Pillars of Risk Management Governance & Compliance

0
0
Hire Risk Expert
You agree to our Terms and Conditions of Use, PDPA & Privacy Policy and Cookies Policy

Pillars of Risk Management Governance & Compliance

GOVERNANCE & COMPLIANCE: WHO DECIDES, WHAT RULES APPLY, AND WHO MAKES SURE WE FOLLOW THROUGH?

GOVERNANCE & COMPLIANCE AS ONE OF THE PILLARS OF RISK MANAGEMENT

On the main Pillars of Risk Management page, we explained why Governance & Compliance remains alongside Technology Risk, Enterprise Risk Management, Cyber Risk, Operational Resilience, Business Continuity, Third-Party Risk, Risk Assessment and the Risk Register, even as this website expands into newer areas such as A.I. & Risk, Decision Making, Human Behaviour, Future of Work, Trust, The Science of Risk, The Future Human and Signals.

Governance & Compliance belongs among these foundations because almost every important business decision eventually brings us back to two deceptively simple questions: Who has the authority and responsibility to make this decision? And what rules, obligations or boundaries apply when we make it?

These questions are certainly not new. What is changing is the environment in which we are having to answer them.

A small business can now have employees working from home, customer information stored in the cloud, an outsourced accountant, an external payment provider, freelancers working in different countries and employees using A.I. tools that the business owner may never have personally approved. Very soon, what looks like a technology question becomes a governance question. What looks like an employee issue becomes a compliance question. What looks like an A.I. question can become all three.

For example, should employees be allowed to put company information into an A.I. tool? That may initially sound like an A.I. or Technology Risk question. But who decides which tools are permitted? What information may be entered? Who owns the decision? What rules apply to confidential or personal information? Who checks whether employees are following those rules?

This is where Governance & Compliance enters the picture.

The technology may be new. The need for authority, accountability, boundaries and oversight is not.


FIRST, WHAT IS GRC — AND IS GRC THE SAME AS RISK MANAGEMENT?

This is worth clearing up because GRC is frequently used as though it were another name for Risk Management. It isn't.

GRC stands for Governance, Risk and Compliance. The term emerged in the early 2000s and became particularly associated with OCEG's work on bringing these related organisational capabilities together rather than allowing them to operate in disconnected silos.

The important word here is together.

Governance, Risk Management and Compliance overlap, but they do different jobs. Governance is concerned with how authority, accountability, decision-making and oversight are organised. Risk Management helps us understand uncertainty and what could affect our objectives. Compliance concerns the obligations and boundaries within which we must, or sometimes choose to, operate.

So when experienced practitioners say “GRC is not the same as Risk Management,” they are right.

Risk Management is part of the broader GRC picture, but GRC is not merely Risk Management with two additional letters attached to it.

For someone coming to this subject for the first time, I think there is an easier way of remembering the distinction:

Governance asks: Who decides, and who is accountable?

Risk Management asks: What could affect what we are trying to achieve, and what should we do about it?

Compliance asks: What obligations and boundaries apply, and are we operating within them?

In real life, of course, these questions frequently arrive together.

Imagine a small business deciding whether to introduce an A.I. system. Risk Management might examine what could go wrong and what opportunities the technology creates. Governance determines who can approve the system, who owns its use and who remains accountable for its output. Compliance asks whether its use complies with applicable laws, contractual commitments, internal policies or other obligations.

One decision. Three different lenses.

That is much closer to what GRC was intended to achieve.


GOVERNANCE IS NOT SIMPLY “WHAT THE REGULATOR SAYS”

Governance is sometimes misunderstood as something imposed upon companies by regulators. That is too narrow.

Governance is essentially the system through which authority, decisions, responsibilities and accountability are organised.

Consider a business owned by two people. One owner believes either person can commit the company to a S$50,000 purchase. The other believes anything above S$10,000 requires both of them to agree.

There may be no regulator involved at all.

There is nevertheless a governance problem because nobody has clearly established who has authority to make the decision.

The same thing happens at much smaller levels. Can the manager issue a refund without asking the owner? Who can sign a supplier contract? Who can hire someone? Who can access payroll? Who decides whether employees may use a new A.I. application? What happens when the two people responsible for a business disagree?

