Skip to content
ArtimIS Logo
  • Home
  • Our offers
    • GRC Strategy & Innovation
      • Ensuring a frame of reference
      • Maturity assessment
      • Choosing the appropriate grc tool
      • Why artimis
    • Compliance Advisory
      • SOx – LSF
      • SAPIN II
      • GDPR
      • Why artimis
    • Internal Audit & Internal Control Support
      • Internal Audit
      • Internal Control
      • Why artimis
    • Access Governance Advisory
      • SoD Governance & Support
      • Identity & Access Governance Advisory & Support
      • Authorization Security & Support
      • Why artimis
    • GRC Application Implementation & Services
      • Implementation Services
      • Audit and Project Management
      • Change Management
      • Why artimis
    • Cybersecurity & Data Protection Services
      • Patch Management
      • Federation of Identities
      • Data access & protection
      • Supervision & monitoring
      • Why artimis
  • Career
  • Contact
  • Blog
  • Français
  • Home
  • Our offers
    • GRC Strategy & Innovation
      • Ensuring a frame of reference
      • Maturity assessment
      • Choosing the appropriate grc tool
      • Why artimis
    • Compliance Advisory
      • SOx – LSF
      • SAPIN II
      • GDPR
      • Why artimis
    • Internal Audit & Internal Control Support
      • Internal Audit
      • Internal Control
      • Why artimis
    • Access Governance Advisory
      • SoD Governance & Support
      • Identity & Access Governance Advisory & Support
      • Authorization Security & Support
      • Why artimis
    • GRC Application Implementation & Services
      • Implementation Services
      • Audit and Project Management
      • Change Management
      • Why artimis
    • Cybersecurity & Data Protection Services
      • Patch Management
      • Federation of Identities
      • Data access & protection
      • Supervision & monitoring
      • Why artimis
  • Career
  • Contact
  • Blog
  • Français
  • Home
  • Our offers
    • GRC Strategy & Innovation
      • Ensuring a frame of reference
      • Maturity assessment
      • Choosing the appropriate grc tool
      • Why artimis
    • Compliance Advisory
      • SOx – LSF
      • SAPIN II
      • GDPR
      • Why artimis
    • Internal Audit & Internal Control Support
      • Internal Audit
      • Internal Control
      • Why artimis
    • Access Governance Advisory
      • SoD Governance & Support
      • Identity & Access Governance Advisory & Support
      • Authorization Security & Support
      • Why artimis
    • GRC Application Implementation & Services
      • Implementation Services
      • Audit and Project Management
      • Change Management
      • Why artimis
    • Cybersecurity & Data Protection Services
      • Patch Management
      • Federation of Identities
      • Data access & protection
      • Supervision & monitoring
      • Why artimis
  • Career
  • Contact
  • Blog
  • Français
Loading...
  • GRC STRATEGY AND INNOVATION

    Ensure transformation, Performance and Serenity of your business

  1. Home
  2. Our offers
  3. GRC Strategy & Innovation
GRC Strategy & InnovationMoncef Sifane2021-04-29T17:10:20+02:00
  • Introduction

  • Ensuring a frame of reference

  • Maturity assessment

  • Which GRC Tool?

  • Why ArtimIS

  • Introduction

Introduction

GOVERNANCE

RISKS

COMPLIANCE

Pressure from regulators, external auditors, investors, and other stakeholders oblige companies to invest in GRC programs. For optimization purposes, they want to use technology levers to produce real-time compliance status reports.

Defining a sustainable GRC program requires the definition of new roles and responsibilities or the creation of new departments such as Internal Control. Therefore, the support of GRC experts combining technical and functional knowledge in addition to a certain appetence for ERPs on the market is more than recommended.

The ArtimIS team is made up of certified GRC experts and business experts (internal control, financial compliance) with proven experience in implementing internal control frameworks and controlling information systems. The seniority of the team allows us to provide high quality services. Our background allows us to offer our clients a relevant diagnosis of all processes, risks, and associated governance to help them develop an appropriate GRC strategy.

When you are interested in integrated and transversal risk management within your organization, it is important to understand the objectives and benefits of such a program.

The main objectives are:

The value and benefits are:

  • Strengthen risk awareness and collaborate around the internal control system,
  • Ensure continuous monitoring and reporting of controls on key processes

  • Improve the corporate culture around Governance Risk and Compliance topics

  • Improve market reputation by reassuring investors and third parties with whom the company collaborates

  • Prevent, detect, and reduce company-wide weaknesses & threats

  • Improve the responsiveness and efficiency of business processes to achieve its strategic objectives while optimizing ROI

  • Supporting company transformation through proactive risk management

  • Inspire and motivate its collaborators to the extent that the company conducts its activities in an ethical and appropriate way

  • Reduce the risk of human and operational error, data leakage, fraud, and compliance risks

  • Guarantee the transparency of published financial data, to ensure compliance with the various regulations

  • Guarantee the quality of “Risk” data and efficient reporting at all levels (Internal Audit / Internal Control / Operations)

  • Provide management and executive committees with real-time information to enable effective and pragmatic decision-making

  • Ensuring a frame of reference

Ensuring a frame of reference

In order to support its clients in the implementation of a GRC program, ArtimIS generally uses a reference framework combining good risk management and internal control practices (AMF, COSO 2 & ISO 31000/2009 RM) with the specificities and the user experience of business solutions (ERP: SAP S4 HANA / Oracle or other specific applications).

