×
Blogs

GRC Success Story: How dnata Integrated Firm-Wide GRC Processes with MetricStream

Weekly-Blog-Upload-16-May-2024-dsk
4 min read

Introduction

At the recently held GRC Summit 2024 in Baltimore, David Story, Vice President Health, Safety, & Environment, dnata, provided the audience with a detailed overview of their GRC journey experience with MetricStream.

Dubai National Air Travel Agency (or dnata) was established in 1959 through a government decree. It set up its first international business in 1993. Gradually, over the years, it has seen significant growth across all its business units.

Here are the excerpts from David’s session on “dnata’s Integrated GRC Transformation”.

GRC Program Objective

David: Our foremost priority is safety and security. Through a series of SMART objectives, we're building a best-in-class, health, safety, and environmental system, or HSE ecosystem, as we call it. Over the next few years, up to 2027 and beyond, through our medium-term plan, we are striving for a best-in-class or world-class status, and central to delivering on that goal is the effective use of our GRC platform.

Within dnata, MetricStream is the product that we use, and we have done a number of modifications and upgrades through MetricStream over the years. We refer to it within the company as “dnatahub”, which is everything we do from a GRC perspective.

So, in terms of why GRC is so important to us -- central to that is our safety management system, or SMS. SMS is essentially the bedrock of everything that we do across four key pillars -- safety policy, risk management, assurance, and promotion. To be able to deliver on the requirements of our SMS, our dnatahub platform is absolutely central to achieving those goals.

GRC Journey with MetricStream

David: So, how has the dnatahub platform evolved over the last few years?

We're now into the 9th year of our partnership with MetricStream, beginning back in 2015 along with our “Global One Safety” initiative. The first pillar in that strategy was rolling out Incident Management, which allowed us to have one platform for reporting safety occurrences across local businesses.

In 2018, there was global expansion – we introduced new applications within dnata in addition to incident management and reporting.

In 2020, we started moving into the continuous monitoring phase, which saw the likes of our Documentation Management System (DMS). We also introduced surveys and inspection through the auditors. We would go out there and report safety hazards and threats to our organization. This was across all three of our operational divisions.

The beauty of DMS is that it can be accessed by any of our team in the world who got access to Office 365 accounts. Examples of a DMS document could be a global safety alert, a new manual, a guideline document, or a new operational standard. All of those are published through DMS and are automatically and electronically tested within the system as well. So, for auditing purposes, it's very, very efficient.

We also launched Observation Management as well. And, through Issue and Action Management we can assign tasks and actions to our businesses around the world.

We're now moving into Phase IV, as we call it, looking at how we scale up as we continue to build our business. We are currently two weeks away from the launch of the Euphrates upgrade as well.

We've built a very strong partnership with MetricStream, and we've now established a very strong governance model as well in terms of performance monitoring.

Business Value Realized

David: What's been key to success is keeping things simple. One of the worst things you can do in my role as a safety professional is over-complicate how you manage safety within your business.

In terms of just some numbers, we have got:

  • 20,000+ documents hosted within the DMS platform
  • 10,000+ mobile users (around 14,000 to 15,000 currently)
  • 40,000+ audit and survey documents accessible within the platform

What gives me great confidence is 400,000+ observations. We actively encourage -- from our leadership level all the way down to the front line -- to report any unsafe behaviors and actions within our business. What we've seen over the last 2-3 years is a considerable increase in the number of safety reports within the business. So that leads to a much more positive and safety-aware culture.

Looking Ahead

Over the next few years, we've got some really interesting challenges coming our way. You would have seen the announcement about the new airport project in Dubai. The target is 2033 for the opening of the new terminal with a capacity of 250 million passengers a year. We already have that airport as we have for the last 10 years, and this will be a significant upgrade to be the world's largest international gateway.

We have two to three new businesses that are going to be coming online towards the end of this year, including a particularly large business in Italy. And it's essential that we look at how we scale up to meet that demand, because we could have potentially 3,000 to 4,000 users within dnata by the end of this year.

 

Also Read:

  1. How Autodesk Moved from Siloed to Integrated IT Risk and Compliance Processes
  2. How American Fidelity Assurance Enhanced Third-Party Risk Management and IT Compliance Functions 
  3. Apple Bank Enhances and Streamlines Cyber Risk Management Program with MetricStream
Sumith-Sagar

Sumith Sagar Associate Director, Product Marketing

Sumith Sagar is a proven product marketing professional, specializing in software product positioning, product-led growth marketing, presales and sales enablement. With over 12 years of risk management solutioning experience ranging from Governance, Risk and Compliance (GRC), Commodity Trading & Risk Management (CTRM) and cybersecurity, she has been instrumental in driving BusinessGRC product marketing at MetricStream.

 
Blogs

AI Regulation Trends: Your Guide to AI Policies in the US, UK, and EU

blog-3-July-2024-dsk
8 min read

Introduction

The rapid evolution of Artificial Intelligence (AI) and particularly Generative AI has opened up new opportunities, and prospects of development and inclusive growth. But, in the wrong hands, AI can unleash fraud, discrimination, disinformation, stifle healthy competition, disenfranchise workers, and even threaten national security. The United States of America, the European Union, and the United Kingdom have taken the first steps to regulate the development of AI with a strong focus on data privacy, transparency, accountability, security, and ethics.

Here is a quick overview of the key regulations being implemented in these three regions, highlighting the main points to note.

The European Union’s Artificial Intelligence Act

The European Parliament adopted the Artificial Intelligence Act in March 2024, which will be fully applicable 2 years after entry into force. The objective of this Act is to standardize a technology-neutral definition for AI for future reference. Furthermore, the Act aims to ensure that AI systems within the EU are safe, transparent, traceable, non-discriminatory, environmentally friendly and monitored by people and not automation. The law uses a risk-based approach, with different requirements based on the level of risk. 