These are governance questions.

Large organisations may answer them through boards, committees, delegated authorities, management structures and formal oversight arrangements. A small company may answer them with something considerably simpler. The scale changes. The underlying need for clarity over authority and accountability does not.

Regulators become particularly important in regulated industries because they may prescribe governance expectations, responsibilities or minimum standards. But they did not invent the underlying need for governance.

A two-person business needs governance.

A family business needs governance.

A partnership needs governance.

And increasingly, even a solopreneur needs to think about governance when authority is being delegated to employees, external service providers, automated systems or A.I. agents.


COMPLIANCE IS ALSO BIGGER THAN “COMPLYING WITH THE REGULATOR”

Compliance has a similar misunderstanding.

If I asked someone unfamiliar with Risk Management what Compliance means, a perfectly understandable answer might be: “Following the law and doing what the regulator says.”

That is certainly part of it. But it is not the whole picture.

A business may need to comply with legislation, regulations, licence conditions and regulatory requirements. It may also have obligations arising from contracts with customers, suppliers, landlords or business partners. Professional standards and industry codes may apply. The company itself may establish policies and standards that employees are expected to follow.

So the more useful question is not simply “What does the regulator require?”

It is:

“What obligations apply to what we are doing?”

For a small business, these questions can be extremely ordinary. Are we handling customer information appropriately? Are licences being renewed? Are employment obligations being met? Are contractual commitments being honoured? Are employees following the controls we established for confidential information?

Seen this way, Compliance is not an abstract department somewhere in a large financial institution. It is part of everyday business.


DOES GOVERNANCE & COMPLIANCE MEAN WE NEED LAWYERS?

Not necessarily.

Lawyers can be extremely important where legislation needs to be interpreted, contracts drafted, legal rights established or legal consequences understood. But Governance & Compliance is not another name for Legal.

Suppose a small company needs to decide whether refunds above S$2,000 require the owner's approval. That is primarily a governance and business-control decision. You do not necessarily need a lawyer to decide it.

If the company needs to understand whether a particular contractual clause is enforceable, that may require legal expertise.

Compliance often sits between these worlds. A lawyer may explain what a law or contractual provision means. Compliance professionals may then help translate relevant obligations into practical policies, procedures, controls, training and monitoring. Governance determines who owns the decision and who is accountable for ensuring the arrangements work.

In a small business, one person may perform several of these functions. That is perfectly possible.

The functions can overlap without the concepts becoming the same thing.


HOW GOVERNANCE & COMPLIANCE GREW FROM VERY ORDINARY BUSINESS PROBLEMS

Long before businesses talked about GRC frameworks, they had governance and compliance problems.

Someone had to decide who could handle money. Someone had to decide who could enter into agreements. Records had to be maintained. Responsibilities had to be divided. Rules had to be followed.

As businesses grew larger and society became more regulated, these arrangements became more formal. Approval authorities, boards, policies, procedures, codes of conduct, compliance functions, monitoring programmes and internal controls developed around problems that had existed for a very long time.

This is similar to what we have seen throughout the Pillars of Risk Management. The professional tools become more sophisticated, but underneath them we often find a very familiar human problem.

For Governance & Compliance, that problem can often be reduced to four questions:

Who decides? Who is responsible? What rules apply? How do we know they are being followed?


WHAT DOES GOVERNANCE & COMPLIANCE LOOK LIKE IN A SMALL BUSINESS?

A small business does not need to recreate the governance structure of a multinational company.

In fact, doing so would probably defeat the purpose.

What it needs is enough governance to remove dangerous ambiguity and enough compliance structure to avoid discovering important obligations only after they have been breached.

One of the simplest governance tools is an approval matrix or Delegation of Authority. It establishes who can approve what. Perhaps a manager can approve ordinary purchases up to a certain amount, while larger expenditure requires the owner's approval. Certain contracts may only be signed by a director. Refunds above an agreed amount might require a second check.

RACI matrix can be useful when responsibility is unclear. Who is Responsible? Who is Accountable? Who needs to be Consulted? Who merely needs to be Informed? A five-person company certainly does not need a RACI chart for everything it does, but for an important activity where everyone assumes somebody else owns it, the tool can be surprisingly useful.