Before launching into the definition and implementation of a GRC Program, it is important to define the governance, i.e. to define the organization, the sponsors, the key actors of the project, the contributors, but also to identify the processes to be covered in priority.

ArtimIS experts assist their clients in identifying the players needed for each line of defense:

First line of defense

Finance

Administrative and Financial Management

Controlling

Accounting

–

Line of business

BU Managers

Employees

Human Resources

–

Other GRC roles

Purchasing

Quality

Legal

EHS

Second line of defense

Risk Management

Sector risks

Operational risks

Process risks

Project risks

Internal control

Internal control over reporting

IT Controls

Operational Controls

Risks and IT security

Information security

Information compliance

IT Governance

–

Ethics and compliance

Ethics & Compliance

Fraud Investigators

Management of procedures

–

Third line of defense

Internal Auditing

Financial auditing

IT Audit

Operational audit

Third party audit

Once the governance is defined (Organization, People, Processes, Applications, …) we need now to evaluate, define and implement the risk management and internal control system.

To do so, we can rely on the ISO 31000/2009 RM reference framework below:

 

————- Governance & Organization ————

Risk Assessment

Risks Culture

Posture, register & risk treatment

Program Definition and Implementation

Risk Anthology

Risk hierarchy and segmentation

Risk methodology

Program Review and Optimization

Notification, Reporting and Incident Feedback

Crisis Management Unit/cell

————- Risk Classification & Reporting ————

Risk Assessment

Risk and Threat Mapping, Data and Systems Combination

Impact and probability assessment

Program Definition and Implementation

Strategic Risk Alignment

Awareness of regulations, standards, and other internal rules

Program Review and Optimization

Risk Mitigation / Compensation

Risk and metrics reporting

————- Associated processes ————

Risk Assessment

Evaluation of the level of Maturity
Gap Analysis (Current/desired level)
Definition of strategy and roadmap
Evaluation of the level of readability of risk management and compliance initiatives (Context/ID/Objectives/Evaluations/Treatments)

Program Definition and Implementation

Review of processes/sub-processes & mapping
KPI/KRI/KCI Association
Policy, international and internal guidelines & controls library
Harmonization of the control environment

Program Review and Optimization

Communication & Change Management
Training & Sensibilization
SWOT analysis
Forum & Community
Continuous improvement of skills, added value and ROI

————- Applicative Technology & GRC Platform ————

Risk Assessment

Business Cases
PoC
RFI/RFP Process

Program Definition and Implementation

Application and system architecture definition
Phased implementation

Program Review and Optimization

Configuration and performance review
Development & fine-tunning

  • Maturity assessment

Maturity Assessment

Risk management and compliance efforts are intended to use application technologies and GRC platforms as a lever to:

  • Optimize the internal control system,

  • improve process performance,

  • and reduce the costs associated with compliance tasks through automation of controls, among other things.

However, before you can imagine supporting your risk management and internal control system with a GRC platform, you must first consider the level of maturity of your system.

ArtimIS proposes to its prospects and clients to set to music an assessment of the maturity level in “self-assessment” mode to define the most appropriate trajectory:

Functional Grade

Maturité Description
Level 1 Ad-Hoc/risk management and internal control is not formalized and not present. The organization is content simply to position representatives in silos isolated from it. However, an annual control is ensured by external audits to detect and remedy critical risks over the following year.
Level 2 Fragmented/Risk management and internal control is decentralized and disparate. Consequently, there is a lack of communication and consolidation of information between the various departments and management. Also, activities are based on office automation tools. However, a periodic control is carried out by a so-called independent entity, the internal audit (the third line of defense) within the organization itself to cover the most critical risks in a detective manner.
Level 3 Managed/Risk management and internal control is carried out within a department (a second line of defense is created) which centralizes and coordinates all activities by relying on a network (the first line of defense).
Level 4 Integrated/Risk management and internal control is fully integrated and covers all the organization’s processes. Stakeholders, sponsors, and the organization are clearly defined, documented and lively. In addition, there is a continuous control system in place to proactively prevent risks and to measure the effectiveness of the exercise of control. The coordination of the three lines of defense is centralized but remains more focused on compliance and critical risk management.
Level 5 Agile/Risk Management and Internal Control has evolved into a framework where every employee understands and undertakes the achievement of risk management objectives. In addition, GRC activities are aligned with corporate strategy. There is a real federation of risks via a shared service center that operates in complete autonomy and whose actions are relevant and only amplify the performance of the processes.

