessment
Control Self AssessmentControl Self Assessment
Control Self AssessmentManoj Agarwal
 
A Lawyer, a Salesperson and the Operations Guy Walk into a Bar . . .
A Lawyer, a Salesperson and the Operations Guy Walk into a Bar . . .A Lawyer, a Salesperson and the Operations Guy Walk into a Bar . . .
A Lawyer, a Salesperson and the Operations Guy Walk into a Bar . . .jadams6
 
Foundations of control
Foundations of controlFoundations of control
Foundations of controlShaibal Ahmed
 

Tendances (20)

GRC
GRCGRC
GRC
 
Vendor Management - PCI DSS, ISO 27001, E13PA,HIPPA & FFIEC
Vendor Management - PCI DSS, ISO 27001, E13PA,HIPPA & FFIECVendor Management - PCI DSS, ISO 27001, E13PA,HIPPA & FFIEC
Vendor Management - PCI DSS, ISO 27001, E13PA,HIPPA & FFIEC
 
Governance, Risk, and Compliance Services
Governance, Risk, and Compliance ServicesGovernance, Risk, and Compliance Services
Governance, Risk, and Compliance Services
 
What is GRC – Governance, Risk and Compliance
What is GRC – Governance, Risk and Compliance What is GRC – Governance, Risk and Compliance
What is GRC – Governance, Risk and Compliance
 
6 benefits of internal auditing
6 benefits of internal auditing6 benefits of internal auditing
6 benefits of internal auditing
 
CMLGroup - What is GRC?
CMLGroup - What is GRC?CMLGroup - What is GRC?
CMLGroup - What is GRC?
 
Governance Risk and Compliance - in Higher Education - Australia
Governance Risk and Compliance - in Higher Education - AustraliaGovernance Risk and Compliance - in Higher Education - Australia
Governance Risk and Compliance - in Higher Education - Australia
 
Governance risk and compliance
Governance risk and complianceGovernance risk and compliance
Governance risk and compliance
 
Governance, Risk, Compliance & Trust (OCEG graphics removed)
Governance, Risk, Compliance & Trust (OCEG graphics removed)Governance, Risk, Compliance & Trust (OCEG graphics removed)
Governance, Risk, Compliance & Trust (OCEG graphics removed)
 
Getting It Right
Getting It RightGetting It Right
Getting It Right
 
Foundations Of Control
Foundations Of ControlFoundations Of Control
Foundations Of Control
 
The Vision, Highlights and Implementation Benefits of GRC STACK
The Vision, Highlights and Implementation Benefits of GRC STACKThe Vision, Highlights and Implementation Benefits of GRC STACK
The Vision, Highlights and Implementation Benefits of GRC STACK
 
Why businesses need to integrate their GRC now!
Why businesses need to integrate their GRC now!Why businesses need to integrate their GRC now!
Why businesses need to integrate their GRC now!
 
A Best Practices Guide to Quality Management
A Best Practices Guide to Quality ManagementA Best Practices Guide to Quality Management
A Best Practices Guide to Quality Management
 
Architecting the Framework for Compliance & Risk Management
Architecting the Framework for Compliance & Risk ManagementArchitecting the Framework for Compliance & Risk Management
Architecting the Framework for Compliance & Risk Management
 
conroling slides by sohar bakhsh
conroling slides by sohar bakhshconroling slides by sohar bakhsh
conroling slides by sohar bakhsh
 
Control Self Assessment
Control Self AssessmentControl Self Assessment
Control Self Assessment
 
Context of the organization
Context of the organizationContext of the organization
Context of the organization
 
A Lawyer, a Salesperson and the Operations Guy Walk into a Bar . . .
A Lawyer, a Salesperson and the Operations Guy Walk into a Bar . . .A Lawyer, a Salesperson and the Operations Guy Walk into a Bar . . .
A Lawyer, a Salesperson and the Operations Guy Walk into a Bar . . .
 
