When surrounded by risk, GRC automation can help

Within corporate environments, accountants are essential team members when it comes to governance, risk and compliance, especially during the pandemic.

Unpredictable, chaotic, challenging — these are our favorite go-to words to describe today’s environment. Many of us hope that we’ll wake up and find that this was all a movie. In the opening scene, we have the pandemic villain. In the very next, we have the everyday heroes who never planned to be — nurses, grocers and delivery workers. Both visible and behind the scenes, these heroes give us confidence that we can reach a happy ending, just as we have in other crises.

One of the unsung heroes of the past six months has been accountants. Accountants played (and continue to play) a critical role in promoting the public interest and serving as trusted advisors. From audits, taxes and advisory services to strategy and helping with the Paycheck Protection Program, accountants were deemed essential and have worked around the clock to provide guidance and assistance with shifting regulations and due dates.

CORONAVIRUS IMPACT: ADDITIONAL COVERAGE
Langolis McGee Leonhardt.png

Sasha Leonhardt and Jon Langlois are partners and David McGee is a law clerk at Buckley LLP where they represent bank and nonbank mortgage originators, mortgage servicers, and secondary market purchasers in regulatory compliance, transactional, and enforcement matters.

Jeff is the Chief Innovation Officer at Transcarent, leading our efforts to design novel products and partnerships supporting our end-to-end Member support services. His interests span from furthering evidence-based health initiatives to innovative opportunities that deliver trusted, simple, seamless and connected solutions that drive value for our clients, Members and the providers themselves.

Prior to joining Transcarent, Jeff was the Health Strategy and Innovation Leader at Mercer Consulting. He was the Chief Medical Officer at One Medical, designing their innovative model of care and was responsible for the company’s B2B strategy. Jeff has also served as the Chief Medical Officer at RedBrick health where he was responsible for the company’s clinical programs (wellbeing, disease management, medication therapy management). Jeff led design, development and ongoing operations of the clinical and coaching programs as well as leading outcomes research for a range of population health programs.

Previously, he was a partner at Willis Towers Watson, where he was responsible for employer based health management programs, employer-provider contracting and onsite/near site clinics. He has operated a national group of 58 primary care medical practices, was Chief Medical Officer of an early ACO management firm and was an analyst at a hedge fund.

Jeff is a board-certified internist and rheumatologist and an Associate Professor at NYU School of Medicine.

Stephen Graziano is the director of channel sales at Flimp Communications. Prior to joining Flimp, Stephen spent most of his career working in the insurance consulting space, specifically in the voluntary insurance and benefits communication arenas. He is passionate about helping employees and employers have a better experience with their benefits through better understanding, higher engagement, and cost savings for both parties.

Within corporate environments, accountants are also essential team members when it comes to governance, risk and compliance (GRC), as they ensure that the business’s strategies and goals are in alignment, risks are identified and addressed, and the business complies with laws and regulations. GRC is always a key responsibility, but it’s even more critical when processes could be compromised due to factors outside of an organization’s control — for instance, an unplanned move from a physical to virtual workplace in only a few days.

Recent events have shown us that organizations already using cloud-based technology were in a much better position than those that were not, and the pandemic environment has magnified the vulnerabilities associated with reliance on manual processes and disparate systems. In particular, moving from a single physical environment to one spread across multiple virtual locations without adequate security and safeguards in place has introduced unexpected risks that are not yet fully realized. This is one of the many reasons why it’s time to re-imagine the ideas we used to think would never work, including how and when technology can be leveraged to improve the GRC function.

GRC in a pre-COVID-19 environment was already complex with many moving parts. Add in a sudden shift to virtual business processes and now there are even bigger potential fires around every corner. But that doesn’t mean you get a pass. Decision-makers expect information that is reliable; regulators require compliance and reasonable assurance that financial reports are materially accurate; the public needs insight to make informed investment decisions. On top of these business-as-usual expectations, the complexity of COVID means that GRC teams must be able to assess new risks, comply with changing regulations and revise governance processes, while balancing speed, relevance and accuracy.

Implementing technology that can automate, predict and adjust compliance processes makes these expectations more manageable. Technology solutions that leverage artificial intelligence and machine learning also make it possible to segregate duties, undergo internal audit assessments, model risk, and analyze errors and policy violations so that risk is decreased and control is back in the hands of the finance team.

Advertisement

The light at the end of the tunnel seems distant, but for all its pain, suffering and disappointments, COVID did help us make lemonade out of lemons. For instance, in a recent conversation with business leaders, I learned that transformation plans are expected to accelerate (not slow down) due to the pandemic, paths forward are being re-imagined, and technology projects now have a greater sense of urgency. In the past, a failed technology implementation was so daunting that many leaders would not risk having a failure on their resume, which made it easier to just kick the can down the road.

Current events have shown that, while the fear of a technology failure hasn’t gone away, the potential benefits have surpassed the dread. Standing still is not a viable business strategy, and speed-to-market, winning customer mindshare, and competitive advantage are all considerations as businesses assess the path forward. Fortunately, in either circumstance of new systems planned or those already underway, there are technologies that can reduce the risk of failure. GRC cloud solutions that include AI-driven risk analysis tools help anticipate risks and track resolution, as well as continuously monitor access policies while onboarding new users, changing role assignments or designing new roles.

When I served as a chief information technology officer, I couldn’t count the times that “temporary” access would be requested or new work assignments would occur — providing team members with more access than needed and creating an easy target for audit team findings. Almost 16 years later, I am happy to note that technology has evolved and improved with time — better and more extensive functionality, improved deployment options, integration that reduces the need to move sensitive data to less secure systems for analysis, and to my delight, no spreadsheets to manage workflows. It feels like dinosaurs were roaming the Earth compared to the current technology options that allow GRC professionals to automate high-risk processes across procurement, accounts payable, accounts receivable and the general ledger.

Technology is not the silver bullet to every business challenge. However, there’s no denying the benefits of analyzing requisitions, purchase orders, invoices, expense reports and orders using AI and machine learning. In a pandemic environment, new risks — both predictable and evolving — will occur, and GRC professionals must have tools to not only calculate the likelihood and impact of risks, but to comply with regulations that mandate highly controlled internal controls, integrity over the financial reports and the safeguarding of user-designated consent parameters.

Ensuring alignment with the mission, purpose and values of the organization, while simultaneously achieving business growth and satisfying stakeholders, was already keeping executives up at night. Now, things like natural disasters, economic uncertainty and the current pandemic have piled onto an ever-growing list of concerns. While external pressures may not let up in the short term, leveraging technology solutions that automate risk and compliance processes will give GRC professionals at least one less sheep to count.

More Thought Leadership

For years, creating a standout piece of B2B content was already challenging enough. Now, with AI tools churning out articles, social posts, and even entire white papers in minutes, the market is swamped with new content every day. Buyers and senior decision-makers rarely have the time—or the patience—to sift through it all. In an AI-flooded world, any veneer of "quality" can seem suspect if readers sense it might be auto-generated.

The decline of traditional search marketing is becoming impossible to ignore. Not long ago, a robust SEO strategy served as the backbone of inbound lead generation, supplying a steady flow of site visitors and form fills. But as AI-driven search evolves, many businesses now watch their organic traffic vanish—sometimes dramatically—because search engines are surfacing direct answers or relying on large language models (LLMs) to summarize content, causing fewer clicks to reach content-rich websites and publishers.

AI-driven search is rewriting how buyers find answers, and it's forcing a major change in how we think about inbound.