SlideShare a Scribd company logo
1 of 23
Download to read offline
Separated at Birth –
EA and GRC

January 31, 2013
Speaking today




                   David Baker                                   Colin Tong
     Principal, PwC Advisory                        Manager, PwC Advisory
     Enterprise Architecture Center of Excellence   Information Risk Management
     PricewaterhouseCoopers LLP                     PricewaterhouseCoopers LLP

     david.c.baker@us.pwc.com                       colin.d.tong@us.pwc.com
     +1.512.554.9035 (mobile)                       +1.415.412.9723


                                                                                  01/31/2013
© 2013 PricewaterhouseCoopers LLP                                                          2
Learning objectives



•  Understand key complexities facing the implementation of
   governance, risk, and compliance (GRC) solutions

•  See the similarities in how Enterprise Architecture (EA) and GRC
   consider the enterprise

•  Learn about EA techniques that may reduce the complexity
   sometimes associated with GRC

•  Understand how enterprise architecture models can support GRC
   activities

•  Learn the roles that EA and GRC play together in breaking down
   GRC silos



                                                              01/31/2013
© 2013 PricewaterhouseCoopers LLP                                      3
Companies continue to face increasing change combined
      with increasing need for oversight and transparency

     Increasing stakeholder
           demands                        Share-                  The               Comm-           Industry
                                                                                                                            Others
                                          holder                 Board               unity         Regulators
               +

   Expansion of Risk and
                                   IT              Legal         Finance       Risk Mgmt        Compliance            Internal Audit
 Control Oversight Functions




               +

     Expanding Risks, Laws
                                   SOX        Anti-Fraud   Privacy       AML   Credit    FCPA    BCP      Info Sec.    Op Risk       FSG
        and Regulations

               =
•  Business Fatigue
•  Lack of coordination
•  Duplicate efforts
•  Risks falling through
   the cracks
•  Competition for attention                                                   Business Unit

                                                                                                                           01/31/2013
      © 2013 PricewaterhouseCoopers LLP                                                                                             4
The current governance, risk and compliance (GRC)
environment faces many complications

1.  The multifaceted risk environment presents multiple, fragmented views of
    risk management

2.  GRC work tends to be performed in silos such as IT, Legal, Operations,
    Finance

3.  Compliance involves enterprise alignment and control to stay within
    mandated and voluntary boundaries

4.  Compliance is often based on checklists of requirements




Adapted from “Foundations of GRC: Establishing an Enterprise View of Risk & Compliance, Michael Rasmussen, 2009
                                                                                                                  01/31/2013
© 2013 PricewaterhouseCoopers LLP                                                                                          5
Poll Question


                                         01/31/2013
© 2013 PricewaterhouseCoopers LLP                 6
The solutions to these complications all involve use of a
      holistic enterprise operating model
                                                                                                                                                                          v
                                                                                         CORPORATE STRATEGY                                                                       2. Holistic view of
1. Link enterprise                                                                                                                                                                  how the
  risk                                          Ambition                                          Business Model                                  Strategic Agenda
                                                                                                                                                                                    enterprise
  management to
  enterprise
                     u                                                                       Strategic Foundation
                                                                                                                                                                                    operates with

  performance
  management
                                                                                                                        w                                                          integrated GRC
                                                                                                                                                                                    capabilities
                                                                                         CUSTOMER OFFERING


                                                           Products, Services                                                             Alliance
                                  Customers                                                Channels           Intermediaries                                         Brands
                                                              & Solutions                                                                 Partners
3. Use the
  enterprise view                                                                        BUSINESS CAPABILITIES
  to help the
                                PROCESS                                                                  ORGANISATION
  organization                                                                                                                                                                    4. GRC should be
                                       Processes                              Policies
  meet strategic                                                                                             Organisation
                                                                                                              Structure
                                                                                                                                          Roles &
                                                                                                                                       Accountabilities
                                                                                                                                                                    Physical
                                                                                                                                                                   Environment      managed by
  plans and                     TECHNOLOGY                                                                                                                                          specific
  objectives while                Application              Integration           Infrastructure
                                                                                                              Networks &
                                                                                                          Interdependencies
                                                                                                                                         Governance
                                                                                                                                        Arrangements
                                                                                                                                                                    Suppliers
                                                                                                                                                                                    outcomes
  staying within                                                                                                                                                                    (principled
                                INFORMATION                                                              PEOPLE CAPABILITIES
  mandatory and                    Reports &                                                                                       Workforce                          Culture &     performance)
  voluntary                        Analytics
                                                           Semantics                 Data                 Competencies
                                                                                                                                    & Talent
                                                                                                                                                     Reward
                                                                                                                                                                     Behaviours
                                                                                                                                                                                    rather than
  boundaries                                                                                                                                                                        checklists.
                                                                                         CORPORATE STRUCTURE


                                    Tax Structure &                      Legal & Regulatory                                                                Cash, Banking &
                                                                                                                   Capital Structure
                                     Arrangements                            Structure                                                                    Treasury Structure


                                                                                         ENTERPRISE PERFORMANCE
                                                                                         MANAGEMENT METRICS
                                                                                                                                                              x
                                                            PwC’s Operating Model Framework
                                                                                                                                                                                       01/31/2013
      © 2013 PricewaterhouseCoopers LLP                                                                                                                                                         7
That same holistic enterprise operating model has also been
the holy grail of the Enterprise Architecture (EA) discipline


                   Business                                                   Managers
              wants to know                    CORPORATE STRATEGY
                                                                              want to know


    How can I innovate?                        CUSTOMER OFFERING            Is my portfolio of activities aligned
  How quickly can I get it?                                                         with the strategy?
How much does it cost / save?
                                               BUSINESS CAPABILITIES            Have we done this before?
    What are the risks?                                                           How do we get it done?
                                               CORPORATE STRUCTURE
     What’s possible?                                                            How do I make sure it’s
                                               ENTERPRISE PERFORMANCE                done correctly?
                                               MANAGEMENT METRICS
                                                                                    What’s possible?
                                                                                Am I meeting expectations
                                                                                      efficiently?
                                            Staff                                What risks am I taking?
                                        wants to know

                                             What do I change?
                                           What do I build it with?
                                            When do I change it?
                                     How well am I aligning with our EA?
                                    What things should I NOT be changing?
                                                                                                    01/31/2013
© 2013 PricewaterhouseCoopers LLP                                                                            8
Like twins separated at birth, GRC and EA work toward the
same outcomes