Foundations of control
Foundations of controlFoundations of control
Foundations of control
 

En vedette

Novice guide on digital slr pictures
Novice guide on digital slr picturesNovice guide on digital slr pictures
Novice guide on digital slr picturesallen62satterlee
 
PHP függőségkezelés composerrrel
PHP függőségkezelés composerrrelPHP függőségkezelés composerrrel
PHP függőségkezelés composerrrelmaerlyng
 
Nrg Flow Booklet[1]
Nrg Flow Booklet[1]Nrg Flow Booklet[1]
Nrg Flow Booklet[1]SamuelOrphe
 
Introduction of vef programs as of april 13a
Introduction of vef programs   as of april 13aIntroduction of vef programs   as of april 13a
Introduction of vef programs as of april 13acuongvef
 

En vedette (7)

Novice guide on digital slr pictures
Novice guide on digital slr picturesNovice guide on digital slr pictures
Novice guide on digital slr pictures
 
Cultural tourism glossary enjoy language within tourism project (1)
Cultural tourism glossary   enjoy language within tourism project (1)Cultural tourism glossary   enjoy language within tourism project (1)
Cultural tourism glossary enjoy language within tourism project (1)
 
PHP függőségkezelés composerrrel
PHP függőségkezelés composerrrelPHP függőségkezelés composerrrel
PHP függőségkezelés composerrrel
 
Nrg Flow Booklet[1]
Nrg Flow Booklet[1]Nrg Flow Booklet[1]
Nrg Flow Booklet[1]
 
Introduction of vef programs as of april 13a
Introduction of vef programs   as of april 13aIntroduction of vef programs   as of april 13a
Introduction of vef programs as of april 13a
 
Hotel vocabulary enjoy language within tourism project
Hotel vocabulary   enjoy language within tourism projectHotel vocabulary   enjoy language within tourism project
Hotel vocabulary enjoy language within tourism project
 
Silex
SilexSilex
Silex
 

Similaire à Holistic GRC Approach Links Processes, Risks, Compliance

Risk and Regulatory Change Management - 360factors EUEC 2015 Presentation
Risk and Regulatory Change Management - 360factors EUEC 2015 PresentationRisk and Regulatory Change Management - 360factors EUEC 2015 Presentation
Risk and Regulatory Change Management - 360factors EUEC 2015 Presentation360factors
 
2016-06-08 FDA Inspection Readiness - Mikael Yde
2016-06-08 FDA Inspection Readiness - Mikael Yde2016-06-08 FDA Inspection Readiness - Mikael Yde
2016-06-08 FDA Inspection Readiness - Mikael Ydemikaelyde
 
What do the changes to ISO14001 mean for business?
What do the changes to ISO14001 mean for business? What do the changes to ISO14001 mean for business?
What do the changes to ISO14001 mean for business? Ardea International
 
Working in Compliance vs. Working On Compliance
Working in Compliance vs. Working On ComplianceWorking in Compliance vs. Working On Compliance
Working in Compliance vs. Working On Compliance360factors
 
ISO 9001 2015 Overview presentation
ISO 9001 2015 Overview presentation ISO 9001 2015 Overview presentation
ISO 9001 2015 Overview presentation Govind Ramu
 
Regulatory Change Management
Regulatory Change ManagementRegulatory Change Management
Regulatory Change Management360factors
 
ASSE Safety 2016: Ed Sattar Speaks about Operational Risk and Regulatory Chan...
ASSE Safety 2016: Ed Sattar Speaks about Operational Risk and Regulatory Chan...ASSE Safety 2016: Ed Sattar Speaks about Operational Risk and Regulatory Chan...
ASSE Safety 2016: Ed Sattar Speaks about Operational Risk and Regulatory Chan...Ed Sattar
 
REGULATORY CHANGE MANAGEMENT (RCM) In Environmental Health and Safety
REGULATORY CHANGE MANAGEMENT  (RCM)   In Environmental Health and SafetyREGULATORY CHANGE MANAGEMENT  (RCM)   In Environmental Health and Safety
REGULATORY CHANGE MANAGEMENT (RCM) In Environmental Health and Safety360factors
 
Segregation of Duties Solutions
Segregation of Duties SolutionsSegregation of Duties Solutions
Segregation of Duties SolutionsAhmed Abdul Hamed
 
gray_audit_presentation.ppt
gray_audit_presentation.pptgray_audit_presentation.ppt
gray_audit_presentation.pptKhalilIdhman
 