Technological Grade

Maturity Description
Level 1 Ad-Hoc/Oral Voice
Level 2 Office Tools
Level 3 ERP-Office Tools and Data Analysis Solutions
Level 4 GRC platform integrated with ERP and other applications
Level 5 GRC platform integrated with ERPs and other applications by adding an advanced technology layer (Robots, CCM, Process Mining or ML to go
  • Which GRC Tool?

Which GRC Tool?

Our clients are continually seeking to improve their level of maturity and are therefore more and more questioning their options in terms of offering GRC platforms.

How to proceed, where to start?

As the tools of the GRC market are constantly evolving, we attach importance to innovation and technology watch to respond pertinently to the requirements of our clients and in an agnostic manner.

We also keep ourselves systematically informed about business and regulatory developments to offer appropriate support.

Thus, ArtimIS teams support its clients in the development of business cases to guide and refine the choice of the GRC solution

GRC for Enterprise

Ability to manage an integrated architecture across multiple GRC domains through a structured architecture and a process-covered information technology strategy

Audit Management

Ability to manage audit planning, human resources, documentation, execution and fieldwork, observations, reporting and analysis

–

Automation of Controls

Ability to automate the detection and application of internal controls over business processes, systems, records, transactions, documents, and information

–

Compliance Management

Ability to manage a global compliance program, manage change, assess compliance, remediate non-compliance, and report alerts

Internal Control Management

Ability to manage, define, document, map, monitor, test, evaluate, and report on the organization’s set of internal controls

–

IT Management

Ability to govern IT in the context of business objectives and to manage IT processes, technology, risk, and information compliance

Problem Management

Ability to report problems and incidents by managing, documenting, resolving, and reporting complaints, problems, incidents, events, and investigations

Risk Management

Ability to identify, assess, measure, address, manage, monitor, and report on risks to objectives, divisions, departments, processes, assets, and projects

Third-party Management

Ability to govern, manage and monitor all the company’s third-party relationships, particularly the risks and compliance issues that these relationships create.

In relation to the different functionalities desired and the context of our customers, we evaluate the solutions under different Axes, here are some examples (Licensing Model & durability of the editor, Technical-functional skills on the FR and EU market*, Time vs. Cost of implementation, Functional coverage by application module, Ergonomics of the solution, Architecture & Security of the solution (Code, Access, Data, …)

In addition to the proven experience of our consultants, these studies are inspired by the best methods (PRINCE2) and research firm (Gartner / Forrester / IDC study) while being adapted to the context of our customers to offer them an agile and pragmatic choice support process.

  • Why ArtimIS

Why ArtimIS?

GRC expertise

  • Seniority of Consultants & Certifications to the key,
  • 15 years of experience in GRC and on different application environments: SAP, Oracle & Workday
  • Strong proximity and good understanding of the challenges of the different executive members (Finance, Internal Audit, Internal Control, Compliance & IT)

Pragmatism

  • Pragmatic, agile, and aligned approach to the implementation strategy of market standards (COSO 2 & ISO 31000/2009 RM)
  • Proven experience in GRC program management and change management (communication, video, game challenge, training, …),

Complementarity

  • Proposition of a complete team combining Business (Internal Control & SOx) and Technical expertise on ERPs: SAP (ECC / S4 Hana / Ariba / Fiori) and Oracle (eOBS/Fusion/JDE/NetSuite/PeopleSoft)
  • Proposition of GRC technical experts on SAP GRC (Access Control, Process Control, Risk Management), Oracle RMC (with Selected Partner for GRC Go to Market strategy), Galvanize (ControlBond, AuditBond, ComplianceBond, RiskBond, …)

Sustainability

  • Competitive service costs compared to large Audit and Consulting firms
  • Highly advantageous GRC technical implementation and support service costs thanks to our nearshoring/offshoring approach
  • 60% of our revenue comes from loyal customers and 40% from new customers who trust us and whom we will retain

Our expertise and constant technological watch enable us to support our clients daily in their risk governance and compliance objectives.

Through ArtimIS, they have improved their maturity around the risk culture in the enterprise, they become able to detect and prevent threats through reinforced lines of defense. Finally, they have the tools that best meet their needs, their processes and, of course, their organizational or budgetary constraints.

Arnott Hales, Partner at ArtimIS

© Copyright

2019 – 2023 ArtimIS

Politique de confidentialité

https://www.artimis.fr/politique-de-confidentialite/

Contact

11 rue des Halles, 75001 Paris

Phone number: +33984380455

Email: contact@artimis.fr

LinkedIn: Artimis SAS

 

Page load link
Nous utilisons des cookies pour vous garantir la meilleure expérience sur notre site web. Si vous continuez à utiliser ce site, nous supposerons que vous en êtes satisfait.OkNonPolitique de confidentialité
Go to Top