26.04.2024
QKS Insight
The Impact of Regulatory Evolution on GRC Strategies
Author:
Sahil Dhamgaye

Regulations have long been a key driver of Governance, Risk, and Compliance (GRC) adoption. Since the inception of GRC, regulations like the Sarbanes-Oxley Act (SOX) of 2002 have significantly influenced its development. This act, introduced following accounting scandals at companies like Enron and WorldCom, aimed to protect investors from fraudulent accounting activities and mandated strict reforms to improve financial disclosures.
Early Development and Influence of Regulatory Changes:
Initially, GRC efforts focused heavily on SOX compliance, but over time, they expanded to address broader organizational efficiencies and risk management. Between 2002 and 2007, regulatory changes like the Basel II Accord began shaping the GRC landscape further, aiming to enhance risk management in the banking sector. However, Basel II faced criticism for its shortcomings, particularly highlighted by the financial crisis of 2008. This led to the development of Basel III, which aimed to address the deficiencies of its predecessors.
The period from 2008 to 2013 saw significant regulatory changes, including the Dodd-Frank Act of 2010, which introduced extensive reforms to improve financial regulation. This act required robust risk management and compliance frameworks.
Between 2014 and 2019, the regulatory landscape continued to evolve with the introduction of the General Data Protection Regulation (GDPR) by the European Union. GDPR set stringent guidelines for data protection and privacy, necessitating significant changes in GRC practices, particularly around data handling and third-party risk management.
Pandemic Influence and Modern Regulatory Drivers:
From 2020 to the present, the COVID-19 pandemic has further influenced GRC practices. The shift to remote work and increased cybersecurity threats required organizations to adapt their GRC strategies to address new risks. Additionally, regulations like the California Consumer Privacy Act (CCPA) and the European Union's Digital Operational Resilience Act (DORA) have introduced new requirements, emphasizing operational resilience and third-party risk management.
For much of its existence, GRC was often overlooked due to various factors. Initially, the absence of a solid Governance, Risk, and Compliance framework and ongoing crises, such as accounting scandals and financial downturns, diverted organizational focus toward compliance rather than realizing the benefits of GRC. Several factors contributed to the slow adoption of GRC:
1. Lack of Awareness: Organizations initially did not fully grasp how technology in the GRC space could streamline processes, improve efficiency, and reduce costs.
2. Legacy Systems: Many organizations relied on deeply ingrained legacy systems and manual processes, making the transition to technology-driven solutions challenging.
3. Risk Aversion: Fear of introducing new risks or compliance issues made organizations hesitant to adopt new technologies.
4. Cost Considerations: The high cost of implementing new technology solutions, especially for smaller organizations, often outweighed the perceived benefits.
5. Integration Challenges: The complexity and time required to integrate new technology with existing systems deterred many organizations from adopting GRC solutions.
Despite these challenges, GRC adoption received a significant boost in 2020. The COVID-19 pandemic and geopolitical events like the war in Ukraine underscored the need for reliable technology to support business continuity. The pandemic acted as a catalyst for significant changes in GRC practices:
1. Crisis Preparedness and Integration: The pandemic highlighted the importance of integrated GRC capabilities. Organizations with strong GRC systems were better equipped to handle global crises.
2. Technology Adoption: The shift from manual GRC methods to cloud-based technology accelerated digital transformation, facilitating clearer communication, easier access, and agile risk management.
3. Confidence in Crisis Planning: Integrated GRC systems enhanced crisis preparedness and workforce confidence. Many organizations invested in improving their crisis management capabilities, with some vendors offering specialized pandemic planning tools.
Additionally, regulatory complexity has arguably been the most influential factor in GRC adoption. Evolving regulations pose significant challenges for compliance but also drive organizations to enhance their resilience against risks. The changing regulatory landscape continuously pushes GRC professionals to develop more robust and adaptive frameworks.
Regulatory Evolution and Its Impact:
Regulatory frameworks are in a constant state of evolution, driven by changes in laws, regulations, and industry standards. Initially, the focus was on compliance regulations, but as technological advancements emerged, organizations increasingly needed to address regulations related to cyber-attacks and data breaches. These changes have spurred digital transformation in the market, making technology adoption crucial for effective GRC. The shift has also highlighted the rise of cloud-based solutions, automation, and analytics to enhance risk management and compliance. Moreover, the regulatory landscape has moved from inefficient siloed approaches to integrated systems that connect people, data, and processes, providing a holistic view of risks.