Risk level definition: It defines 2 levels of risk and states obligations for providers and users depending on the risk level:

  • Unacceptable Risk AI Systems - These are considered to be harmful for people and will be banned:

    • Cognitive behavioral manipulation of people or vulnerable groups
    • Social scoring or segmentation of people based on behavior, personal characteristics or socio-economic status
    • Biometric identification and categorization
    • Real time and remote biometric identification such as facial recognition programs

    There are some exceptions and rules established for law enforcement agencies.

  • High Risk AI Systems - AI systems that can negatively impact fundamental rights and / or safety of people:

    AI systems used in products covered by the EU’s product safety legislation, such as toys, aviation devices and systems, cars, medical devices and elevators.

    AI systems in specific areas that have to be registered with an EU database:

    • Systems used for managing or operating critical infrastructure
    • Systems used for educational and vocational training
    • Those used to employment, employee management and access to self -employment
    • Those that are involved with access to and utilization of essential private and public services and benefits
    • Law enforcement systems.
    • Systems involving migration, asylum, border control management
    • Those providing legal interpretation and application of laws.

    High-risk AI systems will have to be assessed before they can reach the market and will be assessed throughout their lifecycle. EU residents can file complaints with relevant national authorities.

Transparency requirements – While the Act does not classify Generative AI as high risk, it mandates transparency requirements and compliance with EU copyright laws:

  • Disclosures that state the content was generated by AI
  • Designing the model to stop it from generating illegal content
  • Publishing summaries of copyrighted data used for training

Supporting Innovation – The Act aims to help startups and small to medium businesses leverage AI with opportunities to develop and train AI algorithms before public release. National authorities have to provide companies with suitable testing conditions that simulate real-world conditions.

United Kingdom’s Response to the White Paper Consultation on Regulating Artificial Intelligence

In February 2024, the UK Government announced its response to the 2023 whitepaper consultation on AI regulation. Its pro-innovation stance on AI follows an outcome-based approach with a focus on 2 key characteristics – adaptivity and autonomy – that will guide domain specific interpretation.

It provides preliminary definitions for 3 powerful AI systems that are integrated into downstream AI systems:

  • Highly capable GPAI – large language models fall into this category. These are foundational models that can carry out a wide range of tasks. Their capabilities can range from basic to advanced and can even grow to outpace the most advanced models in use currently.
  • Highly Capable Narrow AI- these can carry out a limited range of tasks within a specific field or domain. These can also meet or outpace the most advanced models in use today within those specific domains
  • Agentic AI – this is an emerging subset of AI technology that can complete numerous sequential steps over long periods of time using tools like the Internet and narrow AI models.

It sets out five cross-sectoral principles for regulators to use when driving responsible AI design, development, and application:

  • Safety, security, and robustness
  • Appropriate transparency and explainability
  • Fairness
  • Accountability and Governance
  • Contestability and Redress

The principles are to be implemented on the basis of three foundational pillars:

  • Working with existing regulatory authorities and frameworks – UK will not be instituting a separate AI regulator. Instead existing regulatory offices such as the Information Commissioner's Office (ICO), Ofcom, and the FCA, will implement the five principles as they oversee their respective domains and use existing laws and regulations. They are expected to quickly implement the AI regulatory framework within their domains. Their strategy must include an overview of the steps taken to align their AI plans with the principles defined in the framework, an analysis of AI-related risks, and an overview of their ability to manage these risks.
  • Creating a central function for risk monitoring and regulatory coordination – The UK has set up a central function within DSIT to monitor and evaluate AI risks and address any gaps in the regulatory environment. This is because AI opportunities and risks cannot be addressed in isolation.
  • Foster innovation via a multi-agency advisory service – A multi-regulatory advisory service, the AI and Digital Hub, will be launched to help innovators ensure complete legal and regulatory compliance before they launch their products.

Blueprint for an AI Bill of Rights by the White House Office of Science and Technology Policy

The White House Office of Science and Technology Policy has formulated the Blueprint for an AI Bill of Rights with five principles to guide the design, use, and deployment of AI systems. The includes:

Safe and Effective Systems

  • Diverse communities, stakeholders, and domain experts should be consulted during the development of automated systems so that concerns, risks, and possible impact of the systems can be better identified
  • Extensive pre-deployment testing, risk identification and mitigation, and ongoing monitoring to ensure safety and effectiveness
  • Automated systems must be designed to proactively protect the American public from any negative impact due to unintended uses or impact of the systems. This includes inappropriate or irrelevant use of data in the design, use, and deployment of these systems

Algorithmic Discrimination Protections

  • This happens when automated systems contribute to differential and unfair treatment of people based on their race, color, ethnicity, gender, medical condition, sexual orientation, gender identity, religion, disability or any other classification protected by law
  • Designers and developers have to take proactive and continuous steps to protect the American public from such discrimination and ensure that systems are designed to be equitable
  • This must include proactive equity assessments as part of the system design, use of representative data, protection against proxies for demographic features, ensuring accessibility for people with disabilities, disparity testing and mitigation, and organizational oversight
  • It also recommends independent evaluation and plain language reporting

Data Privacy

  • Built-in measures to protect against abusive data practices and default measures to ensure individual agency over how personal data is collected and used
  • Designers, developers, and deployers of such systems must secure individual consent regarding the collection use, transfer, access, and even deletion of personal data
  • Consent collection mechanisms must be brief and in easily understood language
  • Data pertaining to sensitive domains such as healthcare, education, criminal justice, and finance, must be used only for necessary functions and be protected by ethical review and use prohibitions
  • The American public cannot be subjected to unchecked surveillance and such technologies must undergo stricter oversight with pre deployment assessment of possible negative impact
  • Continuous surveillance cannot be used in education, work, housing, or in other contexts where the use of such surveillance technologies is likely to limit rights, opportunities, or access

Notice and Explanation

  • People must know when an automated system is being used and understand how it impacts them
  • This must be communicated via plain language documentation with clear description of how the system works and its outcomes
  • People must know when an outcome impacting them was determined by an automated system even when that system was not the only input determining the outcome

Human Alternatives, Consideration, and Fallback

  • People should have the option of connecting with people to remedy any problems and should be able to opt out of automated systems to engage with a person instead
  • Engagement with humans should be accessible, equitable effective and managed well with adequate operator training. It should not put additional burden on the public
  • Automated systems in sensitive domains must be customized to provide meaningful access for oversight and include human consideration for high risk or negative decisions

In addition to these federal guidelines, several states are also formulating their own regulations. 17 states (California, Colorado, Connecticut, Delaware, Illinois, Indiana, Iowa, Louisiana, Maryland, Montana, New York, Oregon, Tennessee, Texas, Vermont, Virginia and Washington) have enacted 29 bills on AI regulation over the last five years.

