Book Review: Mission-Critical Governance—Focusing on What Matters Most
I have argued for years that GRC is not ultimately about maintaining collections of risks, controls, policies, issues, audits, obligations, and assessments. All of these are important components of GRC, but none of them is the destination. Governance establishes direction and enables reliable decision-making. Risk management addresses uncertainty in achieving objectives. Compliance ensures that the organization acts with integrity in meeting its obligations and commitments while pursuing those objectives. What ultimately matters, then, is not the volume of governance activity an organization can demonstrate, but whether it can reliably make decisions, achieve objectives, address uncertainty, and act with integrity.