Compliance can be equally practical. An obligations register can record important regulatory, legal, contractual or other requirements. A licence calendar can prevent renewals from being forgotten. Policies establish expectations. Procedures explain how something should actually be done. Training helps people understand what is required. Monitoring and control testing help determine whether what was supposed to happen actually happened.

The point is not to accumulate governance tools.

The point is to use the right tool to answer the problem in front of us.


THE THREE LINES MODEL: OLD TOOL, NEW PROBLEMS

The Three Lines Model is a good example of why I do not think established Risk Management tools should simply be thrown away because something newer has appeared.

For an experienced Risk Management practitioner, the Three Lines Model will already be familiar. Broadly, management owns and manages activities and risks; specialist functions can provide expertise, monitoring and challenge; and Internal Audit can provide independent assurance.

For a tiny business, creating three separate organisational “lines” would obviously make little sense.

But the thinking behind the model remains valuable: who owns the risk, who challenges or monitors it, and who independently tells us whether the arrangement is actually working?

Now apply that old question to A.I.

An employee creates an A.I. agent that performs an important business task. Who owns what the agent does? Who decides what information it may access? Who checks whether the controls are adequate? If the A.I. comes from an external vendor, where does the vendor's responsibility end and the company's responsibility begin? Who provides independent assurance if the use becomes sufficiently important?

Suddenly the Three Lines Model does not look quite so old.

The tool has not necessarily become obsolete.

The thing we are applying it to has changed.


HOW GOVERNANCE & COMPLIANCE CONNECTS WITH THE OTHER PILLARS

This is also where the interconnected structure of this website becomes important.

Enterprise Risk Management helps us see uncertainty across the business. Governance helps determine who owns those risks, who receives information about them and who decides whether the exposure is acceptable.

Technology Risk and Cyber Risk depend heavily upon governance. Who approves access to a system? Who can introduce new software? Who removes access when an employee leaves? Who responds when information is compromised? Technology controls are much weaker when ownership and accountability are unclear.

Operational Resilience and Business Continuity have the same dependency. A Business Continuity Plan can say what should happen, but someone still needs authority to activate it. Somebody must be able to approve emergency expenditure, communicate with customers, change normal procedures and make decisions while the business is under pressure.

COVID-19 made this particularly visible. Businesses were suddenly making decisions about remote work, access to systems, employee availability, customer communication, suppliers and workplace arrangements at extraordinary speed. A continuity plan mattered, but so did knowing who could actually make the decisions when the normal way of working disappeared.

Governance therefore runs quietly through many of the other Pillars.


THE WORLD CHANGED. GOVERNANCE HAD TO FOLLOW IT.

Governance & Compliance has traditionally been associated with policies, approvals, reporting, regulation and oversight. Those tools remain relevant, but the environment around them is changing rapidly.

Remote and hybrid work changed where decisions are made. Outsourcing moved important activities beyond the physical boundaries of the company. Cloud computing moved information and systems outside company premises. Platform businesses made small companies dependent upon organisations many times their size. Freelancing and flexible work changed who actually performs the work.

Consumer expectations changed too. People increasingly expect businesses to explain how their information is used, how important decisions are made and who is responsible when something goes wrong.

Then came A.I.

A.I. introduces something particularly interesting to governance because for perhaps the first time at scale, businesses are beginning to delegate parts of thinking, recommending, deciding and acting to technology.

That changes the governance question considerably.


WHAT HAPPENS TO GOVERNANCE WHEN A.I. STARTS MAKING DECISIONS?

Suppose an employee uses an A.I. tool to improve the wording of an email. The governance implications may be relatively modest.

Now suppose an A.I. system recommends which customer should receive a particular product, identifies suspicious transactions, screens job applicants, evaluates investments or provides advice that employees routinely accept.

Who owns the outcome?

Who approved the A.I.?

What information is it permitted to use?

When must a human review the output?

Who checks whether the system continues to behave appropriately?

What happens if the underlying model changes?

These questions take us directly into A.I. Governance, which we explore in greater depth under A.I. & Risk. But notice where many of the tools come from.

Ownership.

Approval.

Delegated authority.

Access control.