Stay Ahead with MetricStream

AI technologies are here to stay and the world has to learn to use them safely for the betterment of humanity. Regulations for AI development and use are critical to protect populations from bias, discrimination and breach of privacy. AI technologies are evolving at an unprecedented pace, and regulators across the world are following suit with quick updates or new frameworks. Organizations need automated compliance platforms to keep pace with this rapidly changing regulatory landscape.

MetricStream’s Compliance Management can simplify and fortify enterprise compliance initiatives amidst a rapidly changing regulatory landscape. Gain greater visibility into control effectiveness and quick issue remediation with streamlined:

  • Mapping of regulations to processes, assets, risks, controls, and issues
  • Identifying, prioritizing, managing, and monitoring areas of high compliance risk
  • Performing control testing and monitoring
  • Creating and communicating corporate policies
  • Identifying, capturing, and managing regulatory updates
  • Generating reports with drill-down capabilities

Even as compliance management is simplified and streamlined, it is important to have a mechanism in place to keep track of rapidly evolving regulations. MetricStream’s Regulatory Change Management platform is a centralized framework that can help organizations capture, curate, identify, extract, consolidate, and manage regulatory changes and updates sourced from diverse providers.

Find out more. Request a personalized demo today!

Pat McParland

Patricia McParland AVP – Marketing

Pat McParland is AVP of Product Marketing at MetricStream. She is responsible for creating product messaging, product go-to-market plans, and analyzing market trends for MetricStream's cyber compliance and third party risk product lines. Pat has more than 25 years of financial data and technology marketing experience at Fortune 1000 brands as well as startups and has led product and marketing teams at Dow Jones and Dun & Bradstreet. She has a BA from the College of William and Mary and lives in Summit, New Jersey.

 
Blogs

Enterprise GRC in Asia-Pacific: Trends, Challenges, and Opportunities

blog-26-June-2024-dsk-1
6 min read

Introduction

With Asia-Pacific’s (APAC) economic growth surpassing expectations, businesses have much to be optimistic about. However, as regulations and risks in the region grow more numerous, the need for effective governance, risk, and compliance (GRC) has never been more pressing. APAC GRC professionals are being called upon to spot emerging risks, connect the dots, and help their organizations adapt swiftly to regulatory changes. GRC solutions that can help meet these demands at scale and speed will make all the difference.

I recently had the chance to host GRC Design Workshops in Malaysia and the Philippines in association with our strategic partners - HCLTech and Expleo respectively. The workshops, led by Michael Rasmussen, GRC Analyst & Pundit, GRC 20/20 Research, delved into a range of GRC areas, including the evolving risk and regulatory landscape in APAC, GRC challenges faced by organizations in the region, how technology and automation can help, and more.

Here are some of the key takeaways from the workshops, providing insights into the trends and opportunities likely to be encountered by GRC professionals as they gear up for the road ahead.

1. Constantly Changing Regulations

Keeping pace with regulatory change is no small feat. In the past three years alone, Singapore, Hong Kong, and Australia have either revised or issued new standards and guidelines around operational risk management and resilience.

Meanwhile, India enacted its first comprehensive data protection law in 2023 – the Digital Personal Data Protection (DPDP) Act, even as Japan substantially amended its own Act on the Protection of Personal Information (APPI), a year earlier.

Climate change too has been enveloped in a flurry of regulatory activity. Vietnam’s Law on Environmental Protection took effect in 2022, followed by Malaysia’s Energy Efficiency and Conservation Act in 2023.

2. Risks Galore

In addition to juggling regulations, APAC GRC professionals also have to navigate a growing variety of risks – including the Ukraine and Middle East conflicts that have strained global supply chains; extreme weather events like the floods in China and drought in India; the risks of deep fakes and misinformation associated with AI; and of course, the constant threat of a cyberattack. Incidentally, APAC experienced the highest year-on-year surge in weekly cyberattacks during Q1 2023, with an average of 1,835 attacks per organization.

Risks come from within the organization too – from changes to business objectives, structures, processes, employees, and technologies, as well as from the extended enterprise of suppliers, vendors, contractors, dealers, and distributors.

Getting these risks under control is key to strengthening organizational resilience and performance.

3. Connecting the Dots

If there’s anything we’ve learned over the past few years, it’s that everything is connected. A data breach in a third-party service provider’s system can disrupt entire supply chains, damage business reputations, trigger hefty regulatory penalties, and sometimes even shut down operations for days.

That’s why it’s so important to be able to see the big picture – to understand how risks impact and influence each other, how they affect compliance, and how they hinder or help the achievement of business objectives. 

GRC offers that perspective. It enables organizations to understand the road ahead more clearly, make better-informed decisions, and capitalize on the right opportunities at the right time. In other words, GRC shouldn’t be seen as an afterthought, but an enabler of the business.