                                                                                                             PWC EA CAPABILITY MODEL

                                                                                                                          Strategic
                                                                                                                          Planning



                                                                                                         Portfolio                       Architecture
                                                                                                          Mgmt                           Governance



                                                                                                        Reference
                                                                                                       Architecture                      Innovation




                                                                                                                          Standards
                                                                                                                          Definition




         Let’s return to the GRC complications and see how to apply EA
                                solutions to each

Includes material copied from or derived from the OCEG Red Book GRC Capability Model, Version 2.1, page 3, http://www.oceg.org/RedBook
                                                                                                                                          01/31/2013
© 2013 PricewaterhouseCoopers LLP                                                                                                                  9
u Issue: The multifaceted risk environment presents
 multiple, fragmented views of risk management

Departments or functions that serve on the compliance committee




 Source: PwC State of Compliance: 2012 Study, June 2012
                                                                  01/31/2013
 © 2013 PricewaterhouseCoopers LLP                                        10
u EA Answer: Link enterprise risk management to corporate
performance management

                                                                      •  Understand the factors that motivate the
             Internal & External Drivers
                                                                         business
                          Makes
                         operative
      Vision                               Mission                    •  Extract and drive additional detail into
    Statement                             Statement
                                                                         elements of the business model

             Amplifies         A component
                                    of                                •  Clearly articulate the Ambition – things that
                        Channels
                                                                         the business wishes to achieve
                         Effort
       Goals
                                                                      •  Clearly articulate the decisions – things that
                                                                         the business will employ to achieve the
             Quantifies                    Strategies                    Ambition
                        Channels
     Objectives          Effort
     & Metrics                                                           In this way, the business model becomes
                                                                           a common foundation for identifying
     Ambition                          Business Model
                                                                                 risks to the business intent
                                         Decisions

Some terms and relationships adapted from the Object Management Group’s Business Motivation Model, Release 1.3
                                                                                                                 01/31/2013
© 2013 PricewaterhouseCoopers LLP                                                                                        11
v Issue: GRC work tends to be performed in silos such as IT,
Legal, Operations, Finance

GRC functions sharing a common GRC-specific tool, technology or platform with
                             other functions




Source: PwC State of Compliance: 2012 Study, June 2012
                                                                       01/31/2013
© 2013 PricewaterhouseCoopers LLP                                              12
v EA Answer: Holistic view of how the enterprise operates
with integrated GRC capabilities

 Corporate Ambition                               Business Model                                             Enterprise Operating
                                                                                                                    Model
           Goals                                                                                                             CORPORATE STRATEGY



                                                             Strategies                                                      CUSTOMER OFFERING

                                                                                                                             BUSINESS CAPABILITIES
        Objectives &
          Metrics                                                                                                            CORPORATE STRUCTURE

                                                                                                                             ENTERPRISE PERFORMANCE
                                                                                                                             MANAGEMENT METRICS




                                                                                                         Business                    Operating
                                                                              Ambition
                                                                                                          Model                       Model
                                                                               Impact
Desired GRC Capabilities                                                                                  Impact                      Impact
                                                 Organize                      Impact A                  Impact B                     Impact C

                                                 Assess                        Impact D                   Impact E                     Impact F

                                                 Proact                        Impact G                  Impact H                      Impact I

                                                 Detect                        Impact J                  Impact K                      Impact L

                                                 Respond                       Impact M                  Impact N                     Impact O

                                                 Measure                       Impact P                  Impact Q                     Impact R

                                     Includes material copied from or derived from the OCEG Red Book GRC Capability Model,                   01/31/2013
 © 2013 PricewaterhouseCoopers LLP   Version 2.1, page 3, http://www.oceg.org/RedBook                                                                13
Poll Question


                                         01/31/2013
© 2013 PricewaterhouseCoopers LLP                14
w Issue: Compliance involves enterprise alignment and
control to stay within mandated and voluntary boundaries




Includes material copied from or derived from “Making the Business Case: Integrating Governance, Risk and Compliance to Drive Principled Performance”,
page 6, http://www.oceg.org/view/IllusBigPictureBusinessCase
                                                                                                                                                         01/31/2013
© 2013 PricewaterhouseCoopers LLP                                                                                                                                15
w EA Answer: Use the enterprise view to help the
organization meet strategic plans and objectives while
staying within mandatory and voluntary boundaries


                                      •    Strategic Roadmaps: Modernization plans
                                           for business areas. Typically 3-5 year view.


                                      •    Reference Architectures: reusable patterns
                                           for technical and operations solutions


                                      •    Guiding Principles: statements used as filters
                                           for decision making


                                      •    Standards: a library of stable technologies
                                           and processes for consistency


Image courtesy of Wikimedia Commons
                                                                                   01/31/2013
© 2013 PricewaterhouseCoopers LLP                                                          16
x Issue: Compliance is often based on checklists of
   requirements

                                 Checklists are like looking in a rearview mirror




  How do you                                      q  Do A
   ensure the                                                                       Have you asked
 checklists are                                   q Check B                          all the right
   complete,                                                                          questions?
accurate, and up
                                                  q Redo C
    to date?                                      q Do D



                               Checklists can lead to a false sense of security

   Image courtesy of Wikimedia Commons
                                                                                          01/31/2013
   © 2013 PricewaterhouseCoopers LLP                                                              17
x EA Answer: GRC should be managed by specific outcomes
(principled performance) rather than checklists

                               Principled Performance
“Reliable achievement of objectives while addressing uncertainty and acting with integrity”




   Current                                                                                                                                       Target
    State                                                                                                                                         State
  Operating                                                                                                                                     Operating
    Model                                                                                                                                        Model



                    The EA constitution, in combination with an EA roadmap, enable the
                     EA governance process to assist you in getting where you are going,
                      while maintaining alignment with corporate goals and objectives
Includes material copied from or derived from “Increase Principled Performance and Reduce the Cost (and Hassle) of Risk Management and Compliance”, http://www.oceg.org/event/
increase-principled-performance-and-reduce-cost-and-hassle-risk-management-and-compliance

Image courtesy of Stock.xchng
                                                                                                                                                             01/31/2013
© 2013 PricewaterhouseCoopers LLP                                                                                                                                    18
Poll Question


                                         01/31/2013
© 2013 PricewaterhouseCoopers LLP                19
We’ve discussed 4 EA techniques that can help implement
your GRC program