Maclear’s IT GRC Tools – Key Issues and Trends
Maclear’s  IT GRC Tools – Key Issues and TrendsMaclear’s  IT GRC Tools – Key Issues and Trends
Maclear’s IT GRC Tools – Key Issues and TrendsMaclear LLC
 
Awareness of iatf 16949
Awareness of iatf 16949Awareness of iatf 16949
Awareness of iatf 16949Pavan Patil
 
Toronix - SOA Governance Quick Start
Toronix - SOA Governance Quick StartToronix - SOA Governance Quick Start
Toronix - SOA Governance Quick Startrrowntree
 
ISO9001 2015 Quality Manual template
ISO9001 2015 Quality Manual templateISO9001 2015 Quality Manual template
ISO9001 2015 Quality Manual templateRyan Chen
 
TrustedAgent GRC for Public Sector
TrustedAgent GRC for Public SectorTrustedAgent GRC for Public Sector
TrustedAgent GRC for Public SectorTri Phan
 
TrustedAgent GRC for Public Sector
TrustedAgent GRC for Public SectorTrustedAgent GRC for Public Sector
TrustedAgent GRC for Public SectorTuan Phan
 
Running Head ZIFFCORP AUDIT PROPOSAL 1 ZiffCo.docx
Running Head ZIFFCORP AUDIT PROPOSAL 1 ZiffCo.docxRunning Head ZIFFCORP AUDIT PROPOSAL 1 ZiffCo.docx
Running Head ZIFFCORP AUDIT PROPOSAL 1 ZiffCo.docxjeffsrosalyn
 
Model-Driven Regulatory Compliance: A Case Study of “Know Your Customer” Regu...
Model-Driven Regulatory Compliance: A Case Study of “Know Your Customer” Regu...Model-Driven Regulatory Compliance: A Case Study of “Know Your Customer” Regu...
Model-Driven Regulatory Compliance: A Case Study of “Know Your Customer” Regu...Dr.-Ing. Sagar Sunkle
 

Similaire à Holistic GRC Approach Links Processes, Risks, Compliance (20)

Risk and Regulatory Change Management - 360factors EUEC 2015 Presentation
Risk and Regulatory Change Management - 360factors EUEC 2015 PresentationRisk and Regulatory Change Management - 360factors EUEC 2015 Presentation
Risk and Regulatory Change Management - 360factors EUEC 2015 Presentation
 
2016-06-08 FDA Inspection Readiness - Mikael Yde
2016-06-08 FDA Inspection Readiness - Mikael Yde2016-06-08 FDA Inspection Readiness - Mikael Yde
2016-06-08 FDA Inspection Readiness - Mikael Yde
 
What do the changes to ISO14001 mean for business?
What do the changes to ISO14001 mean for business? What do the changes to ISO14001 mean for business?
What do the changes to ISO14001 mean for business?
 
Working in Compliance vs. Working On Compliance
Working in Compliance vs. Working On ComplianceWorking in Compliance vs. Working On Compliance
Working in Compliance vs. Working On Compliance
 
ISO 9001 2015 Overview presentation
ISO 9001 2015 Overview presentation ISO 9001 2015 Overview presentation
ISO 9001 2015 Overview presentation
 
Regulatory Change Management
Regulatory Change ManagementRegulatory Change Management
Regulatory Change Management
 
ASSE Safety 2016: Ed Sattar Speaks about Operational Risk and Regulatory Chan...
ASSE Safety 2016: Ed Sattar Speaks about Operational Risk and Regulatory Chan...ASSE Safety 2016: Ed Sattar Speaks about Operational Risk and Regulatory Chan...
ASSE Safety 2016: Ed Sattar Speaks about Operational Risk and Regulatory Chan...
 