Challenges and Roadblocks

APAC GRC professionals tell us that these are some of the GRC challenges they face:

  • Data silos: Risk and compliance data is scattered across disparate systems and business functions. So, organizations don’t have a clear view of their GRC universe.
  • Inefficient processes: GRC data is manually managed through spreadsheets, emails, and other cumbersome tools that slow down risk efforts and limit efficiency.
  • Lack of forward-looking risk visibility: When an organization’s sights are only fixed on the rear-view mirror, they aren’t able to anticipate emerging risks. Issues are managed reactively rather than proactively.
  • Limited agility: With manual and siloed GRC processes, organizations can’t adapt quickly to regulatory and business changes. Nor can they coordinate and integrate GRC across business functions.
  • Forgetting the G in GRC: Many organizations forget that GRC begins with governance – i.e., the achievement of objectives. Whether it’s an enterprise objective or a process objective, that’s what risks and compliance should be measured against.

The GRC Playbook: Six Winning Practices

Here are six ways to overcome the above challenges, and create a truly world-class GRC program:

  • Automate wherever possible: Toss out those spreadsheets, and unlock new efficiencies by streamlining and automating your GRC processes. With automation, you can monitor risk exposure and compliance status in real time, and respond more proactively when issues Also, automating routine GRC tasks frees up more time for your teams to focus on value adding and strategic activities like risk analysis.
  • Build a single source of GRC truth: Break down silos, and unify all your GRC data in a single system of record. Enrich that data by integrating information from other systems like ERP platforms, social media, transaction systems, threat and vulnerability scanners, and regulatory content feeds. The idea is to have complete horizontal and vertical GRC visibility across your enterprise through one platform. This can help you make better-informed decisions that optimize risk-reward trade-offs.
  • Understand risk interconnectedness: Map your GRC data in such a way that users understand the relationships between various risks, regulations, policies, controls, third parties, ESG (environmental, social, and governance) elements, strategic objectives, audits, incidents, and cases. Having a connected view of GRC will help you target your risk management efforts and resources in the right place, in the right way, at the right time.
  • Foster risk awareness across teams: Bring together your risk managers, compliance professionals, and auditors on one platform where they can seamlessly collaborate and exchange GRC insights. Empower your front line with simple, intuitive GRC tools to capture issues and risks as they arise.
  • Enable continuous control monitoring and regulatory horizon scanning: Chances are that you can’t manually monitor all your controls and regulatory changes all the time – even though you need to. So, choose a continuous control monitoring (CCM) tool that can automate the process. Go from periodic, sample-based testing models to always-on monitoring of full control populations. Couple that with regulatory change management software that can automatically capture alerts on proposed and anticipated legislation, as well as regulatory updates. So, you can adapt your compliance program faster.
  • Use AI for richer insights: AI-powered analytics can unlock the full potential of your GRC and transactional data by connecting with multiple data sources, and drawing out insights faster. Use it to enable predictive and data-driven decision-making. You can even train AI models to identify risk and control deficiencies, patterns of over-testing and under-testing, and duplicate risks and controls that can be removed.

Transform your GRC program with MetricStream

MetricStream ConnectedGRC helps you build an automated, truly integrated, and collaborative approach to GRC. Reduce risk exposure with streamlined assessments and mitigation. Enable consistent compliance with robust control testing and reporting tools. Finally, achieve your objectives with ease using strong governance and policy management mechanisms.

MetricStream products are packed with best practice workflows, content, AI, and analytics to help you:

  • Drive business growth and strategic differentiation through your GRC program
  • Connect risk, compliance, audit, cybersecurity, and sustainability on one platform
  • Improve GRC efficiency, reduce costs
  • Protect your digital business from cyber risks and evolving threats
  • Grow with purpose using ESG best practices

To learn how MetricStream can help you on your GRC journey, request a personalized demo today.

Vishwas-Udupa-headshot

Vishwas Udupa Director, Field Sales MEA

Vishwas Udupa is Director of Sales (MEA & APAC) at MetricStream. In his role, Vishwas is responsible for market strategy and sales, managing marquee accounts, regional go-to-market initiatives, and analyzing market trends.

Vishwas has 19 years of experience in Governance Risk and Compliance (GRC) domain as a Risk & Audit consultant and in sales profile across Oracle Financial Services, Thomson Reuters, London Stock Exchange Group (LSEG) and Empowered Systems. He has a Masters in Business Administration at ICFAI and Bachelor of Engineering degree from MSRIT, and lives in Bangalore, India.

 
Blogs

How American Fidelity Assurance Enhanced Third-Party Risk Management and IT Compliance Functions

Weekly-Blog-Upload-16-May-2024-dsk
4 min read

Introduction

At the 2023 GRC Summit in Miami, Tice Morgan, Senior Manager, Governance and Compliance, American Fidelity Assurance, discussed how they improved the management of their third-party risks and IT compliance processes, their transformation journey experience with MetricStream, and more. American Fidelity Assurance is a leading health insurance company operating in 49 states across the US.

Here are the excerpts from Tice’s session at the summit.

Challenges

Tice: A lot of our GRC needs were associated with simplifying our compliance program and also looking at how we could better control or at least assess our third parties.

We operate in 49 states, and what I found was that I'm answering the same questions for each of these regulators, sometimes on a quarterly basis, sometimes only on an annual basis. We really wanted to look at a compliance framework that we can customize to allow our organization to harmonize these controls. State once and then use many times.

Having a consistent approach to control and that consistent expectation of evidence has really been a challenge for our organization. And part of that is our ability to tailor our control efficacy and the frequency in which we operate. When the team comes in to test controls, they're going to test it once a year. They're going to do a small sample set. But if we look at the volume, and some of the issues that we've had like any large organization was things slip through the cracks. If they happen to sample one of those slips through the cracks, that control is going to fail for that year. So, what we're actually in the process of implementing it's a monthly control testing component so we can at least catch that up.

The Implementation Journey

Tice: Our GRC program today primarily focuses on third-party risk and IT compliance.

I wanted to start out really small. We started with the Third-Party Risk Management product, and that was a pretty quick deployment. For IT compliance, it's definitely more of a long-term strategy for our organization. And part of that is that the ecosystem is changing – especially on the privacy side.