Unify your multifaceted GRC environment by linking your risk and
compliance measures to the corporate strategy. (EA modeling)
Bridge your GRC silos by designing a common set of GRC
capabilities and assess the impact by using a holistic operating
model of your enterprise. (GRC capability mapping and impact
analysis)
Help your efforts stay within voluntary and mandatory boundaries
by creating an EA constitution (strategic planning, reference
architectures, standards and guiding principles)
Avoid the pitfalls associated with management by checklist by
leveraging the EA constitution (EA governance)




                                                                   01/31/2013
© 2013 PricewaterhouseCoopers LLP                                          20
Thank you




© 2013 PwC. All rights reserved. PwC refers to the PwC network and/or one or more of its
member firms, each of which is a separate legal entity. Please see www.pwc.com/structure for
further details. This content is for general information purposes only, and should not be used as
a substitute for consultation with professional advisors. PwC helps organizations and individuals
create the value they’re looking for. We’re a network of firms in 158 countries with more than
180,000 people who are committed to delivering quality in assurance, tax and advisory
services. Tell us what matters to you and find out more by visiting us at www.pwc.com.

Includes material copied from or derived from OCEG at http://www.oceg.org
Questions?
Separated at Birth: EA and GRC                  ...to be
                                                          continu
                                                      in Part      ed
                                         Putting               II
                                                  GRC A
                                            method         rchitec
                                                     s into p       ture
                                                              ractice



         MEGA is revolutionizing the approach to
                              operational governance

          Imagine your business united...


          Imagine your business




            www.mega.com - @mega_int -

More Related Content

What's hot

IT Governance - Governing IT: Do or Die?
IT Governance - Governing IT: Do or Die?IT Governance - Governing IT: Do or Die?
IT Governance - Governing IT: Do or Die?Eryk Budi Pratama
 
IT Strategy & Planning
IT Strategy & PlanningIT Strategy & Planning
IT Strategy & Planningchakraj
 
Data Governance
Data GovernanceData Governance
Data GovernanceRob Lux
 
Data Management, Metadata Management, and Data Governance – Working Together
Data Management, Metadata Management, and Data Governance – Working TogetherData Management, Metadata Management, and Data Governance – Working Together
Data Management, Metadata Management, and Data Governance – Working TogetherDATAVERSITY
 
Digital Operating Model & IT4IT
Digital Operating Model & IT4ITDigital Operating Model & IT4IT
Digital Operating Model & IT4ITDavid Favelle
 
Enterprise Data Architecture Deliverables
Enterprise Data Architecture DeliverablesEnterprise Data Architecture Deliverables
Enterprise Data Architecture DeliverablesLars E Martinsson
 
An Introduction into the design of business using business architecture
An Introduction into the design of business using business architectureAn Introduction into the design of business using business architecture
An Introduction into the design of business using business architectureCraig Martin
 
IT4IT - The Full Story for Digital Transformation - Part 1
IT4IT - The Full Story for Digital Transformation - Part 1IT4IT - The Full Story for Digital Transformation - Part 1
IT4IT - The Full Story for Digital Transformation - Part 1Mohamed Zakarya Abdelgawad
 
DMBOK 2.0 and other frameworks including TOGAF & COBIT - keynote from DAMA Au...
DMBOK 2.0 and other frameworks including TOGAF & COBIT - keynote from DAMA Au...DMBOK 2.0 and other frameworks including TOGAF & COBIT - keynote from DAMA Au...
DMBOK 2.0 and other frameworks including TOGAF & COBIT - keynote from DAMA Au...Christopher Bradley
 
Digital Transformation And Solution Architecture
Digital Transformation And Solution ArchitectureDigital Transformation And Solution Architecture
Digital Transformation And Solution ArchitectureAlan McSweeney
 
Enterprise Cybersecurity: From Strategy to Operating Model
Enterprise Cybersecurity: From Strategy to Operating ModelEnterprise Cybersecurity: From Strategy to Operating Model
Enterprise Cybersecurity: From Strategy to Operating ModelEryk Budi Pratama
 
Lecture about "Enterprise Architecture @ ING" given at Solvay Brussels School...
Lecture about "Enterprise Architecture @ ING" given at Solvay Brussels School...Lecture about "Enterprise Architecture @ ING" given at Solvay Brussels School...
Lecture about "Enterprise Architecture @ ING" given at Solvay Brussels School...Alain Heremans
 
Data strategy in a Big Data world
Data strategy in a Big Data worldData strategy in a Big Data world
Data strategy in a Big Data worldCraig Milroy
 
Transform Data to Insight
Transform Data to InsightTransform Data to Insight
Transform Data to InsightWorkday, Inc.
 
Review of Data Management Maturity Models
Review of Data Management Maturity ModelsReview of Data Management Maturity Models
Review of Data Management Maturity ModelsAlan McSweeney
 
Data Governance Program Powerpoint Presentation Slides
Data Governance Program Powerpoint Presentation SlidesData Governance Program Powerpoint Presentation Slides
Data Governance Program Powerpoint Presentation SlidesSlideTeam
 
Digital Transformation Strategy and Plan Template
Digital Transformation Strategy and Plan TemplateDigital Transformation Strategy and Plan Template
Digital Transformation Strategy and Plan TemplateAurelien Domont, MBA
 

What's hot (20)

IT Governance - Governing IT: Do or Die?
IT Governance - Governing IT: Do or Die?IT Governance - Governing IT: Do or Die?
IT Governance - Governing IT: Do or Die?
 