Oversight.

Monitoring.

Escalation.

Independent challenge.

These are not concepts invented for Generative A.I.

They are established Governance & Compliance concepts being applied to a new form of decision-making.


AGENTIC A.I. MAKES AN OLD GOVERNANCE QUESTION EVEN MORE INTERESTING

Agentic A.I. pushes this further because an A.I. system may increasingly be able not merely to recommend something but to act.

Imagine an A.I. tool that drafts an email for an employee. The employee reads it and presses Send.

Now imagine an A.I. agent that identifies the customer, decides what message should be sent and sends it automatically.

Something important has changed.

Authority has effectively been delegated to the system.

This means familiar governance tools may need to evolve. Delegation of Authority may eventually have to consider what an A.I. agent is authorised to do. Approval limits may become agent transaction limits. Segregation of duties may need to consider combinations of humans and machines. Access controls may need to determine not only which employee can access information, but which intelligent agent can access it and what that agent can subsequently do.

We may therefore begin seeing more use of agent permission frameworks, human approval gates, action limits, activity logs, override mechanisms and escalation rules.

Again, the technology is new.

But underneath it sits a very old governance problem:

How much authority should I delegate, and how do I remain accountable after I delegate it?


WHY HUMAN BEHAVIOUR STILL MATTERS

A company can have excellent policies and still have poor Governance & Compliance.

This happens because rules are implemented by people.

An employee may ignore a procedure because it takes too long. A manager may quietly encourage people to bypass a control because targets are difficult to meet. Employees may complete compulsory training without understanding why the requirement exists. Senior people may routinely behave in ways that contradict the organisation's written policies.

This is why Governance & Compliance connects directly to Human Behaviour.

If someone asks, “Why do my employees keep ignoring this procedure?”, the answer may not be another policy or another training course.

Perhaps the control is badly designed.

Perhaps the incentives are wrong.

Perhaps nobody understands why the control exists.

Perhaps management itself does not follow it.

Perhaps the business has created so much friction that employees have invented their own workaround.

The compliance problem may therefore also be a behavioural problem.

This is an important evolution in the toolkit. Instead of asking only “Did we write the rule?”, risk practitioners increasingly need to ask “What actually happens when real people encounter this rule in their everyday work?”


GOVERNANCE, COMPLIANCE AND TRUST ARE NOT THE SAME THING

Governance & Compliance also connects naturally to Trust, but the concepts should not be confused.

A company can comply with the minimum legal requirement and still behave in a way that customers consider unfair, opaque or irresponsible.

Likewise, good governance involves more than proving that nobody broke a rule. Accountability, transparency, consistency and the ability to explain important decisions all affect whether people trust an organisation.

Governance & Compliance therefore asks whether responsibilities, obligations and controls are appropriate.

Trust asks a more human question:

Do I believe you will use the authority you have responsibly?

This becomes particularly important as A.I. systems participate in decisions that customers or employees may not understand.


FROM PERIODIC COMPLIANCE TO CONTINUOUS GOVERNANCE

The Governance & Compliance toolkit is also becoming less static.

The traditional toolkit remains useful: policies, procedures, approval matrices, Delegation of Authority, RACI, compliance registers, declarations, attestations, training, control testing, breach registers, monitoring and the Three Lines Model.

But some tools are being adapted.

Regulatory registers can be supplemented by regulatory horizon scanning so that businesses can see what may be coming rather than responding only after a new requirement takes effect.

Manual approvals can become digital workflows with an audit trail showing who approved what and when.

Periodic compliance checks can increasingly be supported by continuous monitoring and automated alerts.

A.I. introduces additional tools such as A.I. inventories, use-case registers, A.I. risk classification, human-oversight frameworks and model or agent permission controls.

This is not necessarily a replacement of old Governance & Compliance.

It is an expansion of the toolkit to deal with a world that is more digital, distributed, automated and interconnected.


SIGNALS CAN HELP US SEE THE NEXT COMPLIANCE QUESTION COMING

There is another connection here with Signals.

Traditional Compliance often begins with a requirement that already exists. Regulatory horizon scanning asks an earlier question: What is changing that may become important to us?