One of the compelling features of the MetricStream Platform is that it has really helped us enable our organization to be a little bit more efficient and a little bit more consistent about how we support our compliance and our third-party program.

Business Value Realized

Tice: From a key learnings and best practices perspective, one of the things that I always stress is to keep it simple. We had 137 controls when we started, and we've been able to whittle that down to 68 key controls that primarily address the majority. There are always those one offs, and we do accommodate for some of those. But I think those should be more the exception versus the rule.

The other element is to explain, educate, collaborate, and then automate. I will admit that I look at automation in two ways. There are always the technology automation components, system interaction, and API integration. Those are all good, but in a lot of cases, automation can also be just process efficiency.

The other thing is best practices – really understanding the mechanics of what you are trying to assess. The other element is identifying key source systems and reporting requirements. I really can't stress this enough, because in a lot of cases, there are a lot of systems, and getting the data out of those systems [is critical]. The GRC platform that you’re implementing is only a component of your overall compliance function.

The one thing that it does allow us to do is facilitate continuous control monitoring. In a lot of cases, we are working to test controls on a monthly basis. That way, even though our external regulators are going to do it in a quarter or on a yearly basis, we know in advance that we’re going to have an issue with that control. We can go do the awareness, we can go to the communication, the training, augment that control, or refine that control to make sure that evidence is going to be good for us. So, we catch it before the regulator or our internal audit team assesses it. It also allows us to reduce our overall control expectations and the ability to reuse controls for certain things.

You can watch the complete session here:

 

Find out how we can help you on your GRC journey. Request a personalized demo today!

Shampa-mani

Shampa Mani Assistant Manager – Marketing

Shampa Mani, Assistant Manager - Marketing, at MetricStream, has over 9 years of experience in content writing and editing. Prior to joining MetricStream, she worked in the news and media industry, covering news on fintech, blockchain technology, and digital currencies. Academically, she has an MBA in Business Economics and an MA in Economics. In her free time, she loves to cook, read, and delve into the world of UFOs and extraterrestrials.

 
Blogs

Taming OpenAI is a Shared Responsibility

blog-12-June-2024-dsk
3 min read

Introduction

It is almost an understatement today to say that the rise of Artificial Intelligence (AI) and Generative AI have been game-changers for businesses. In India, as many as 84% of CEOs are either securing new capital or reallocating funds from other budgets to finance GenAI, aiming to gain a competitive edge. Understandably so, given that, about 84% of Indian consumers say they were most likely to procure from an organization that uses GenAI.

As we find ourselves on the brink of the vast potential of AI, it is immensely critical to approach the technology with awe and a certain amount of prudent skepticism. Let's face it – the big player in the game right now is OpenAI, holding a ton of power in its hands. And guess what? With great power comes great responsibility, and also the fact that concentrating such substantial power in one organization could raise some significant concerns.

Who can overlook the several lawsuits OpenAI struggles with from best-selling authors, citing valid concerns about copyright infringements?

In this background, one must ask how we will keep OpenAI in check. The concern extends to a broader community of researchers, tech companies, policymakers, corporations, and even end-users, all of whom should participate in this conversation.

Navigating the OpenAI Quandary

OpenAI, frequently leading the charge in AI research, has achieved noteworthy advancements. From creating language models capable of producing text similar to human language to solving global challenges, the organization has sparked a surge of technological progress. For countries like India, this has translated into positive outcomes with the adoption of AI technology, which is expected to propel GDP by a substantial $1.2-1.5 trillion over the next seven years.

However, the responsibility for developing and implementing AI does not rest solely on the shoulders of its creators. Instead, this calls for a collaborative effort involving a network of stakeholders, each shouldering their part of the responsibility.

Here's what each stakeholder must do.

Standardize Benchmarks

Researchers must collaborate to usher in best practices that collectively help tackle potential risks associated with AI. Research teams should work on setting up standard benchmarks for testing AI fairness and developing open-source auditing tools.

A Culture of Ethics

Next in line are the tech companies that are actively engaged in the implementation of AI technology. Tasked with deploying AI solutions across diverse industries, these companies are responsible for ensuring compliance with regulatory frameworks and designing AI products that minimize risks. On their part, developing strong ethical AI guidelines and cultivating a culture that emphasizes responsible AI within the company is of utmost importance. Companies should establish AI ethics committees accountable for overseeing AI projects, aligning them with company values, and ensuring transparency in decision-making processes.

Integrate AI-Governance

Conducting AI risk assessments to proactively identify and mitigate potential issues like data breaches, algorithmic bias, and compliance gaps is crucial. Organizations must integrate AI governance into their risk management and compliance strategies – GRC for AI, technically speaking. Essential to this process is collaboration with AI experts to formulate policies and establish processes prioritizing responsible AI adoption.

Balancing between Innovation and Regulation

Policymakers must foster an environment that encourages AI innovation while regulating its use to alleviate risk. Formulating resilient and adaptive regulations that promote innovation and protect public interests could be challenging. So, policymakers must collaborate closely with experts, tech firms and the general public to make well-informed decisions and tackle AI's ethical, legal, and societal implications.

Approach to GRC

The fundamental practices of Governance, Risk Management, and Compliance (GRC) have consistently played a crucial role in the business world, ensuring ethical operations and adherence to legal boundaries for organizations. Nevertheless, using AI in diverse facets of business operations demands an evolution of GRC practices. 

The GRC approach must take into account AI-related risks like data breaches, algorithmic biases and compliance-related issues. Organizations must create governance frameworks that supervise AI strategies, investments, and initiatives, such as aligning AI projects with organizational goals and ensuring transparency in decision-making processes.

The responsibilities and risks of AI should not rest solely on the shoulders of one company. Taming OpenAI or any such technology will require collaboration between researchers, tech firms, policymakers, corporations, and end-users. Additionally, these efforts must all be rooted in robust modern technology-enabled GRC practices to foster an environment of responsible innovation.

