Understanding governance, risk and compliance information systems (GRC IS): The experts view

被引:34
|
作者
Papazafeiropoulou, Anastasia [1 ]
Spanaki, Konstantina [2 ]
机构
[1] Brunel Univ, Dept Comp Sci, St Johns Bldg, Uxbridge UB8 3PH, Middx, England
[2] Imperial Coll, Tanaka Bldg,South Kensigton Campus, London SW7 2AZ, England
基金
英国工程与自然科学研究理事会;
关键词
Governance; Risk and Compliance Information Systems (GRC IS); Enterprise Systems; System Aspects; FRAMEWORK; SOFTWARE;
D O I
10.1007/s10796-015-9572-3
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Although Governance, Risk and Compliance (GRC) is an emerging field of study within the information systems (IS) academic community, the concept behind the acronym has to still be demystified and further investigated. The study investigates GRC systems in depth by (a) reviewing the literature on existing GRC studies, and (b) presenting a field study on views about GRC application by professional experts. The aim of this exploratory study is to understand the aspects and the nature of the GRC system following an enterprise systems approach. The result of this study is a framework of particular GRC characteristics that need to be taken into consideration when these systems are put in place. This framework includes specific areas such as: goals and objectives, purpose of the system, key stakeholders, methodology and requirements prior to implementation, critical success factors and problems/barriers. Further discussion about the issues, the concerns and the diverse views on GRC would assist in developing an agenda for the future research on the GRC field.
引用
收藏
页码:1251 / 1263
页数:13
相关论文
共 50 条
  • [41] Using the governance risk and compliance model to ensure implementation of computerized systems that meets regulators expectations
    Franchetti, Joseph
    ABSTRACTS OF PAPERS OF THE AMERICAN CHEMICAL SOCIETY, 2017, 254
  • [42] Open Governance: A New Paradigm for Understanding Urban Governance in an Information Age
    Meijer, Albert Jacob
    Lips, Miriam
    Chen, Kaiping
    FRONTIERS IN SUSTAINABLE CITIES, 2019, 1
  • [43] A process model for integrated IT governance, risk, and compliance management
    Racz, Nicolas
    Weippl, Edgar
    Seufert, Andreas
    DATABASES AND INFORMATION SYSTEMS, 2010, : 155 - 169
  • [44] Information Security Governance - Compliance management vs operational management
    von Solms, SH
    COMPUTERS & SECURITY, 2005, 24 (06) : 443 - 447
  • [45] Information Systems for the Governance of Compliant Service Systems
    Dubois, Eric
    ADVANCED INFORMATION SYSTEMS ENGINEERING (CAISE 2014), 2014, 8484 : 1 - 11
  • [46] Corporate risk and corporate governance: another view
    Li, Hao
    Jahera, John, Jr.
    Yost, Keven
    MANAGERIAL FINANCE, 2013, 39 (03) : 204 - 227
  • [47] Experts' understanding of the public: knowledge control in a risk controversy
    Young, Nathan
    Matthews, Ralph
    PUBLIC UNDERSTANDING OF SCIENCE, 2007, 16 (02) : 123 - 144
  • [48] Corporate governance in practice: the role of practitioners' understanding in implementing compliance programs
    Stacchezzini, Riccardo
    Rossignoli, Francesca
    Corbella, Silvano
    ACCOUNTING AUDITING & ACCOUNTABILITY JOURNAL, 2020, 33 (04): : 887 - 911
  • [49] Understanding the influence of information systems competencies on process innovation: A resource-based view
    Tarafdar, Monideepa
    Gordon, Steven R.
    JOURNAL OF STRATEGIC INFORMATION SYSTEMS, 2007, 16 (04): : 353 - 392
  • [50] Understanding transnational information systems with supranational governance: A multi-level conflict management perspective
    Rukanova, Boriana
    Wigand, Rolf T.
    van Stijn, Eveline
    Tan, Yao-Hua
    GOVERNMENT INFORMATION QUARTERLY, 2015, 32 (02) : 182 - 197