topleft
topright






Lost Password?
CIOZone Points Beta

Featured Member

CIOs Online Now
IBM offers insights and perspectives to help CIOs with the issues that matter most

Featured Groups

Newest Forum Posts

in CIO Conversations (Sponsored by IBM) by jrajani, 19-11-08 15:48
in CIO Conversations (Sponsored by IBM) by davidfcarr, 18-11-08 20:58
in Member Introductions by Bill Gerneglia, 17-11-08 20:32
Dr. Arthur M. Langer

Sponsored Links


Predict the future with HP Insight Power Manager


Affordable technology-no compromise. HP server solutions.
IBM offers insights and perspectives to help CIOs with the issues that matter most AMD Corporate Computing Zone - Business solutions that mean serious business Juniper Zone - Network Security - Network Infrastructure SugarCRM - CRM On-Demand or On-Site? A Decision Framework for Choosing the Right Deployment Benefits of HP Polyserve Software in SQL Server Environments
GRC Platforms: A CIO's Guide Print E-mail
Thursday, 24 July 2008

Also See:
6 GRC Platforms CIOs Should Know
Defining IT GRC
5 Measures To Minimize Risk


By Laton McCartney


The so-called Governance, Risk and Compliance market "is hard to size," says Michael Rasmussen, president of Corporate Integrity, a market research firm and advisory firm. That's because it encompasses everything from Sox compliance, enterprise risk management, environmental regulations, audit management, IT governance, operational risk management for business processes, market risk, credit and at least a dozen other categories.


"You could even add IT security and physical security into that mix," Rasmussen adds, noting that today corporations spend about $40 billion for the former and more than three times that for the latter.


Even without including the security categories, however, Governance, Risk and Compliance (GRC) is a market that's growing exponentially and is already generating some eye-popping numbers. AMR Research, for instance, projects companies will spend in excess of $35 billion in GRC solutions and services in 2008, a 7 % increase over 2007.


advertisement

Rasmussen puts the figure as high as $52.1 billion in 2008—$10 billion in software and the remainder in GRC professional services and GRC content/information providers.


The GRC market jump-started with the passage of Sarbanes-Oxley (SOX) and in particular the need to deal with Section 404 of SOX—the requirement for companies to check the effectiveness of internal controls and procedures for financial reporting. It went into high gear—at least the risk portion of it—in the wake of the mortgage crisis, which exposed the failure of many existing risk management systems in the financial sector. Now, in anticipation of new fiscal regulations that are likely to result from the almost unimaginable mortgage and banking failures plus other factors such as the growth of corporate social responsibility and what Rasmussen terms "an increasing risk profile in a distributed world," the GRC business will continue to boom.


AMR, in fact, pegs 2009 growth at 7% as companies shift their focus from compliance to better operational and financial risk management.

To date, most of the GRC vendors have come out with solutions aimed at specific segments of the overall GRC market such as financial controls, IT governance, policy enforcement and data privacy. More recently some of the major players in the market are rolling out GRC platforms or, as Rasmussen defines them, GRC infrastructures, that can host all kinds of targeted GRC applications while eliminating the more targeted approach to GRC that is prevalent today.


These platforms allow companies to collaborate across GRC silos, provide them with an enterprise view of risk and compliance and enables the various factions—finance, audit, IT—involved with GRC to work together.

Who's offering such products?


Here's a list of the vendors that are currently providing enterprise GRC platforms.




Be first to comment this article
RSS comments

Write Comment
  • Please keep the topic of messages relevant to the subject of the article.
Name:
E-mail
Comment:

Code:* Code
I wish to be contacted by email regarding additional comments

 
< Prev   Next >





A CIO discussion forum around business and technology topics that matter most to CIOs today.

CIOZone Poll

What do CIOs really want for the Holidays?
 

CIOZone White Paper Library

Acronis

Riverbed

RSA

Tripwire

Vendor Blogs

Must Watch Videos

CIOZone Select Video Center

News & Noteworthy Archive

Past News Items From Reuters