This blog was initially featured as an article on ET CISO. Read the original version here.

Find out more about MetricStream ConectedGRC. Request a personalized demo now.

Gunjan

Gunjan Sinha Executive Chairman, MetricStream

Gunjan Sinha, Executive Chairman, MetricStream, helps lead the overall direction and vision of the company. His focus in on building MetricStream into a global GRC leader with strong teams that are excited about new markets, disruptive technologies and social impact.

 
Blogs

Your Ultimate Guide to the MetricStream 2024 GRC Summit: 7 Pro Tips

Weekly-Blog-Upload-8-May-2024-dsk
5 min read

Introduction

The MetricStream GRC Summit 2024 is all set for June 17th and 18th at the Baltimore Marriott Waterfront in Maryland. For over a decade, the GRC Summit has been the ‘go-to GRC event’ for the risk and compliance community, enabling the fostering of connections, sharing of insights, and exchanging of best practices. It has continuously set the stage for what’s next in the world of GRC. Under the compelling theme of Experience the Power of Connection, this year's Summit promises to be our best yet. Prepare to join an esteemed global community of risk, compliance, audit, and cyber professionals for an unparalleled experience.

With so many significant events happening around the same time, such as the IIA International Conference, the Gartner Conference, and the American Bankers Association (ABA) conference, we know your time is limited. So, here are some top things to do to maximize your experience at the premier technology conference of the year!

1. Attend Keynote Sessions

The keynote speeches have always been a highlight of the GRC Summit, and this year is no exception. Attendees can look forward to exclusive insights from MetricStream leaders, including Gaurav Kapoor, Co-Founder and Co-CEO, Prasad Sabbineni, Co-CEO, and Gunjan Sinha, Co-Founder and Executive Chairman, along with other industry leaders in the opening and closing keynotes.

2. Experience In-Depth Panel Dialogues

These sessions are not to be missed! Numerous thought leaders will participate in panels on day 2. Listed below are a few that are sure to be insightful and thought-provoking.

  • Navigating the Risks on the Horizon: Preparing for What’s Next in GRC, featuring Michael Koenig, Global Chief Ethics and Compliance Officer, JBS, Tolu Oyefesobi, Chief for Financial Controls and Operational Risk, Inter-American Development Bank, and Prabha Thomas, VP, Chief Risk & Compliance Officer, Tata Consultancy Services
  • GRC in the Era of AI and Automation: Looking at the Road Ahead featuring Michael Cover, Director, Blue Cross Blue Shield of Michigan, and Michael Rinard, Chief Legal & Chief Compliance Officer, Mosaic Health System
  • Transformative Strategies for a Modern Compliance & Risk Function featuring Faisal Siddiqui, Deputy Chief Compliance Officer, International Finance Corporation (IFC)/World Bank Group, Bianca Forde, VP, Global Ethics & Compliance Programs, Otis Elevator Co., and Anand Narayana, Head of Regulatory Change Management, Americas, Sumitomo Mitsui Banking Corporation
  • Managing Data Privacy and Security Risks in the Era of GenAI and Data Explosion featuring Xin (Cindy) Tu, Director of IT & Data Audit, Discover Financial Services, Oded Anderman, Privacy Program Manager, Meta, Eduardo R. Ortiz, VP, Global Head of Cybersecurity, TTI Group, Inc., and Ananeya Abebe, SVP, Director of Data Risk Governance, KeyBank
  • The Expanding Scope of Operational Risk Programs in the Time of Operational Resilience, featuring Madiha Fatima, Executive Director - Global Head of Horizontal Risk Management, JP MorganChase, Alapan Arnab, Technology Resilience Executive, Former - Scotiabank and Barclays Africa, Spruille Braden, Head of Operational Resilience, PGIM, and Kamlesh Sidhwani, CRO Canada, Sumitomo Mitsui Banking Corporation – SMBC
  • Driving Value in Your GRC Program: Creating Synergies across Audit, Risk, and Compliance featuring Jeannie Kim, VP, Enterprise Risk Management, Mitsui & Co. Energy Marketing and Services (USA), Inc. (MEMS) and Joseph Hegge, Senior Audit Program Manager, Lockheed Martin Corporation

3. Discover Real-Life Case Studies

Don't miss out on these real-life narratives showcasing how organizations have effectively tackled the intricate realm of GRC hurdles. They provide invaluable insights and inspiration to propel your own GRC endeavors forward. Check out:

  • Blue Cross Blue Shield of Michigan Case Study: Enable Risk & Compliance Program Effectiveness presented by Nicholas Cannon, Manager, Blue Cross Blue Shield of Michigan, and Jason James, Senior Business Systems Analyst, Blue Cross Blue Shield of Michigan
  • Bank OZK Case Study: Agile Risk Strategies in Action presented by Arindam Majumdar, Deputy Chief Risk Officer, Bank OZK
  • Apple Bank Case Study: IT Risk and Compliance Transformation presented by Jonathan Ruf, First Vice President - Head of Cyber and Information Risk, Apple Bank

4. Explore Product Sessions

Product sessions are a cornerstone of the GRC Summit. Our tailored product sessions promise to equip you with thorough insights, enabling you to grasp the full spectrum of capabilities and advantages our offerings deliver.

Raghuram Srinivas, SVP, Product Management, MS Innovations, MetricStream, will be presenting sessions on:

  • What's New in CyberGRC
  • Harness the Power of AI for Risk
  • What's New in Regulatory Compliance
  • What’s New in ERM & ORM

Kiran Kumar Nakhate, Senior Principal Product & Platform Development Manager, MetricStream, will be presenting a session on:

  • Low Code No Code

5. Join Deep-Dive Workshops

The workshops are designed to offer practical insights and hands-on experience from industry experts, fostering a deeper understanding of critical GRC strategies and their real-world applications. Gain extensive knowledge of specific topics that you can apply directly to your organizations.

