Chris McClean serves Security & Risk Professionals. See the full Analyst bio.
Visit Forrester.com to learn how we make Security & Risk Professionals successful every day.
Avoid The Headlines, Focus On Corporate Culture
Posted by Chris McClean on May 23, 2012
- 320 Recommendations
- 0 comments
Guest post from Researcher Nick Hayes.
Chris and I recently published a report describing how to build risk and compliance principles into your company’s corporate culture. As we worked to finalize, edit, and publish the report, a flurry of new corporate scandals emerged, all related to this topic.
Here are just a few of them:
- Wal-Mart executives accused of trying to hush up bribery cases in Mexico (article here).
- A whistleblower accuses Infosys of engaging in a systematic practice of visa fraud (article here).
- A former Goldman Sachs employee writes an op-ed for the New York Times blasting the company’s ethics (article here).
- JP Morgan suffers a $2 billion trading loss due to “poorly monitored” trades (article here).
What’s the common theme? The financial, reputational, regulatory, and operational risks related to poor employee behavior are massive, and often overlooked.
To avoid seeing your company become the next on this list, make sure your strategy includes a focus on building the right corporate culture, one that’s based on sound compliance and risk management principles. This requires more than just implementing tighter internal controls and policies; it means getting your entire workforce to intuitively know how to act, even when no one is watching – it means influencing your workforce’s underlying assumptions.
You should work to infuse these principles into all corporate functions using a strong mix of policies, incentives, enforcement, and numerous communication channels; then reinforce all of these with a strong, consistent “tone-at-the-top.” The benefits extend beyond risk reduction. In fact, the most ethical companies tend to fare better in investor returns than the S&P 500.
Forrester identified five best practices critical to establishing the right risk and compliance culture; we recommend you take a look.
Best regards,
Nick
Categories:
search forrester's blogs
Secure the digital business future.
Attend Forrester’s Forum for Security & Risk Professionals EMEA, June 10-11, London UK
Analyst Blogs
- Andras Cser (30)
- Andrew Rose (17)
- Chris McClean (54)
- Christopher Sherman (1)
- Edward Ferrara (19)
- Eve Maler (19)
- Heidi Shey (9)
- John Kindervag (28)
- Khalid Kark (13)
- Laura Koetzle (2)
- Nick Hayes (5)
- Rick Holland (20)
- Stephanie Balaouras (50)
Top Categories
- GRC (21)
- Enterprise Risk Management (10)
- Governance Risk and Compliance (2)
- IT Risk Management (2)
- IT security (2)
- acquisitions (1)
- BC/DR (1)
- BT Resiliency (1)
- Business continuity (1)
- business technology resiliency (1)
- See all
Archives
- March 2013 (1)
- February 2013 (1)
- November 2012 (1)
- May 2012 (2)
- March 2012 (1)
- November 2011 (1)
- October 2011 (1)
- September 2011 (1)
- May 2011 (1)
- February 2011 (2)
- January 2011 (1)
- December 2010 (1)
- November 2010 (1)
- See all