Several factors have influenced GRC adoption, including risk management, cost reduction, and the complexities of dynamic business environments. However, the continuously evolving regulatory landscape has been a major driver of GRC adoption. Since the inception of GRC practices and solutions, the following factors have contributed to their adoption:
1. Increased Regulatory Complexity: Regulations have become more complex and stringent, making it challenging for organizations to comply with multiple requirements simultaneously. This has created a need for integrated GRC solutions to manage and comply with these regulations efficiently.
2. Focus on Risk Management: With rising regulatory requirements related to risk management, organizations recognize the necessity for robust practices. GRC solutions have evolved to provide tools and frameworks for identifying, assessing, and mitigating risks across organizations.
3. Digital Transformation: The rise of digital technologies has led to new risks and compliance challenges. GRC solutions have incorporated features such as cybersecurity, data protection, and privacy management to address these challenges.
4. Globalization: The globalization of businesses has increased regulatory requirements related to cross-border operations. GRC solutions support organizations in managing compliance with international regulations and standards, such as GDPR, HIPAA, and ISO standards.
5. Focus on Accountability and Transparency: There is a growing emphasis on corporate accountability and transparency. GRC solutions help organizations improve governance practices and demonstrate compliance with regulations, thereby increasing trust from stakeholders.
Future Regulatory Trends in GRC:
The GRC market is poised for significant growth, driven by an increase in regulations targeting specific industry areas. Here are the key regulatory focuses anticipated to shape the future of GRC:
1. AI-Focused Regulations: The adoption of AI technologies has surged, prompting a regulatory focus on AI. The National Institute of Standards and Technology (NIST) released the AI Risk Management Framework (AI RMF 1.0) in January 2023. The European Union will enforce its first major AI regulations by May 2024. Countries like China, Canada, Brazil, South Korea, Singapore, the UK, and the UAE are also advancing AI-related regulations.
2. Cybersecurity-Focused Regulations: Cyber risk remains a significant threat, exacerbated by the accessibility of AI-based tools. In July 2023, the U.S. Securities and Exchange Commission (SEC) implemented mandatory Cybersecurity Rules. NIST released an update to its Cybersecurity Framework (NIST CSF 2.0) in February 2024. Other notable updates include Australia's Information Security Manual (ISM), the U.S. Department of Defense’s Cybersecurity Maturity Model Certification (CMMC), and the European Union’s Network and Information Systems 2 (NIS 2) Directive.
3. Operational Resilience-Focused Regulations: Operational resilience has gained importance due to global disruptions. The EU's Digital Operational Resilience Act (DORA) aims to strengthen ICT and digital risk management in the financial sector. Australia’s Prudential Regulation Authority (APRA) published the CPS 230 Operational Risk Management standard in July 2023 to ensure resilience against operational risks.
4. Data Privacy-Focused Regulations: Protecting Personally Identifiable Information (PII) is critical. The California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) have set new standards for consumer data protection. The UK’s Department for Science, Innovation, and Technology introduced amendments to data protection legislation in September 2023. Other significant regulations include the California Delete Act, the Payment Card Industry Data Security Standard (PCI DSS), ISO 27001's new amendment, and the Gramm-Leach-Bliley Act (GLBA).
5. Regulations Related to Fairness and Sustainability: Diversity, equality, inclusion (DEI), and sustainability are becoming regulatory priorities. In the U.S., 22 states adjusted their minimum wage in January 2024, with further changes anticipated from the Department of Labor. The European Parliament’s Corporate Sustainability Reporting Directive (CSRD) mandates comprehensive sustainability reporting, influencing investor and stakeholder decisions.
Conclusion:
The evolving regulatory landscape has consistently been a key driver for the adoption of GRC platforms and software. To stay competitive, organizations must prioritize compliance with contemporary regulations, which necessitates adapting to new requirements and integrating them into their GRC strategies.
For GRC vendors, enhancing offerings to focus on risk aversion, cost-effectiveness, and addressing integration challenges is crucial. By improving these aspects, vendors can attract more organizations that have not yet adopted GRC solutions, spreading awareness of the benefits of modern Governance, Risk, and Compliance platforms.
Both GRC vendors and user organizations should capitalize on the ongoing digital transformation, emphasizing the transition from outdated legacy systems to newer, technology-driven solutions. This shift can help industry trends favor modern GRC platforms.
However, the introduction of new regulations also presents challenges for GRC vendors. Effective implementation of these regulations is crucial. If executed correctly, these regulatory changes can drive the growth of GRC products and increase overall adoption rates. Proactively addressing these challenges and leveraging digital transformation can position GRC vendors and organizations for success in an evolving regulatory environment.
Author: Sahil Dhamgaye, Analyst at Quadrant Knowledge Solutions