Christopher E. Mandel, Founder & President, Excellence in Risk Management, LLC, will be conducting a deep-dive workshop on:

  • How do you practice effective ERM and how does ERM align with a GRC strategy?

Grace Beason, Director Of Governance, Risk and Compliance, Guidewire Software, and Gavin Anthony Grounds, CEO & Co-founder, Mercury Risk and Compliance, Former - Meta & Verizon, will jointly be conducting a workshop on:

  • Cyber Risk Quantification: Harnessing Quantified Insights for Better-Informed Strategic and Operational Decision-Making

6. Enjoy the Venue and City

Located at the Baltimore Marriott Waterfront, the venue offers stunning views and a range of amenities. Take some time to enjoy the local attractions in Baltimore, such as the Inner Harbor, historic sites, and vibrant dining scene, to make the most of your visit.

7. Network with Industry Peers

Networking is a significant component of the GRC Summit. Attendees will have the chance to connect with peers, share experiences, and discuss challenges. The Summit provides a conducive environment for formal and informal networking opportunities, fostering connections that can lead to future collaborations.

See You in Baltimore!

The list above is just a part of what’s on our Agenda. Join us and deep-dive into all things GRC! Get to know more about our esteemed speakers. Read our recent blog post. Meet our Speakers, to get to know more about the speakers and their areas of expertise.

Not yet registered? Register now.

dummy MSI

Aanya Sharan Associate Director - Marketing

Read the blogs authored by Aanya Sharan, Associate Director - Marketing, for the latest insights on governance, risk management, cyber resilience, and more.

 
Blogs

How Autodesk Moved from Siloed to Integrated IT Risk and Compliance Processes

Weekly-Blog-Upload-16-May-2024-dsk
3 min read

Introduction

At MetricStream’s flagship event, GRC Summit, Clyde Tsai, GRC Lead at Autodesk, shared how MetricStream has helped them implement an integrated framework for IT risk and compliance management programs. Autodesk is a leading provider of software products to architecture, engineering, construction, product design, manufacturing, media, and entertainment industries.

Here are the key takeaways from Clyde’s session at the summit.

Why MetricStream?

Clyde: One of the very special things about Autodesk teaming up with MetricStream is that we're trying to get FedRAMP compliant. We are in the midst of getting the authority to operate in FedRAMP – it is the ability to sell to the federal government. It’s a huge audit and continuous process. That was actually our main driver for choosing MetricStream.

Apart from that we're also doing compliance for a range of frameworks. We’re trying to infuse more of a culture of risk-aware decision-making. We have a small risk team and we’re trying to do as many risk assessments as we can. Automation really helps us with that.

The Journey So Far

Clyde: We’re two years into it. Specifically, the products – IT and Cyber Risk Management, IT and Cyber Compliance Management, and Policy and Document Management. All of our initial use cases are security use cases – security compliance, security risk, FedRAMP compliance, and security policies.

Key Challenges and Learnings

Clyde: We have this challenge with silos -- we have security, privacy, internal audit, ERM, IT, and legal. The challenge that I see here is understanding and being informed when something is happening in any of these areas that affects me as a GRC implementation person. To address this challenge, we are just learning how to do interdisciplinary working groups.

An example of this is our initiative to put together an information asset inventory, which is a requirement for ISO and other frameworks. This information asset inventory includes all organizational databases, EC2s, containers, and much more. To do it right, one should collect this data from other systems. But the challenge is determining the authoritative sources of truth and what the systems are, what data is in them, and then normalizing them if they're coming from multiple systems.

In such a situation, one should piggyback on other data consolidation efforts. And that's one thing that I've learned while putting together these interdisciplinary groups. I am communicating with these groups, and they have similar initiatives going on. So, I can put my requirements in there as they might have bigger teams for doing these things.

Another challenge is that we have some processes that are mature and some that are immature. MetricStream has a lot of these workflows already as out-of-the-box workflows. Therefore, you have an opportunity to just use that as your process and have the perfect alignment between your technology and your process, which is rare to have.

Business Value and Realized Benefits

Clyde: Regarding business value that we have realized:

  • We now have a one-stop shop for product owners and other leaders on SOC2 and ISO compliance. We plan to do a lot of other frameworks, like SOX, which we have to comply with.
  • We have a single source of truth risk register for Autodesk at least from the security perspective.
  • Regarding security risk assessments, we are in the process of getting those onboarded on MetricStream.
  • We have implemented an integrated framework and process for integrating all risk data
  • We have a huge requirement around FedRAMP, which requires us to report to our sponsoring federal agency every month, such as, how we are doing against vulnerabilities, etc. We have achieved complete automation around FedRAMP Plan of Action and Milestones (POAM) tracking:
    • Generation of monthly POAM Report to sponsoring agency
    • Issues tracking for open vulnerabilities
    • Parity checks to ensure more than 90% of assets are scanned

Going forward, our priorities include end-to-end compliance testing, integrated control framework, automated evidence collection, and security policy management lifecycle.

You can watch the complete session here:

 

Join us in our upcoming GRC Summit 2024 in Baltimore on June 17-18 to explore other real-world GRC implementation stories. To register, click here.

Shampa-mani

Shampa Mani Assistant Manager – Marketing

Shampa Mani, Assistant Manager - Marketing, at MetricStream, has over 9 years of experience in content writing and editing. Prior to joining MetricStream, she worked in the news and media industry, covering news on fintech, blockchain technology, and digital currencies. Academically, she has an MBA in Business Economics and an MA in Economics. In her free time, she loves to cook, read, and delve into the world of UFOs and extraterrestrials.

 

Related Resources

Blogs

GRC Summit 2024, Baltimore: Get to Know Our Speakers

Weekly-Blog-Upload-8-May-2024-dsk
4 min read

Introduction

We're officially in countdown mode! With just six weeks to go until the 2024 GRC Summit, to be held on June 17th and 18th in Baltimore, excitement is high. This year marks the 12th anniversary of our GRC event, and our theme, "Experience the Power of Connection," aims to empower you to achieve more as you continue to thrive on risk!

