Hi everyone. Following up on my earlier post about communicating the value of GRC to non-GRC stakeholders, I’m sharing a new resource: Vanta’s GRC Roles & Value Guide.
The guide is designed to help GRC professionals connect the work they do every day to the business outcomes their stakeholders care about.
TL;DR: Inside the guide:
Five common GRC roles: executive decision-maker, program owner, assessor, business stakeholder and task executor
Four business value levers: revenue enabled, risk reduced, time and cost returned, and trust demonstrated
Examples of how to translate GRC activity into operational and business outcomes
Guidance on choosing metrics that communicate impact, not just effort
“Say this, not that” examples for making GRC updates more meaningful
Sample updates for executives, program owners and functional leaders
A worksheet for preparing weekly, monthly and quarterly updates
Ways Vanta can help make GRC work more visible, provable and repeatable
A few takeaways I hope people get from it:
Completing GRC work is not the same as communicating its value.
Activity metrics are useful, but operational and business outcomes are what usually influence decisions.
The same GRC work should be translated differently for an executive, an Engineering leader, an auditor or an individual contributor.
A strong update should explain what changed, why it matters and what decision or support is needed.
This resource may be especially useful for:
GRC and security program managers
CISOs and security leaders
Control owners in HR, IT, Finance and Legal
Internal auditors, external auditors and MSPs
GRC contributors responsible for evidence, remediation and assessments
I’d love to hear from the community: What other resources would help you operate, mature or communicate the value of your GRC program?
For example, would resources on executive reporting, risk quantification, board communication, business cases for GRC investment, or communicating with control owners be useful?