Optimize the IT Operating Model
Optimize the IT Operating ModelOptimize the IT Operating Model
Optimize the IT Operating Model
 
IT Strategy & Planning
IT Strategy & PlanningIT Strategy & Planning
IT Strategy & Planning
 
Data Governance
Data GovernanceData Governance
Data Governance
 
Data Management, Metadata Management, and Data Governance – Working Together
Data Management, Metadata Management, and Data Governance – Working TogetherData Management, Metadata Management, and Data Governance – Working Together
Data Management, Metadata Management, and Data Governance – Working Together
 
Digital Operating Model & IT4IT
Digital Operating Model & IT4ITDigital Operating Model & IT4IT
Digital Operating Model & IT4IT
 
Enterprise Data Architecture Deliverables
Enterprise Data Architecture DeliverablesEnterprise Data Architecture Deliverables
Enterprise Data Architecture Deliverables
 
IT Strategy
IT StrategyIT Strategy
IT Strategy
 
An Introduction into the design of business using business architecture
An Introduction into the design of business using business architectureAn Introduction into the design of business using business architecture
An Introduction into the design of business using business architecture
 
IT4IT - The Full Story for Digital Transformation - Part 1
IT4IT - The Full Story for Digital Transformation - Part 1IT4IT - The Full Story for Digital Transformation - Part 1
IT4IT - The Full Story for Digital Transformation - Part 1
 
DMBOK 2.0 and other frameworks including TOGAF & COBIT - keynote from DAMA Au...
DMBOK 2.0 and other frameworks including TOGAF & COBIT - keynote from DAMA Au...DMBOK 2.0 and other frameworks including TOGAF & COBIT - keynote from DAMA Au...
DMBOK 2.0 and other frameworks including TOGAF & COBIT - keynote from DAMA Au...
 
Digital Transformation And Solution Architecture
Digital Transformation And Solution ArchitectureDigital Transformation And Solution Architecture
Digital Transformation And Solution Architecture
 
Enterprise Cybersecurity: From Strategy to Operating Model
Enterprise Cybersecurity: From Strategy to Operating ModelEnterprise Cybersecurity: From Strategy to Operating Model
Enterprise Cybersecurity: From Strategy to Operating Model
 
Lecture about "Enterprise Architecture @ ING" given at Solvay Brussels School...
Lecture about "Enterprise Architecture @ ING" given at Solvay Brussels School...Lecture about "Enterprise Architecture @ ING" given at Solvay Brussels School...
Lecture about "Enterprise Architecture @ ING" given at Solvay Brussels School...
 
Data strategy in a Big Data world
Data strategy in a Big Data worldData strategy in a Big Data world
Data strategy in a Big Data world
 
Strategic Operating Model
Strategic Operating Model Strategic Operating Model
Strategic Operating Model
 
Transform Data to Insight
Transform Data to InsightTransform Data to Insight
Transform Data to Insight
 
Review of Data Management Maturity Models
Review of Data Management Maturity ModelsReview of Data Management Maturity Models
Review of Data Management Maturity Models
 
Data Governance Program Powerpoint Presentation Slides
Data Governance Program Powerpoint Presentation SlidesData Governance Program Powerpoint Presentation Slides
Data Governance Program Powerpoint Presentation Slides
 
Digital Transformation Strategy and Plan Template
Digital Transformation Strategy and Plan TemplateDigital Transformation Strategy and Plan Template
Digital Transformation Strategy and Plan Template
 

Viewers also liked

Business Driven Architecture for Strategic Transformation
Business Driven Architecture for Strategic TransformationBusiness Driven Architecture for Strategic Transformation
Business Driven Architecture for Strategic TransformationDavid Baker
 
Strategic Architecture
Strategic ArchitectureStrategic Architecture
Strategic ArchitectureDavid Baker
 
Strategic architecture
Strategic architectureStrategic architecture
Strategic architectureBas van Gils
 
Getting Some Respect - How to Measure and Communicate Your EA Success
Getting Some Respect - How to Measure and Communicate Your EA SuccessGetting Some Respect - How to Measure and Communicate Your EA Success
Getting Some Respect - How to Measure and Communicate Your EA SuccessDavid Baker
 
Maximizing EA Impact: Using Business Architecture to Achieve Alignment
Maximizing EA Impact: Using Business Architecture to Achieve AlignmentMaximizing EA Impact: Using Business Architecture to Achieve Alignment
Maximizing EA Impact: Using Business Architecture to Achieve AlignmentDavid Baker
 
20120717 baker boundaries for business architecture v3
20120717 baker   boundaries for business architecture v320120717 baker   boundaries for business architecture v3
20120717 baker boundaries for business architecture v3David Baker
 
Operating Model
Operating ModelOperating Model
Operating Modelrmuse70
 
2017 Top Issues - Financial Reporting Modernization - January 2017
2017 Top Issues - Financial Reporting Modernization - January 20172017 Top Issues - Financial Reporting Modernization - January 2017
2017 Top Issues - Financial Reporting Modernization - January 2017PwC
 
PwC Career Boosting Game - Romania
PwC Career Boosting Game - RomaniaPwC Career Boosting Game - Romania
PwC Career Boosting Game - RomaniaPwC_Recruitment
 
IAB Internet Advertising Revenue report 2014 - April 2015
IAB Internet Advertising Revenue report 2014 - April 2015IAB Internet Advertising Revenue report 2014 - April 2015
IAB Internet Advertising Revenue report 2014 - April 2015Margarita Zlatkova
 
Webinar slide-deck-enterprise-architecture-capability-assessments
Webinar slide-deck-enterprise-architecture-capability-assessmentsWebinar slide-deck-enterprise-architecture-capability-assessments
Webinar slide-deck-enterprise-architecture-capability-assessmentsBiZZdesign
 
7 Essential Elements Of EA
7 Essential Elements Of EA7 Essential Elements Of EA
7 Essential Elements Of EADavid Baker
 
PwC Challenge Case Competition 2015
PwC Challenge Case Competition 2015 PwC Challenge Case Competition 2015
PwC Challenge Case Competition 2015 Caleb Kwok
 
Case Presentation for PricewaterhouseCoopers
Case Presentation for PricewaterhouseCoopersCase Presentation for PricewaterhouseCoopers
Case Presentation for PricewaterhouseCoopersImaan Virani
 
Earned value management
Earned value managementEarned value management
Earned value managementAshif AR
 
Webinar: Driving Innovation Across an Enterprise with Booz Allen Hamilton
Webinar: Driving Innovation Across an Enterprise with Booz Allen HamiltonWebinar: Driving Innovation Across an Enterprise with Booz Allen Hamilton
Webinar: Driving Innovation Across an Enterprise with Booz Allen HamiltonBadgeville, Inc.
 