REGULATORY CHANGE MANAGEMENT (RCM) In Environmental Health and Safety
REGULATORY CHANGE MANAGEMENT  (RCM)   In Environmental Health and SafetyREGULATORY CHANGE MANAGEMENT  (RCM)   In Environmental Health and Safety
REGULATORY CHANGE MANAGEMENT (RCM) In Environmental Health and Safety
 
Dennis Batdorf resume
Dennis Batdorf resumeDennis Batdorf resume
Dennis Batdorf resume
 
Segregation of Duties Solutions
Segregation of Duties SolutionsSegregation of Duties Solutions
Segregation of Duties Solutions
 
gray_audit_presentation.ppt
gray_audit_presentation.pptgray_audit_presentation.ppt
gray_audit_presentation.ppt
 
Maclear’s IT GRC Tools – Key Issues and Trends
Maclear’s  IT GRC Tools – Key Issues and TrendsMaclear’s  IT GRC Tools – Key Issues and Trends
Maclear’s IT GRC Tools – Key Issues and Trends
 
Awareness of iatf 16949
Awareness of iatf 16949Awareness of iatf 16949
Awareness of iatf 16949
 
Toronix - SOA Governance Quick Start
Toronix - SOA Governance Quick StartToronix - SOA Governance Quick Start
Toronix - SOA Governance Quick Start
 
Gamp 5 overview by jaya prakash ra
Gamp 5 overview by jaya prakash raGamp 5 overview by jaya prakash ra
Gamp 5 overview by jaya prakash ra
 
ISO9001 2015 Quality Manual template
ISO9001 2015 Quality Manual templateISO9001 2015 Quality Manual template
ISO9001 2015 Quality Manual template
 
TrustedAgent GRC for Public Sector
TrustedAgent GRC for Public SectorTrustedAgent GRC for Public Sector
TrustedAgent GRC for Public Sector
 
TrustedAgent GRC for Public Sector
TrustedAgent GRC for Public SectorTrustedAgent GRC for Public Sector
TrustedAgent GRC for Public Sector
 
Running Head ZIFFCORP AUDIT PROPOSAL 1 ZiffCo.docx
Running Head ZIFFCORP AUDIT PROPOSAL 1 ZiffCo.docxRunning Head ZIFFCORP AUDIT PROPOSAL 1 ZiffCo.docx
Running Head ZIFFCORP AUDIT PROPOSAL 1 ZiffCo.docx
 
Model-Driven Regulatory Compliance: A Case Study of “Know Your Customer” Regu...
Model-Driven Regulatory Compliance: A Case Study of “Know Your Customer” Regu...Model-Driven Regulatory Compliance: A Case Study of “Know Your Customer” Regu...
Model-Driven Regulatory Compliance: A Case Study of “Know Your Customer” Regu...
 

Plus de Dr.-Ing. Sagar Sunkle

Explanation of Proofs of Regulatory (Non-)Compliance Using Semantic Vocabularies
Explanation of Proofs of Regulatory (Non-)Compliance Using Semantic VocabulariesExplanation of Proofs of Regulatory (Non-)Compliance Using Semantic Vocabularies
Explanation of Proofs of Regulatory (Non-)Compliance Using Semantic VocabulariesDr.-Ing. Sagar Sunkle
 
Toward Better Mapping between Regulations and Operational Details of Enterpri...
Toward Better Mapping between Regulations and Operational Details of Enterpri...Toward Better Mapping between Regulations and Operational Details of Enterpri...
Toward Better Mapping between Regulations and Operational Details of Enterpri...Dr.-Ing. Sagar Sunkle
 
Solving Semantic Disparity and Explanation Problems in Regulatory Compliance
Solving Semantic Disparity and Explanation Problems in Regulatory Compliance Solving Semantic Disparity and Explanation Problems in Regulatory Compliance
Solving Semantic Disparity and Explanation Problems in Regulatory Compliance Dr.-Ing. Sagar Sunkle
 
Practical Goal Modeling for Enterprise Change Context: A Problem Statement
Practical Goal Modeling for Enterprise ChangeContext: A Problem StatementPractical Goal Modeling for Enterprise ChangeContext: A Problem Statement
Practical Goal Modeling for Enterprise Change Context: A Problem StatementDr.-Ing. Sagar Sunkle
 
Toward Structured Simulation of What-If Analyses for Enterprise
Toward Structured Simulation of What-If Analyses for EnterpriseToward Structured Simulation of What-If Analyses for Enterprise
Toward Structured Simulation of What-If Analyses for EnterpriseDr.-Ing. Sagar Sunkle
 
Toward Structured Simulation of Enterprise Models
Toward Structured Simulation of Enterprise ModelsToward Structured Simulation of Enterprise Models
Toward Structured Simulation of Enterprise ModelsDr.-Ing. Sagar Sunkle
 
