IT Governance, Risk, Architecture & Compliance
In order to build businesses that are legislatively compliant, commercially reliable and sustainable, organisations need to develop skills that satisfy both business and IT perspectives.
Governance, Risk Management, and Compliance as a skill set reflects the need for organisations to adopt an integrated approach to these three vital areas of business operations. The term embraces a number of related activities within an organisation, e.g. internal audit, compliance programs like Sarbanes Oxley (SOX), enterprise risk management (ERM), operational risk, financial risk, IT Governance, incident management, etc.
However, it is increasingly evident that Governance, Risk Management and Compliance is only meaningful in the context of an Enterprise Architecture, within which the relevant activities and assets of the organisation are situated, defined and inter-related.
It is also important for organisations to consider frameworks such as TOGAF, which provide guidance on the Architecture process.