Introduction to Project Portfolio Management (PPM)
Introduction to Project Portfolio Management (PPM)Introduction to Project Portfolio Management (PPM)
Introduction to Project Portfolio Management (PPM)Kimmy Chen
 

Viewers also liked (20)

Business Driven Architecture for Strategic Transformation
Business Driven Architecture for Strategic TransformationBusiness Driven Architecture for Strategic Transformation
Business Driven Architecture for Strategic Transformation
 
Strategic Architecture
Strategic ArchitectureStrategic Architecture
Strategic Architecture
 
Strategic architecture
Strategic architectureStrategic architecture
Strategic architecture
 
Getting Some Respect - How to Measure and Communicate Your EA Success
Getting Some Respect - How to Measure and Communicate Your EA SuccessGetting Some Respect - How to Measure and Communicate Your EA Success
Getting Some Respect - How to Measure and Communicate Your EA Success
 
Maximizing EA Impact: Using Business Architecture to Achieve Alignment
Maximizing EA Impact: Using Business Architecture to Achieve AlignmentMaximizing EA Impact: Using Business Architecture to Achieve Alignment
Maximizing EA Impact: Using Business Architecture to Achieve Alignment
 
It Finance
It FinanceIt Finance
It Finance
 
20120717 baker boundaries for business architecture v3
20120717 baker   boundaries for business architecture v320120717 baker   boundaries for business architecture v3
20120717 baker boundaries for business architecture v3
 
Operating Model
Operating ModelOperating Model
Operating Model
 
2017 Top Issues - Financial Reporting Modernization - January 2017
2017 Top Issues - Financial Reporting Modernization - January 20172017 Top Issues - Financial Reporting Modernization - January 2017
2017 Top Issues - Financial Reporting Modernization - January 2017
 
PwC Pre-Budget 2012 Presentation
PwC Pre-Budget 2012 PresentationPwC Pre-Budget 2012 Presentation
PwC Pre-Budget 2012 Presentation
 
PwC Career Boosting Game - Romania
PwC Career Boosting Game - RomaniaPwC Career Boosting Game - Romania
PwC Career Boosting Game - Romania
 
IAB Internet Advertising Revenue report 2014 - April 2015
IAB Internet Advertising Revenue report 2014 - April 2015IAB Internet Advertising Revenue report 2014 - April 2015
IAB Internet Advertising Revenue report 2014 - April 2015
 
Portfolio management
Portfolio managementPortfolio management
Portfolio management
 
Webinar slide-deck-enterprise-architecture-capability-assessments
Webinar slide-deck-enterprise-architecture-capability-assessmentsWebinar slide-deck-enterprise-architecture-capability-assessments
Webinar slide-deck-enterprise-architecture-capability-assessments
 
7 Essential Elements Of EA
7 Essential Elements Of EA7 Essential Elements Of EA
7 Essential Elements Of EA
 
PwC Challenge Case Competition 2015
PwC Challenge Case Competition 2015 PwC Challenge Case Competition 2015
PwC Challenge Case Competition 2015
 
Case Presentation for PricewaterhouseCoopers
Case Presentation for PricewaterhouseCoopersCase Presentation for PricewaterhouseCoopers
Case Presentation for PricewaterhouseCoopers
 
Earned value management
Earned value managementEarned value management
Earned value management
 
Webinar: Driving Innovation Across an Enterprise with Booz Allen Hamilton
Webinar: Driving Innovation Across an Enterprise with Booz Allen HamiltonWebinar: Driving Innovation Across an Enterprise with Booz Allen Hamilton
Webinar: Driving Innovation Across an Enterprise with Booz Allen Hamilton
 
Introduction to Project Portfolio Management (PPM)
Introduction to Project Portfolio Management (PPM)Introduction to Project Portfolio Management (PPM)
Introduction to Project Portfolio Management (PPM)
 

Similar to MEGA Webinar - PwC - Baker/Tong - EA & GRC, Separated at Birth

Guerin Associates Nov 2011
Guerin Associates   Nov 2011Guerin Associates   Nov 2011
Guerin Associates Nov 2011michaelguerin
 
Guerin Associates 2011
Guerin Associates 2011Guerin Associates 2011
Guerin Associates 2011michaelguerin
 
Increasing Business Agility: An Integrated Approach to Governance, Risk, and ...
Increasing Business Agility: An Integrated Approach to Governance, Risk, and ...Increasing Business Agility: An Integrated Approach to Governance, Risk, and ...
Increasing Business Agility: An Integrated Approach to Governance, Risk, and ...FindWhitePapers
 
Development impacts presentation for 2013 AOG conference
Development impacts presentation for 2013 AOG conferenceDevelopment impacts presentation for 2013 AOG conference
Development impacts presentation for 2013 AOG conferenceDevImp3
 
WGA Services Overview
WGA Services OverviewWGA Services Overview
WGA Services OverviewWGAOCM
 
IDC Energy Insights - Enterprise Risk Management
IDC Energy Insights - Enterprise Risk ManagementIDC Energy Insights - Enterprise Risk Management
IDC Energy Insights - Enterprise Risk ManagementFindWhitePapers
 
pManifold Introduction to Consulting Practice
pManifold Introduction to Consulting PracticepManifold Introduction to Consulting Practice
pManifold Introduction to Consulting PracticepManifold
 
Enterprise Governance: The Impact of Enterprise Governance on Effective Proje...
Enterprise Governance: The Impact of Enterprise Governance on Effective Proje...Enterprise Governance: The Impact of Enterprise Governance on Effective Proje...
Enterprise Governance: The Impact of Enterprise Governance on Effective Proje...Zulkefle Idris
 
E&C Industry Review By Scott Boutwell Jan09
E&C Industry Review By Scott Boutwell Jan09E&C Industry Review By Scott Boutwell Jan09
E&C Industry Review By Scott Boutwell Jan09Scott Boutwell, LEED AP
 
Integrated Alliance Management Primer
Integrated Alliance Management PrimerIntegrated Alliance Management Primer
Integrated Alliance Management PrimerTimothy Roe
 
Internal audit requirement
Internal audit requirementInternal audit requirement
Internal audit requirementabhijitsingh007
 
Partner marketing 22 march
Partner marketing 22 marchPartner marketing 22 march
Partner marketing 22 marchRob Bartlett
 
Partner marketing 22 march
Partner marketing 22 marchPartner marketing 22 march
Partner marketing 22 marchRob Bartlett
 
PCI IT Conference 2009
PCI IT Conference 2009PCI IT Conference 2009
PCI IT Conference 2009guest43efa2
 
E business strategy
E business strategyE business strategy
E business strategydhasan77
 

Similar to MEGA Webinar - PwC - Baker/Tong - EA & GRC, Separated at Birth (20)

Guerin Associates Nov 2011
Guerin Associates   Nov 2011Guerin Associates   Nov 2011
Guerin Associates Nov 2011
 
Guerin Associates 2011
Guerin Associates 2011Guerin Associates 2011
Guerin Associates 2011
 
Increasing Business Agility: An Integrated Approach to Governance, Risk, and ...
Increasing Business Agility: An Integrated Approach to Governance, Risk, and ...Increasing Business Agility: An Integrated Approach to Governance, Risk, and ...
Increasing Business Agility: An Integrated Approach to Governance, Risk, and ...
 