Incorporating Directives into Enterprise TO-BE Architecture
Incorporating Directives into Enterprise TO-BE ArchitectureIncorporating Directives into Enterprise TO-BE Architecture
Incorporating Directives into Enterprise TO-BE ArchitectureDr.-Ing. Sagar Sunkle
 
Visual Modeling Editor and Ontology API-based Analysis for Decision Making in...
Visual Modeling Editor and Ontology API-based Analysis for Decision Making in...Visual Modeling Editor and Ontology API-based Analysis for Decision Making in...
Visual Modeling Editor and Ontology API-based Analysis for Decision Making in...Dr.-Ing. Sagar Sunkle
 
Intentional modeling for problem solving in enterprise architecture (ICEIS 20...
Intentional modeling for problem solving in enterprise architecture (ICEIS 20...Intentional modeling for problem solving in enterprise architecture (ICEIS 20...
Intentional modeling for problem solving in enterprise architecture (ICEIS 20...Dr.-Ing. Sagar Sunkle
 
Analyzing enterprise models using enterprise architecture-based ontology (MOD...
Analyzing enterprise models using enterprise architecture-based ontology (MOD...Analyzing enterprise models using enterprise architecture-based ontology (MOD...
Analyzing enterprise models using enterprise architecture-based ontology (MOD...Dr.-Ing. Sagar Sunkle
 
Toward innovative model based enterprise IT outsourcing (NGEBIS CAISE 2013)
Toward innovative model based enterprise IT outsourcing (NGEBIS CAISE 2013)Toward innovative model based enterprise IT outsourcing (NGEBIS CAISE 2013)
Toward innovative model based enterprise IT outsourcing (NGEBIS CAISE 2013)Dr.-Ing. Sagar Sunkle
 

Plus de Dr.-Ing. Sagar Sunkle (11)

Explanation of Proofs of Regulatory (Non-)Compliance Using Semantic Vocabularies
Explanation of Proofs of Regulatory (Non-)Compliance Using Semantic VocabulariesExplanation of Proofs of Regulatory (Non-)Compliance Using Semantic Vocabularies
Explanation of Proofs of Regulatory (Non-)Compliance Using Semantic Vocabularies
 
Toward Better Mapping between Regulations and Operational Details of Enterpri...
Toward Better Mapping between Regulations and Operational Details of Enterpri...Toward Better Mapping between Regulations and Operational Details of Enterpri...
Toward Better Mapping between Regulations and Operational Details of Enterpri...
 
Solving Semantic Disparity and Explanation Problems in Regulatory Compliance
Solving Semantic Disparity and Explanation Problems in Regulatory Compliance Solving Semantic Disparity and Explanation Problems in Regulatory Compliance
Solving Semantic Disparity and Explanation Problems in Regulatory Compliance
 
Practical Goal Modeling for Enterprise Change Context: A Problem Statement
Practical Goal Modeling for Enterprise ChangeContext: A Problem StatementPractical Goal Modeling for Enterprise ChangeContext: A Problem Statement
Practical Goal Modeling for Enterprise Change Context: A Problem Statement
 
Toward Structured Simulation of What-If Analyses for Enterprise
Toward Structured Simulation of What-If Analyses for EnterpriseToward Structured Simulation of What-If Analyses for Enterprise
Toward Structured Simulation of What-If Analyses for Enterprise
 
Toward Structured Simulation of Enterprise Models
Toward Structured Simulation of Enterprise ModelsToward Structured Simulation of Enterprise Models
Toward Structured Simulation of Enterprise Models
 
Incorporating Directives into Enterprise TO-BE Architecture
Incorporating Directives into Enterprise TO-BE ArchitectureIncorporating Directives into Enterprise TO-BE Architecture
Incorporating Directives into Enterprise TO-BE Architecture
 
Visual Modeling Editor and Ontology API-based Analysis for Decision Making in...
Visual Modeling Editor and Ontology API-based Analysis for Decision Making in...Visual Modeling Editor and Ontology API-based Analysis for Decision Making in...
Visual Modeling Editor and Ontology API-based Analysis for Decision Making in...
 