A consultation paper, proposed law, emerging industry standard, court decision or changing public expectation may not require immediate action. But it may be worth watching.

The progression then becomes:

Notice the change → understand whether it may apply → assess the impact → establish ownership → change the relevant policy, process or control → communicate it → monitor whether it works.

This connects Governance & Compliance directly with Signals → Regulatory Change.

The objective is not to react to every headline.

It is to avoid discovering an important new obligation only when the deadline arrives.


GOVERNANCE & COMPLIANCE AS A FUTURE SKILL

This is one reason governance-related and compliance-related capabilities are becoming increasingly relevant to the future workforce.

SkillsFuture Singapore's Skills Demand for the Future Economy 2025 work identifies Ethics and Governance in the Digital Economy among its Priority Skills, while its sector work also highlights continuing demand for Digital Security & Governance capabilities.

I would be careful, however, about saying that SkillsFuture formally created one future skill called “Governance & Compliance” unless it uses those exact words. The more accurate conclusion is that governance-, ethics-, digital-security- and compliance-related capabilities are clearly becoming increasingly relevant as work becomes more digital and complex.

And it is not difficult to see why.

A.I. can perform more work, but somebody still needs to decide what it is allowed to do.

A business can outsource an activity, but accountability does not automatically disappear.

Employees can work remotely, but responsibilities and controls still need to function.

Technology can make decisions faster, but somebody still needs to decide which decisions should be automated.

Regulation can evolve, but somebody needs to understand what has changed and what the business should do about it.

Governance & Compliance is therefore becoming less about memorising rules and increasingly about knowing how to establish accountability, interpret obligations and design workable controls in a changing environment.


THE QUESTIONS PEOPLE ASK TODAY SOUND DIFFERENT

Few small-business owners wake up in the morning and type “Please explain a Governance, Risk and Compliance framework” into a search engine or A.I. assistant.

They ask the question created by the problem in front of them.

“Who is responsible if our A.I. gives a customer the wrong answer?”

That is partly A.I. Risk. It is also governance.

“Can I let an A.I. agent send emails or approve transactions without a person checking?”

That is Agentic A.I. It is also Delegation of Authority, access control and governance.

“We outsourced this activity. Are we still responsible if the vendor gets it wrong?”

That takes us from Governance & Compliance into Third-Party Risk.

“Why does nobody follow our procedures even though everyone completed the training?”

That begins in Compliance and leads us into Human Behaviour.

“How do I know which new regulations are going to affect my business?”

That connects Compliance with Signals → Regulatory Change.

“Who is accountable when a decision is partly made by a person and partly made by A.I.?”

That sounds like a very twenty-first-century question.

Yet underneath it is one of the oldest governance questions we have:

Who is responsible for the decision?


THE RULES MAY CHANGE. THE NEED FOR ACCOUNTABILITY DOES NOT.

Governance & Compliance can easily become associated with bureaucracy: more policies, more approvals, more forms and more people telling the business what it cannot do.

That would take us straight back to the “policewoman” problem described on our main Pillars of Risk Managementpage.

That is not what good Governance & Compliance should be.

Good governance should make it easier to understand who can decide, who owns the outcome, where authority begins and ends and how important decisions are overseen.

Good compliance should help us understand which obligations genuinely matter and how we can operate within them without constantly discovering requirements after something has already gone wrong.

Sometimes another policy is needed.

Sometimes the policy already exists and nobody follows it.

Sometimes responsibility is unclear.

Sometimes employees were never properly trained.

Sometimes the control is badly designed.

Sometimes the business has changed but the governance has not.

And sometimes a requirement simply has to be followed because the law, licence, contract or other binding obligation leaves no alternative.

The skill is recognising which problem we actually have.

As we move into A.I., autonomous agents, distributed workforces, external platforms and increasingly complex digital relationships, the language of Governance & Compliance will continue to evolve. The tools will evolve with it.

We may move from asking “Who is allowed to sign this cheque?” to “Should this A.I. agent be allowed to initiate this payment?”

But the underlying thought remains remarkably familiar:

Who has authority? What are the limits? Who remains accountable? What obligations apply? And how do we know that what we intended to happen is what actually happened?

That is why Governance & Compliance remains one of the Pillars of Risk Management.