In late 2017, John Wheeler, Gartner's Global Research Leader for Risk Management Technology, claimed that Governance, Risk, and Compliance (GRC) had become obsolete. In a blog, he announced that Gartner would shift its focus from GRC to Integrated Risk Management (IRM).
What Is the Difference Between IRM and GRC?
GRC is a structured approach that aligns governance, risk management, and compliance activities to help organizations meet objectives while addressing uncertainty and acting with integrity. IRM is a set of practices and processes supported by a risk-aware culture and enabling technologies that improves decision making and performance through an integrated view of how well an organization manages its unique set of risks. Gartner defines IRM using this framework, and the research firm predicted that the number of large enterprises using an IRM solution set would rise from 30% in 2017 to 50% by 2021.
Wheeler believes IRM can shift from GRC’s compliance focus to an analysis of how risk affects all business operations. However, IRM and GRC share significant overlap, and organizations with mature GRC programs that include a complementary enterprise risk management (ERM) focus may already be achieving IRM objectives. ERM is the quantifiable process of identifying, assessing, and managing risks across an entire organization to support strategic decision-making.
IRM vs. GRC: Key Differences
| 维度 | GRC | IRM |
|---|---|---|
| Primary Focus | Compliance and governance | Risk-aware decision making |
| Approach | Conceptual framework for policies and controls | Integrated, data-driven risk analysis |
| 范围 | Regulatory requirements and internal policies | Enterprise-wide risk across all operations |
| Business Outcome | Meeting compliance obligations | Improved performance through risk insights |
是否有必要从 GRC 转向 IRM?
The increasing emphasis on Big Data and the Internet of Things (IoT), as well as globalization and the growing utilization of third-party vendors, are all motivations for concern over organizational risks. A GRC program—when combined with ERM—is capable of managing these evolving risks effectively.
虽然 GRC 和 ERM 的目标相同,但方法历来大相径庭。GRC 更多地从概念上解决治理和合规问题。相比之下,机构风险管理是衡量风险的量化过程。
Many organizations struggle when combining several different platforms to meet compliance and risk needs. A solution that rests at the intersection of both addresses this challenge. While Gartner says prioritizing compliance can hurt risk management, the right ERM-GRC solution can help your organization focus on both.
将 GRC 和 ERM 合二为一
More organizations are turning to adaptable, configurable, and intuitive ERM-GRC solutions to meet the needs of integrated risk management. The best of these allow them to master compliance and risk with fully integrated and turnkey functionality.
Their policies and controls can be linked to federal and state laws, guidelines, and compliance requirements within an ERM-GRC system that has compliance policy management features. These supply a central hub to manage policies, procedures, and enterprise documentation for regulatory, legal, and compliance requirements as well as audits and examinations.
ERM-GRC 软件为一个组织的风险和合规环境提供了解决方案,无论它的缩写是什么。一个组织可以在结构化的框架内,通过均衡的组合来加强控制。
抵御供应商和企业风险
Learn about our best-in-class VRM/ERM solutions. Contact Us
主要收获
- IRM and GRC are complementary approaches; IRM emphasizes risk-aware decision making while GRC focuses on compliance and governance.
- Organizations do not need to abandon GRC—combining GRC with ERM achieves many IRM objectives.
- An integrated ERM-GRC solution provides a central hub for managing policies, compliance, and enterprise-wide risk.
- The right solution balances compliance requirements with strategic risk management within a structured framework.
