Does anyone have an estimate of what it takes to implement GRC?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎08-02-2016 06:48 AM
We're planning to implement GRC, and I'm looking for any information on best approach, level of effort required, etc.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎08-03-2016 01:56 PM
Hi Mark:
I would like to connect you with my colleague, Kevin Griggs, who gave the GRC talk at Knowledge '16 in Vegas this Spring. In addition, if you shoot me an email at Joel.Head@caskllc.com I will send you the GRC Ebook that we authored with ServiceNow.
Cask LLC is one of the top implementers of GRC per ServiceNow and Kevin and I are both located here in Atlanta. Please let me know if you'd like to set up a time to chat! We can meet in person or via phone.
Best,
Joel Head
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎08-03-2016 03:30 PM
Hi Mark,
Implementing the module itself is fairly easy in SN but like many things the overall answer is "it depends".
Which functionality are you looking to implement? Compliance Management, Risk Management, and/or Audit Management? What controls are you implementing and are you taking them out of the provided UFC or a framework your own organization provided?
Then the big question, have you prepared your organization to use the tool with the right process consulting up front, have you mapped controls (and those that have to execute them) to your control objectives, have you done the organizational change management effort to adopt, and the training to use the tool in a way that meets your organizations needs?
To answer your core question though from a technical only standpoint, standing up Audit Management (what most folks are generally referring to when they say GRC) for an insurance company last took us about 210 man hours including loading their control objectives and some (small sub-set) controls mapped to those objective in the system.
Hope that helps, if you want to talk feel free to reach out anytime.
Regards,
Kevin Griggs
404.354.4485