MetricStream’s flagship event, the GRC Summit, has been a ‘must-attend event’ for the GRC community over the past decade. The GRC conference serves as a platform for networking, sharing insights, exchanging best practices, and setting the stage for the future of GRC. Whether it's exploring emerging technologies, discovering new processes, or dissecting new regulations impacting business operations, the summit is the place to stay ahead of the curve.

The two-day technology conference will bring together an influential gathering of 200+ GRC leaders and recognized industry experts to discuss the latest trends and best practices in Connected GRC, the risks and opportunities of artificial intelligence (AI) for GRC, GRC for AI and more.

Find out more: Explore the GRC Summit Agenda.

Meet Our Amazing Speakers

As a leading thought-leadership event in the GRC realm, the GRC Summit consistently showcases top-tier expertise in risk, compliance, cyber, audit, and operational resilience. This year, we're thrilled to present over 45 experts who will deliver insightful keynotes, offer valuable insights and best practices, and generously share their own GRC journeys.

Keep scrolling to meet some of our esteemed speakers and learn more about their areas of expertise.

  • Mike Koenig, Global Chief Ethics and Compliance Officer, JBS, was before being named to this position, the Head of Ethics and Compliance for Pilgrim’s Pride. 25 years prior to joining Pilgrim’s, Mike represented and defended companies, individual executives, and public officials in federal and state criminal, civil and regulatory investigations and trials.  In addition to private practice, Mike served as a federal prosecutor in the  Justice Department’s Criminal Division, Fraud Section, where he prosecuted a variety of white collar crimes, with a primary focus on corporate fraud
  • Michael Cover, Director, Blue Cross Blue Shield of Michigan, serves as Director within the Office of the General Auditor and Corporate Compliance division and is responsible for designing and implementing technology solutions to support regulatory compliance and risk management efforts across the enterprise. Prior to joining BCBSM, Michael was at Ernst & Young within their IT Risk and Assurance practice. While at E&Y he focused on enterprise application implementations, business process redesign and mergers and acquisitions. Michael is a Certified Information Systems Auditor.
  • Faisal Siddiqui, Deputy Chief Compliance Officer, International Finance Corporation (IFC)/World Bank Group, works with IFC’s Business Risk and Compliance Department, which focuses on integrity, regulatory, international tax, regulatory, privacy, and other risks. Faisal also directly manages IFC’s integrity due diligence efforts (including anti-corruption, AML/CFT, and sanctions issues) and heads many of its crisis management teams.
  • Joseph Hegge, Senior Audit Program Manager at Lockheed Martin Corporation, has been with the organization for over 25 years and has more than 15 years of experience as an Internal Auditor and risk professional. Joe oversees the Corporate Internal Audit Professional Services team and is responsible for the department budget and staffing, reporting, quality program, Business Leadership Program (BLP), and Risk Program.
  • Bianca Forde, VP, Global Ethics & Compliance Programs, Otis Elevator Co., serves by the compliance philosophy that emphasizes the importance of corporate cultural values. To that end, she works to execute innovative, data-informed solutions that continuously improve corporate culture, and empower all colleagues to choose the ethical course when challenges arise. Bianca is the 2023 winner of the Compliance Innovator of the Year Award, sponsored by Compliance Week. She is also the author the book, Prosecuted Prosecutor: A Memoir & Blueprint for Prosecutor-led Criminal Justice Reform based on her experience as a former federal prosecutor at the U.S. Attorney’s Office – District of Columbia.
  • Madiha Fatima, Executive Director - Global Head of Horizontal Risk Management, JPMorgan Chase, leads the horizontal risk and control management function overseeing Third Party Risk Management, Insider Threats, and Real Estate risk. In her previous role, she served as the Head of the Third-Party Risk Management Department at Angelo Gordon, where she was responsible for the development of the Third Party Risk Management Framework while enabling businesses to achieve their strategic objectives by utilizing vendors. Before joining Angelo Gordon, she served as the Head of Third Party Risk Governance & Oversight at DTCC. Madiha is a Certified Third Party Risk Professional (CTPRP).
  • Xin (Cindy) Tu, Director of IT & Data Audit, Discover Financial Services, is an IT/Data Risk Leader who has over 17 years of audit experience. She is currently an IT Audit Director at Discover Financial Services managing IT and Data audit portfolio. Prior to joining Discover, Cindy has been with Fannie Mae and Sallie Mae with an overall 9 years’ experience in the Financial Services Industry. Cindy’s specialty areas include IT Audits, Data Governance Audit, and Agile Methodology.
  • Eduardo R. Ortiz, VP, Global Head of Cybersecurity, TTI Group, Inc., is a change leader and one of the leading corporate authorities in building effective Cybersecurity programs for global operations. As Global Head of Cybersecurity for Techtronic Industries, Inc., a $13B global operation, Eduardo oversees a 28-member global team of direct-level IT engineers and analyst staff, and multiple CIOs representing divisions worldwide. Eduardo architected, deployed, and supervised the first full-scale global Managed Detection and Response program for Techtronic Industries. Eduardo is a frequently requested public speaker and a thought leadership guest on industry-related talk shows and podcasts.

Discover more about our speakers, along with the full speaker lineup.

Keynotes from our Co-CEOs and Executive Chairman

MetricStream leaders Gaurav Kapoor and Prasad Sabbineni, our Co-CEOs, along with Gunjan Sinha, our Co-Founder and Executive Chairman, will offer valuable insights in their keynote addresses and panel discussions. 

Secure your ticket now, as they're going fast! Register now.

Stay tuned for more updates on speakers and exciting highlights of the GRC Summit. Bookmark this space!

dummy MSI

Aanya Sharan Associate Director - Marketing

Read the blogs authored by Aanya Sharan, Associate Director - Marketing, for the latest insights on governance, risk management, cyber resilience, and more.

 

Related Resources