CA Community






This Blog

The Four Main Principles of Lean GRC

Published: June 03 2009, 05:00 AM
by Sumner Blount


There has been a lot of attention given over the past few years, to "Lean Production Principles," as exemplified by the success of Toyota's manufacturing processes. In the late 1980s, Toyota adopted Lean Manufacturing and became a leader in both efficiency and quality.





Companies today are looking at ways to leverage technology to bring the strategies of Lean Manufacturing to the world of IT. Check out CA's Lean IT site to learn more about our approach.





Those principles of lean thinking are very appropriate to apply to the management of risk and compliance activities. CA and OCEG (Open Compliance and Ethics Group) have recently teamed up to promote the use of Lean GRC™ practices to help improve the efficiency and effectiveness of risk and compliance. For a complete discussion of this important area, we have co-authored a whitepaper that is now available on our site (note, you'll need to register, but once you do, you can access all of our site content).





We'll be talking about Lean GRC strategies quite a bit over the coming months. We introduced these concepts briefly in yesterday's video blog with Peter Stapleton; in short, the primary principles include:






>> Eliminate waste "" get rid of unnecessary or redundant processes, and automate as many manual processes as possible.





>> Focus on individuals who add value - transfer responsibilities and ownership to those individuals who have the potential to actually add value to the process.





>> Use pull demand to drive value - Traditional production involves the use of "push" demand fulfillment "" the item is manufactured and stored in inventory before an explicit demand has been made. Lean thinking emphasizes using "Pull" demand to increase overall value to the organization.





>> Establish consistency and excellence across the organization "" As you start to optimize and streamline processes, remaining inefficiencies become more obvious. Then, the Lean approach encourages replicating these techniques throughout the organization, further optimizing risk and compliance processes.





Lean GRC helps to significantly reduce or eliminate waste and redundancy in risk and compliance activities. Eliminating redundant activities (such as some controls testing) results in reductions of wasted time, effort, cost, and delay. Centralization of risk and compliance information eliminates inconsistencies and wasted effort to maintain multiple copies of information, thereby greatly improving the timeliness and quality of information used to drive key risk-based executive decisions.




Lean GRC also improves the quality of risk information on which executive decisions are based. Improved information quality yields better decisions.




Lean principles are a fascinating -- and very important -- set of concepts. We'd love to hear of individual cases where you have used these basic ideas to improve the effectiveness of your own risk and compliance environment. Share them directly with other readers in the comments to this post, or visit the Contact Us page here on the blog to email us your stories.




Also, watch our blog in the coming weeks/months for more content and insights on how you can leverage lean strategies to streamline your GRC efforts.





*LeanGRC is a trademark of OCEG.


 

By: Sumner Blount
Sumner Blount has spent his 25-year career focused on the development and marketing of software products for a range of top-tier enterprise IT firms. Currently, he’s a Director in the Security business unit at CA. Previously he managed the large computer operating system development group at Digital...
Read More..

3 people have left comments:

[...] of Lean Thinking, and how these can be related to the area of GRC. (Check out my past posts here: The Four Main Principles of Lean GRC, Eliminating Waste, Focusing on Individuals Who Add Value, and Leveraging Pull Value)  This blog [...]

Posted by: Lean GRC: Establish Consistency and Excellence | CA on Governance, Risk and Compliance (GRC) | October 1, 2009 12:03 PM

[...] highlighting why it is important to focus on individuals who add value in your GRC process.In an earlier blog posting, I introduced the topic of Lean GRC, an area that has started to get some attention recently. To [...]

Posted by: Lean GRC: Focus on Individuals Who Add Value | CA on Governance, Risk and Compliance (GRC) | October 1, 2009 12:03 PM

[...] insights on applying one of the key Lean concepts - eliminating waste - to the discipline of GRC.An earlier blog post looked at the area of GRC and discussed some ways in which new efficiencies can be gained.   This [...]

Posted by: Lean GRC: Eliminating Waste | CA on Governance, Risk and Compliance (GRC) | October 1, 2009 12:03 PM

Leave a Comment

* An asterisk indicates a required field

* :  

:

* :  

 Submit