Author

Irfan Rehmat FCCA is an internal auditor with experience in the Middle East and Pakistan

The days when regulatory compliance in public sector organisations is seen as merely an administrative burden or a task to be fulfilled are over. Governance, risk and compliance (GRC) can no longer be viewed as separate disciplines.

The evolution of integrated GRC, which brings together governance, risk management and compliance into a single system with shared data and processes, has emerged steadily but relentlessly as businesses recognised the inefficiencies in managing each element as a separate function. In the public sector, the transition has proceeded more sedately.

Welcome development

Integrated GRC must be seen as a welcome development. The increasing use of AI by cybercriminals and other bad actors means that cyberattacks are more frequent and sophisticated, and weak points in both the private and public sectors can be exploited much more easily. Strong and effective GRC frameworks have never been more important.

Quality of governance is considered a strategic imperative for public sector organisations

For the public sector, strong GRC is an imperative as organisations increasingly operate in complicated environments, facing evolving regulations, increasing public expectations, and rising scrutiny over accountability and transparency. Governments and state-owned enterprises are required not just to follow laws and regulations, but also to show effective governance, strong risk management and efficient use of public resources.

When GRC in public sector organisations operates in silos, the result is inconsistent information as well as inefficiencies. Leadership does not have access to a cohesive picture of risk and compliance across the organisation, or the comprehensive information they need to make informed strategic decisions.

In today's environment, quality of governance is considered a strategic imperative for public sector organisations. Integrated GRC can bring significant benefits, most importantly a clearer view of compliance and risk across the entire organisation. Other benefits include:

  • greater public trust
  • improved resilience
  • better-quality decision-making
  • less fraud
  • improved perception among stakeholders
  • increased ability to adapt and change
Beyond regulation

But implementing an integrated GRC approach is far more complex than merging three teams into one; data needs to be pooled, activities coordinated and reporting aligned to provide a cohesive, coherent view.

Risk management links governance goals with regulatory requirements

A regulatory framework alone does not ensure proper governance; good practices ensure that regulatory obligations are integrated into the strategy and day-to-day activities of the organisation. So, for example, procurement regulations do not only assure legal compliance but also uphold the governance issues of fairness, honesty, cost-effectiveness and fraud prevention.

Risk management, in turn, links governance goals with regulatory requirements. For many public sector organisations, the legal, reputational and financial implications of non-compliance mean it is one of their biggest risks.

Linking the regulatory framework with enterprise risk management (ERM) allows an organisation to identify risks in regulatory compliance early on, categorise compliance needs by risk, allocate resources appropriately and strengthen organisational resilience.

Implementation hurdles

There are, though, hurdles to successful implementation of an integrated GRC approach in the public sector, including:

Fragmented regulatory requirements. Different regulators may have overlapped and contradicting regulations, which may lead to unnecessary work and costs.

Compliance-centric culture. Organisations may focus solely on passing an inspection, rather than establishing sustainable good governance practices.

Limited risk maturity. Many public sector organisations lack a robust ERM framework.

Evolving regulations. Regulations governing the public sector, notably around cybersecurity and environmental, social and governance requirements, are rapidly changing.

Staff and budget constraints. Lack of resources and limited staffing may hinder governance and compliance initiatives.

Strong pillars

Integrated GRC platforms are gaining popularity among public sector organisations for real-time risk and compliance reporting. Technology can provide support in monitoring and managing governance and compliance through continuous auditing, automated compliance monitoring, risk reports, analysis of exceptions and prediction of risk factors.

But implementing an integrated GRC approach in a public sector organisation is about more than introducing more technology. Integrated GRC needs strong supporting pillars.

Integrated GRC needs enhanced control systems that set the ethical tone

Most significantly, integrated GRC needs enhanced control systems that set the ethical tone, a culture of accountability and a clear enforcement route. An effective framework, such as that of the Committee of Sponsoring Organizations of the Treadway Commission (COSO), sets the structure and principles for an integrated GRC platform.

Risk-based compliance monitoring is also essential. Public procurement, cybersecurity, financial reporting, third-party management, data privacy and asset management are all key areas of risk, and compliance activities should be performed based on the level of risk posed to the organisation.

Finally, integrated GRC demands a culture of governance. Effective governance depends heavily on an organisation’s internal culture and values. Leaders have the responsibility to promote ethical principles, accountability, transparent systems and methods of working, awareness of risks and continuous improvement.

Critical function

GRC has emerged from the back office to become a critical strategic function that has a direct impact on an organisation’s resilience, reputation and success.

Integrated GRC brings greater accountability and resilience to public sector organisations, and transparency and added value for citizens and stakeholders. This is the next challenge for public sector leaders: to establish governance systems that focus on creating excellent organisations.

Advertisement