Can You Really Automate GRC?
There is one big reason for doing it — cost containment. And there is no shortage of vendors hoping to help organizations automate GRC (governance, risk, compliance) through IT. Oracle, Agiliance, and Lumigent are three I have bumped into lately, but there are many more.
Gartner has a Magic Quadrant report on enterprise GRC that lists a dozen or more vendors. Forrester Research and AMR Research, too, cover the automated GRC market extensively. Various recent analyst reports are listed here.
Gartner divides these products between GRCM products (defined as the automation of the management, measurement, remediation, and reporting of controls and risks against objectives, and in accordance with rules, regulations, standards, and policies for the oversight and operation of risk management and compliance programs — a mouthful, for sure) and other GRC products for the automation and monitoring of controls. more