Development impacts presentation for 2013 AOG conference
Development impacts presentation for 2013 AOG conferenceDevelopment impacts presentation for 2013 AOG conference
Development impacts presentation for 2013 AOG conference
 
WGA Services Overview
WGA Services OverviewWGA Services Overview
WGA Services Overview
 
IDC Energy Insights - Enterprise Risk Management
IDC Energy Insights - Enterprise Risk ManagementIDC Energy Insights - Enterprise Risk Management
IDC Energy Insights - Enterprise Risk Management
 
pManifold Introduction to Consulting Practice
pManifold Introduction to Consulting PracticepManifold Introduction to Consulting Practice
pManifold Introduction to Consulting Practice
 
AdvisorAssist Compliance ROI
AdvisorAssist Compliance ROIAdvisorAssist Compliance ROI
AdvisorAssist Compliance ROI
 
Enterprise Governance: The Impact of Enterprise Governance on Effective Proje...
Enterprise Governance: The Impact of Enterprise Governance on Effective Proje...Enterprise Governance: The Impact of Enterprise Governance on Effective Proje...
Enterprise Governance: The Impact of Enterprise Governance on Effective Proje...
 
E&C Industry Review By Scott Boutwell Jan09
E&C Industry Review By Scott Boutwell Jan09E&C Industry Review By Scott Boutwell Jan09
E&C Industry Review By Scott Boutwell Jan09
 
UNGC Kyiv
UNGC KyivUNGC Kyiv
UNGC Kyiv
 
Integrated Alliance Management Primer
Integrated Alliance Management PrimerIntegrated Alliance Management Primer
Integrated Alliance Management Primer
 
Strategic Enterprise Management
Strategic Enterprise ManagementStrategic Enterprise Management
Strategic Enterprise Management
 
Internal audit requirement
Internal audit requirementInternal audit requirement
Internal audit requirement
 
Partner marketing 22 march
Partner marketing 22 marchPartner marketing 22 march
Partner marketing 22 march
 
Partner marketing 22 march
Partner marketing 22 marchPartner marketing 22 march
Partner marketing 22 march
 
PCI IT Conference 2009
PCI IT Conference 2009PCI IT Conference 2009
PCI IT Conference 2009
 
PCI IT conference 2009
PCI IT conference 2009PCI IT conference 2009
PCI IT conference 2009
 
E business strategy
E business strategyE business strategy
E business strategy
 
Wilson Perumal & Company: Firm Introduction
Wilson Perumal & Company: Firm IntroductionWilson Perumal & Company: Firm Introduction
Wilson Perumal & Company: Firm Introduction
 

Recently uploaded

Falcon Invoice Discounting: Aviate Your Cash Flow Challenges
Falcon Invoice Discounting: Aviate Your Cash Flow ChallengesFalcon Invoice Discounting: Aviate Your Cash Flow Challenges
Falcon Invoice Discounting: Aviate Your Cash Flow Challengeshemanthkumar470700
 
Falcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to ProsperityFalcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to Prosperityhemanthkumar470700
 
Rice Manufacturers in India | Shree Krishna Exports
Rice Manufacturers in India | Shree Krishna ExportsRice Manufacturers in India | Shree Krishna Exports
Rice Manufacturers in India | Shree Krishna ExportsShree Krishna Exports
 
Organizational Transformation Lead with Culture
Organizational Transformation Lead with CultureOrganizational Transformation Lead with Culture
Organizational Transformation Lead with CultureSeta Wicaksana
 
joint cost.pptx COST ACCOUNTING Sixteenth Edition ...
joint cost.pptx  COST ACCOUNTING  Sixteenth Edition                          ...joint cost.pptx  COST ACCOUNTING  Sixteenth Edition                          ...
joint cost.pptx COST ACCOUNTING Sixteenth Edition ...NadhimTaha
 
Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024Marel
 
CROSS CULTURAL NEGOTIATION BY PANMISEM NS
CROSS CULTURAL NEGOTIATION BY PANMISEM NSCROSS CULTURAL NEGOTIATION BY PANMISEM NS
CROSS CULTURAL NEGOTIATION BY PANMISEM NSpanmisemningshen123
 
PHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation FinalPHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation FinalPanhandleOilandGas
 
Pre Engineered Building Manufacturers Hyderabad.pptx
Pre Engineered  Building Manufacturers Hyderabad.pptxPre Engineered  Building Manufacturers Hyderabad.pptx
Pre Engineered Building Manufacturers Hyderabad.pptxRoofing Contractor
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfAdmir Softic
 
Arti Languages Pre Seed Teaser Deck 2024.pdf
Arti Languages Pre Seed Teaser Deck 2024.pdfArti Languages Pre Seed Teaser Deck 2024.pdf
Arti Languages Pre Seed Teaser Deck 2024.pdfwill854175
 
Falcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon investment
 
Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...
Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...
Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...meghakumariji156
 
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwaitdaisycvs
 
Over the Top (OTT) Market Size & Growth Outlook 2024-2030
Over the Top (OTT) Market Size & Growth Outlook 2024-2030Over the Top (OTT) Market Size & Growth Outlook 2024-2030
Over the Top (OTT) Market Size & Growth Outlook 2024-2030tarushabhavsar
 
Putting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptxPutting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptxCynthia Clay
 
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 MonthsSEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 MonthsIndeedSEO
 
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...Falcon Invoice Discounting
 

Recently uploaded (20)

Falcon Invoice Discounting: Aviate Your Cash Flow Challenges
Falcon Invoice Discounting: Aviate Your Cash Flow ChallengesFalcon Invoice Discounting: Aviate Your Cash Flow Challenges
Falcon Invoice Discounting: Aviate Your Cash Flow Challenges
 
Falcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to ProsperityFalcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to Prosperity
 
Rice Manufacturers in India | Shree Krishna Exports
Rice Manufacturers in India | Shree Krishna ExportsRice Manufacturers in India | Shree Krishna Exports
Rice Manufacturers in India | Shree Krishna Exports
 
Organizational Transformation Lead with Culture
Organizational Transformation Lead with CultureOrganizational Transformation Lead with Culture
Organizational Transformation Lead with Culture
 
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pillsMifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
 
joint cost.pptx COST ACCOUNTING Sixteenth Edition ...
joint cost.pptx  COST ACCOUNTING  Sixteenth Edition                          ...joint cost.pptx  COST ACCOUNTING  Sixteenth Edition                          ...
joint cost.pptx COST ACCOUNTING Sixteenth Edition ...
 
Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024
 
CROSS CULTURAL NEGOTIATION BY PANMISEM NS
CROSS CULTURAL NEGOTIATION BY PANMISEM NSCROSS CULTURAL NEGOTIATION BY PANMISEM NS
CROSS CULTURAL NEGOTIATION BY PANMISEM NS
 
PHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation FinalPHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation Final
 
Pre Engineered Building Manufacturers Hyderabad.pptx
Pre Engineered  Building Manufacturers Hyderabad.pptxPre Engineered  Building Manufacturers Hyderabad.pptx
Pre Engineered Building Manufacturers Hyderabad.pptx
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
 
Arti Languages Pre Seed Teaser Deck 2024.pdf
Arti Languages Pre Seed Teaser Deck 2024.pdfArti Languages Pre Seed Teaser Deck 2024.pdf
Arti Languages Pre Seed Teaser Deck 2024.pdf
 
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
 
Falcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business Growth
 
Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...
Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...
Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...
 
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
 
Over the Top (OTT) Market Size & Growth Outlook 2024-2030
Over the Top (OTT) Market Size & Growth Outlook 2024-2030Over the Top (OTT) Market Size & Growth Outlook 2024-2030
Over the Top (OTT) Market Size & Growth Outlook 2024-2030
 
Putting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptxPutting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptx
 
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 MonthsSEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
 