Intentional modeling for problem solving in enterprise architecture (ICEIS 20...
Intentional modeling for problem solving in enterprise architecture (ICEIS 20...Intentional modeling for problem solving in enterprise architecture (ICEIS 20...
Intentional modeling for problem solving in enterprise architecture (ICEIS 20...
 
Analyzing enterprise models using enterprise architecture-based ontology (MOD...
Analyzing enterprise models using enterprise architecture-based ontology (MOD...Analyzing enterprise models using enterprise architecture-based ontology (MOD...
Analyzing enterprise models using enterprise architecture-based ontology (MOD...
 
Toward innovative model based enterprise IT outsourcing (NGEBIS CAISE 2013)
Toward innovative model based enterprise IT outsourcing (NGEBIS CAISE 2013)Toward innovative model based enterprise IT outsourcing (NGEBIS CAISE 2013)
Toward innovative model based enterprise IT outsourcing (NGEBIS CAISE 2013)
 

Dernier

Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyAlfredo García Lavilla
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brandgvaughan
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebUiPathCommunity
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024Lonnie McRorey
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek SchlawackFwdays
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii SoldatenkoFwdays
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfPrecisely
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clashcharlottematthew16
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsRizwan Syed
 
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostLeverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostZilliz
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsPixlogix Infotech
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubKalema Edgar
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc
 

Dernier (20)

Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easy
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brand
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio Web
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clash
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL Certs
 
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostLeverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and Cons
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding Club
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 

