More data, more regulations and more parallel initiatives – yet it is becoming increasingly difficult to see what actually matters. When GRC work grows without a shared direction, prioritisation becomes harder and progress can quickly stall. We look at why this happens – and what can bring the different parts back together.
Despite significant investments in GRC, many organisations find that their work gets stuck. The problem is rarely a lack of ambition. More often, there is no shared direction. Different parts of the organisation work from different views of risk, use different approaches and try to solve different problems.
Here are five common reasons GRC work loses momentum – and what your organisation can do to move forward. The symptoms are often the same:
- Difficulty prioritising between different risks.
- Unclear ownership and inconsistent ways of working.
- Ever-increasing amounts of data to manage.
- Parallel initiatives that rarely connect.
- GRC work that takes a lot of time but creates limited value.
1. GRC work stalls when the organisation has different views of risk
Business teams, security, compliance and management often work from their own perspectives and priorities. This makes it difficult to create a shared understanding. As a result, resources are directed towards different areas, making it harder for the organisation to determine what matters most.
A first step is therefore to establish a shared understanding of which risks matter most and why. This requires looking beyond individual regulations and functions. What could actually affect the organisation? Which risks could prevent it from achieving its goals?
When more people share the same view of risk, it becomes easier to make decisions together, prioritise the right actions and create a more connected approach to GRC.
2. GRC work stalls when ways of working vary too much
It is easy to assume that the entire organisation works in the same way. In practice, this is rarely the case. Business teams, security, compliance and management often have different starting points, ways of working and challenges they are trying to solve.
This creates variation that makes governance more difficult. The same control may be carried out in different ways, and the same requirement may be interpreted differently depending on where it is handled in the organisation.
A common mistake is to address this by adding more rules and documentation. A better approach is to establish shared ways of working and a common structure, while still allowing teams to adapt execution to their own circumstances.
It is also important to recognise that different parts of the organisation may be at different levels of maturity. Everyone does not need to work in exactly the same way from day one. What matters is creating a common foundation to build on.
When more people work from the same foundation, it becomes easier to compare results, share experiences and develop GRC work over time.
3. GRC work stalls when you lose the overview
The challenge is rarely a lack of data. More often, it is knowing which information is actually relevant and how it should be used. Otherwise, too much time is spent on administration and reporting, while analysis and follow-up receive less attention.
One way forward is to start with the needs of the organisation. What information is needed to understand risks and make the right decisions? Which information is actually used, and which is collected simply out of habit?
It is also important to regularly review which data is genuinely being put to use. If information is collected without contributing to decisions, it risks becoming yet another administrative burden.
By prioritising the right information, organisations can make better decisions, improve follow-up and use GRC to provide stronger support for the business.
4. GRC work stalls when every requirement is handled separately
It is common to introduce new controls and ways of working every time a new regulation or customer requirement appears. Over time, the number of processes grows, while the same information is requested in multiple places.
This easily leads to duplicated work. Different functions end up working on similar issues without benefiting from each other’s efforts.
A more sustainable approach is to start with what is already in place. Many controls can address several needs at the same time. By reusing controls, information and processes, organisations can reduce administration and spend more time managing the risks that really matter.
5. GRC work stalls when the purpose becomes unclear
Many organisations agree on what needs to be done. Fewer agree on why. Regulatory requirements, customer requirements, audits and internal needs can easily become separate initiatives with their own objectives and ways of working.
When the purpose is unclear, prioritisation also becomes difficult. Should the organisation focus on meeting an individual requirement or on building long-term resilience? Should the focus be on reporting or on strengthening the business?
That is why it is important to regularly return to the fundamental question: What is the purpose of our GRC work? What value should it create for the organisation?
When more people share the same objectives, it becomes easier to make decisions, set the right priorities and build an approach where governance, risk and compliance reinforce one another.
Governance that connects the bigger picture
Much of what is needed is often already in place. Risk assessments, controls, policies and processes already exist. The challenge is that they have often been developed at different times and for different purposes.
This is why GRC work can lose momentum. Not because too little is being done, but because different parts of the organisation are not moving in the same direction.
A first step is to create a shared direction. This does not mean starting again from scratch. Often, it is about building on what already works, creating a common understanding of risk and reusing controls and information wherever possible.
Five questions to ask your organisation
- Do we share a common view of our most important risks?
- Do different parts of the organisation work in the same way?
- Are we collecting the right information – or simply more data?
- Can the same control be used for several purposes?
- Do we agree on why we are doing our GRC work?
When governance, risk and compliance are connected, it also becomes easier to meet new requirements without creating new parallel processes. This allows GRC to move from being an administrative exercise to supporting better decisions and a more resilient organisation. That is when the work gains a shared direction.