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
 

MEGA Webinar - PwC - Baker/Tong - EA & GRC, Separated at Birth

  • 1. Separated at Birth – EA and GRC January 31, 2013
  • 2. Speaking today David Baker Colin Tong Principal, PwC Advisory Manager, PwC Advisory Enterprise Architecture Center of Excellence Information Risk Management PricewaterhouseCoopers LLP PricewaterhouseCoopers LLP david.c.baker@us.pwc.com colin.d.tong@us.pwc.com +1.512.554.9035 (mobile) +1.415.412.9723 01/31/2013 © 2013 PricewaterhouseCoopers LLP 2
  • 3. Learning objectives •  Understand key complexities facing the implementation of governance, risk, and compliance (GRC) solutions •  See the similarities in how Enterprise Architecture (EA) and GRC consider the enterprise •  Learn about EA techniques that may reduce the complexity sometimes associated with GRC •  Understand how enterprise architecture models can support GRC activities •  Learn the roles that EA and GRC play together in breaking down GRC silos 01/31/2013 © 2013 PricewaterhouseCoopers LLP 3
  • 4. Companies continue to face increasing change combined with increasing need for oversight and transparency Increasing stakeholder demands Share- The Comm- Industry Others holder Board unity Regulators + Expansion of Risk and IT Legal Finance Risk Mgmt Compliance Internal Audit Control Oversight Functions + Expanding Risks, Laws SOX Anti-Fraud Privacy AML Credit FCPA BCP Info Sec. Op Risk FSG and Regulations = •  Business Fatigue •  Lack of coordination •  Duplicate efforts •  Risks falling through the cracks •  Competition for attention Business Unit 01/31/2013 © 2013 PricewaterhouseCoopers LLP 4
  • 5. The current governance, risk and compliance (GRC) environment faces many complications 1.  The multifaceted risk environment presents multiple, fragmented views of risk management 2.  GRC work tends to be performed in silos such as IT, Legal, Operations, Finance 3.  Compliance involves enterprise alignment and control to stay within mandated and voluntary boundaries 4.  Compliance is often based on checklists of requirements Adapted from “Foundations of GRC: Establishing an Enterprise View of Risk & Compliance, Michael Rasmussen, 2009 01/31/2013 © 2013 PricewaterhouseCoopers LLP 5
  • 6. Poll Question 01/31/2013 © 2013 PricewaterhouseCoopers LLP 6
  • 7. The solutions to these complications all involve use of a holistic enterprise operating model v CORPORATE STRATEGY 2. Holistic view of 1. Link enterprise how the risk Ambition Business Model Strategic Agenda enterprise management to enterprise u Strategic Foundation operates with performance management w integrated GRC capabilities CUSTOMER OFFERING Products, Services Alliance Customers Channels Intermediaries Brands & Solutions Partners 3. Use the enterprise view BUSINESS CAPABILITIES to help the PROCESS ORGANISATION organization 4. GRC should be Processes Policies meet strategic Organisation Structure Roles & Accountabilities Physical Environment managed by plans and TECHNOLOGY specific objectives while Application Integration Infrastructure Networks & Interdependencies Governance Arrangements Suppliers outcomes staying within (principled INFORMATION PEOPLE CAPABILITIES mandatory and Reports & Workforce Culture & performance) voluntary Analytics Semantics Data Competencies & Talent Reward Behaviours rather than boundaries checklists. CORPORATE STRUCTURE Tax Structure & Legal & Regulatory Cash, Banking & Capital Structure Arrangements Structure Treasury Structure ENTERPRISE PERFORMANCE MANAGEMENT METRICS x PwC’s Operating Model Framework 01/31/2013 © 2013 PricewaterhouseCoopers LLP 7
  • 8. That same holistic enterprise operating model has also been the holy grail of the Enterprise Architecture (EA) discipline Business Managers wants to know CORPORATE STRATEGY want to know How can I innovate? CUSTOMER OFFERING Is my portfolio of activities aligned How quickly can I get it? with the strategy? How much does it cost / save? BUSINESS CAPABILITIES Have we done this before? What are the risks? How do we get it done? CORPORATE STRUCTURE What’s possible? How do I make sure it’s ENTERPRISE PERFORMANCE done correctly? MANAGEMENT METRICS What’s possible? Am I meeting expectations efficiently? Staff What risks am I taking? wants to know What do I change? What do I build it with? When do I change it? How well am I aligning with our EA? What things should I NOT be changing? 01/31/2013 © 2013 PricewaterhouseCoopers LLP 8
  • 9. Like twins separated at birth, GRC and EA work toward the same outcomes PWC EA CAPABILITY MODEL Strategic Planning Portfolio Architecture Mgmt Governance Reference Architecture Innovation Standards Definition Let’s return to the GRC complications and see how to apply EA solutions to each Includes material copied from or derived from the OCEG Red Book GRC Capability Model, Version 2.1, page 3, http://www.oceg.org/RedBook 01/31/2013 © 2013 PricewaterhouseCoopers LLP 9
  • 10. u Issue: The multifaceted risk environment presents multiple, fragmented views of risk management Departments or functions that serve on the compliance committee Source: PwC State of Compliance: 2012 Study, June 2012 01/31/2013 © 2013 PricewaterhouseCoopers LLP 10
  • 11. u EA Answer: Link enterprise risk management to corporate performance management •  Understand the factors that motivate the Internal & External Drivers business Makes operative Vision Mission •  Extract and drive additional detail into Statement Statement elements of the business model Amplifies A component of •  Clearly articulate the Ambition – things that Channels the business wishes to achieve Effort Goals •  Clearly articulate the decisions – things that the business will employ to achieve the Quantifies Strategies Ambition Channels Objectives Effort & Metrics In this way, the business model becomes a common foundation for identifying Ambition Business Model risks to the business intent Decisions Some terms and relationships adapted from the Object Management Group’s Business Motivation Model, Release 1.3 01/31/2013 © 2013 PricewaterhouseCoopers LLP 11
  • 12. v Issue: GRC work tends to be performed in silos such as IT, Legal, Operations, Finance GRC functions sharing a common GRC-specific tool, technology or platform with other functions Source: PwC State of Compliance: 2012 Study, June 2012 01/31/2013 © 2013 PricewaterhouseCoopers LLP 12
  • 13. v EA Answer: Holistic view of how the enterprise operates with integrated GRC capabilities Corporate Ambition Business Model Enterprise Operating Model Goals CORPORATE STRATEGY Strategies CUSTOMER OFFERING BUSINESS CAPABILITIES Objectives & Metrics CORPORATE STRUCTURE ENTERPRISE PERFORMANCE MANAGEMENT METRICS Business Operating Ambition Model Model Impact Desired GRC Capabilities Impact Impact Organize Impact A Impact B Impact C Assess Impact D Impact E Impact F Proact Impact G Impact H Impact I Detect Impact J Impact K Impact L Respond Impact M Impact N Impact O Measure Impact P Impact Q Impact R Includes material copied from or derived from the OCEG Red Book GRC Capability Model, 01/31/2013 © 2013 PricewaterhouseCoopers LLP Version 2.1, page 3, http://www.oceg.org/RedBook 13
  • 14. Poll Question 01/31/2013 © 2013 PricewaterhouseCoopers LLP 14
  • 15. w Issue: Compliance involves enterprise alignment and control to stay within mandated and voluntary boundaries Includes material copied from or derived from “Making the Business Case: Integrating Governance, Risk and Compliance to Drive Principled Performance”, page 6, http://www.oceg.org/view/IllusBigPictureBusinessCase 01/31/2013 © 2013 PricewaterhouseCoopers LLP 15
  • 16. w EA Answer: Use the enterprise view to help the organization meet strategic plans and objectives while staying within mandatory and voluntary boundaries •  Strategic Roadmaps: Modernization plans for business areas. Typically 3-5 year view. •  Reference Architectures: reusable patterns for technical and operations solutions •  Guiding Principles: statements used as filters for decision making •  Standards: a library of stable technologies and processes for consistency Image courtesy of Wikimedia Commons 01/31/2013 © 2013 PricewaterhouseCoopers LLP 16
  • 17. x Issue: Compliance is often based on checklists of requirements Checklists are like looking in a rearview mirror How do you q  Do A ensure the Have you asked checklists are q Check B all the right complete, questions? accurate, and up q Redo C to date? q Do D Checklists can lead to a false sense of security Image courtesy of Wikimedia Commons 01/31/2013 © 2013 PricewaterhouseCoopers LLP 17
  • 18. x EA Answer: GRC should be managed by specific outcomes (principled performance) rather than checklists Principled Performance “Reliable achievement of objectives while addressing uncertainty and acting with integrity” Current Target State State Operating Operating Model Model The EA constitution, in combination with an EA roadmap, enable the EA governance process to assist you in getting where you are going, while maintaining alignment with corporate goals and objectives Includes material copied from or derived from “Increase Principled Performance and Reduce the Cost (and Hassle) of Risk Management and Compliance”, http://www.oceg.org/event/ increase-principled-performance-and-reduce-cost-and-hassle-risk-management-and-compliance Image courtesy of Stock.xchng 01/31/2013 © 2013 PricewaterhouseCoopers LLP 18
  • 19. Poll Question 01/31/2013 © 2013 PricewaterhouseCoopers LLP 19
  • 20. We’ve discussed 4 EA techniques that can help implement your GRC program Unify your multifaceted GRC environment by linking your risk and compliance measures to the corporate strategy. (EA modeling) Bridge your GRC silos by designing a common set of GRC capabilities and assess the impact by using a holistic operating model of your enterprise. (GRC capability mapping and impact analysis) Help your efforts stay within voluntary and mandatory boundaries by creating an EA constitution (strategic planning, reference architectures, standards and guiding principles) Avoid the pitfalls associated with management by checklist by leveraging the EA constitution (EA governance) 01/31/2013 © 2013 PricewaterhouseCoopers LLP 20
  • 21. Thank you © 2013 PwC. All rights reserved. PwC refers to the PwC network and/or one or more of its member firms, each of which is a separate legal entity. Please see www.pwc.com/structure for further details. This content is for general information purposes only, and should not be used as a substitute for consultation with professional advisors. PwC helps organizations and individuals create the value they’re looking for. We’re a network of firms in 158 countries with more than 180,000 people who are committed to delivering quality in assurance, tax and advisory services. Tell us what matters to you and find out more by visiting us at www.pwc.com. Includes material copied from or derived from OCEG at http://www.oceg.org
  • 23. Separated at Birth: EA and GRC ...to be continu in Part ed Putting II GRC A method rchitec s into p ture ractice MEGA is revolutionizing the approach to operational governance Imagine your business united... Imagine your business www.mega.com - @mega_int -