Holistic GRC Approach Links Processes, Risks, Compliance

  • 1. Sagar Sunkle and Vinay Kulkarni Tata Consultancy Services Research, India Toward a Holistic Method for Regulatory Change Management
  • 2. 1. Increasing spend on compliance (in US estimated at $15 Billion. Estimated to increase 5 times more by 2018) 2. Demand for governance, risk management, and compliance (GRC) in US is most high but Canada, Japan, India, Australia, South Africa, and members of EU have started enforcing various regulations for some time now 3. Non-compliance is penalized severely 4. Largely document-oriented process with conservative interpretation of rules 5. Uncertainty about what constitutes compliance 6. Main challenges a. Non-compliance identification + remediation + proof explanation b. Regulatory change management with risk adjusted decision making Motivation
  • 3. Internal Controls Risk Appetite Key Objectives Processes Risks Policies Issues Heat maps Inquiries/Su rveys Governance Compliance Regulations and Standards Risk define determine use contemplate prevent, detect, correct, track associated fulfill identify risks in may be ensure compliance with assessment leads to fulfill are established in update define fulfill Ideal- Integrated Governance, Risk, and Compliance
  • 4. Internal Controls Risk Appetite Processes Risks Issues Heat maps Inquiries/Su rveys Governance Compliance Regulations and Standards Risk determine use prevent, detect, correct, track associated identify risks in may be ensure compliance with assessment leads to update define fulfill In reality- Industry GRC needs to be improved 1. Informal representation of regulations-content Management-based 2. Compliance proofs are document-driven 3. Risk handling is expert- reliant
  • 5. Changes in Internal Controls Changed Processes Change Risks Inquiries/Su rveys Business Process Modeling + Change Propagation Formal Compliance Checking + Norm Change Changes in Regulations and Standards Risk Modeling + Change Risk use prevent, detect, correct, track associated Identify risks in ensure compliance with define fulfill enact in In reality- Formal Research Needs to be Coordinated
  • 6. Changes in Internal Controls Formal Compliance Checking + Norm Change Changes in Regulations and Standards ensure compliance with fulfill Formal Treatment of Changes in Regulations • Distinction between legal and count-as rules • Distinction between norms and their legal effects • Distinction between Ex Tunc and Ex Nunc norms • Ways in which expansion and contraction of legal effects is achieved
  • 7. Changes in Internal Controls Formal Compliance Checking + Norm Change Changes in Regulations and Standards ensure compliance with fulfill Formal Treatment of Changes in Regulations To use norm change research, formal representation of regulations is necessary that is capable of handling norm change
  • 8. Changes in Internal Controls Changed Processes Business Process Modeling + Change Propagation Formal Compliance Checking + Norm Change Changes in Regulations and Standards ensure compliance with define fulfill enact in Formal Treatment of Changes in Processes • Considerable work in business process compliance checking- Enact regulations as rules in business processes- One Size Fits all solutions • But do not take into consideration where do processes of enterprise lie along the process rule continuum
  • 9. Embedded Rules Explicit Navigation Paths Complex Navigation Analysis Rule Guided Process Behavior Rule-driven Process Composites Rule-driven Services Rule-Dynamic Process-rule ContinuumLow Changeability High Changeability Change in rules separate from change in process model Stable processes with no frequent changes in process model Rules use process context; frequent changes in rules to adjust to attribute values of process elements Rules use not only the process context but other business data including historical data about attributes of business objects Domain-specific and meta-rules determine how to evolve a process to optimize achievement of business goals Same as rule-driven process composites, but at a much fine-grained level of services Rules change dynamically leading to dynamic composition of business processes and services Tailoring Propagation of Changes in Regulations to Process Types
  • 10. Changes in Internal Controls Changed Processes Change Risks Inquiries/Su rveys Formal Compliance Checking + Norm Change Changes in Regulations and Standards Risk Modeling + Change Risk use prevent, detect, correct, track associated Identify risks in ensure compliance with fulfill enact in Risk Modeling in relation to Business Processes Sizeable work in risk modeling and some in risk aware business processes But risks and especially legal risks are domain-specific= probability of domain-specific event evaluated by its domain- specific consequences
  • 11. Changes in Internal Controls Changed Processes Change Risks Inquiries/Su rveys Business Process Modeling + Change Propagation Formal Compliance Checking + Norm Change Changes in Regulations and Standards Risk Modeling + Change Risk use prevent, detect, correct, track associated Identify risks in ensure compliance with define fulfill enact in Best of Both worlds- Integrated Formal GRC
  • 12. BankType IdentityProof CustomerType DocumentType AddressProof obligatedTo Perform admits 1..* hasRelated obtain 1..* 1..* DocumentSubmission 1..* RiskProfile hasRelated 1 hasRelated Process applicable To 1..*Processes Risk Regulations BranchType has RiskPerception isBasedOn 1..* drives 1..* DDDOfficer DueDillegenceActivity isCarriedOutBy 1..* 1..* usedToMitigateA MLRisk 1..* Rules customerType_data(Customer_ID,Conditions...) customerType_KYC_document_data(Customer_ID,Conditions...) Low < Medium < High Prob(ML/FTevent, Consequence) customerRiskProfile( Customer_ID, Risk_Status) 1..* Early work I- Domain-specific Regulation Model
  • 13. Early work II- Tie together Key Elements of Business Changes in Internal Controls Changed Processes Change Risks Inquiries/Su rveys Business Process Modeling + Change Propagation Formal Compliance Checking + Norm Change Changes in Regulations and Standards Risk Modeling + Change Risk use prevent, detect, correct, track associated Identify risks in ensure compliance with define fulfill enact in Key Objectives define fulfill
  • 14. Early work II- Simulation of Regulatory Scenarios 1. Take into consideration business objectives of regulatee and regulation objectives of regulator 2. Also represent actions of other important stakeholders such as regulatee’s customers 3. Simulate core GRC components of processes, risk, and compliance along with courses of action taken by regulatee, regulatee’s customers, and regulator 4. Early work with simulation machinery based on actor model of computation 5. Capable of representing propagation of changes triggered by changing regulations
  • 15. Conclusions 1. Regulatory compliance and regulatory change management are critical problems and need to be solved with an integrated perspective 2. Best features of current industry GRC and formal solutions need to be put together for a holistic treatment 3. Our proposal marries formal representation of regulations and changes therein to a) business process and rule stage and b) risk in changes to regulation in GRC context
  • 16. Questions? Please feel free to contact me at sagar.sunkle@tcs.com

Notes de l'éditeur

  1. Major Risk adjusted decision making and risk evaluation for other corporate business objectives Ex. Active Risk Manager, Archer EMC-RSA Data collection for risk-based decision making Ex. Most GRC solutions provide some support but none exemplary [based on Gartner 2011 and 2012 GRC Magic Quadrants] Data and risk visualization Ex. Jade MethodWare Geography support meeting specific needs of geographies outside native geography Ex. CMO Compliance Minor Integration of GRC software with office productivity software Ex. IBM OpenPages Open source capabilities for content management Ex. AlignAlytics