Customer Case Study

Strengthening IT Risk, Incident and Policy Management with a GRC Platform

How a global supply chain consulting and technology services firm used an integrated GRC platform to move from fragmented, departmental IT controls to a systemic, governed single source of truth for IT risk, incidents and policy.

Industry: Global Supply Chain Consulting & Technology Services
Approach: Integrated GRC platform
Footprint: Four business functions in scope — HR, IT Infrastructure, Finance and Projects
Focus: IT risk management, incident management, policy management
GRC Platform Hero
Staff Trained
~100 employees across consulting, delivery, operations & risk functions
Workshops Delivered
30+ capability-building seminars across all in-scope domains
Improvement Opportunities
~150 identified from the gap between current state & leading practice
Initiatives Launched
10 structured initiatives chartered, sponsored & launched

From Fragmented Controls to a Single Source of Truth

A global supply chain consulting and technology services firm launched a program to improve the governance and management of its information and technology (I&T) practices, concentrating on three areas where fragmentation was creating real exposure: IT risk management, incident management and policy management. The effort was driven both by external pressure — customer due-diligence requirements, supply-chain due-diligence regulation and sanctions-screening obligations — and by an internal recognition that I&T decisions were being made without a shared, governed view of risk and control.

The program was operationalized on a single, integrated GRC platform that served as both the governance model and the system of record for risk, incidents and policy, creating a structured approach to incident and policy management with GRC software across business units. The firm trained roughly 100 employees across consulting, delivery, operations and risk functions on the platform and a common risk-and-control methodology, which built internal recognition that good I&T governance is an enterprise responsibility. The approach was deliberately vendor-neutral: the value came from a unified model and a single source of truth, independent of any one toolset.

"How can improving the governance and management of I&T practices contribute to value creation across the enterprise — not just to the IT department?"
The Guiding Question

Siloed Controls, No Enterprise View

I&T controls existed, but they had grown up around the organization chart rather than around a coherent governance model. Risk registers, incident logs and policy documents were maintained separately by each function — HR, IT Infrastructure, Finance and Projects — in each function's own language. There was no common taxonomy, no consistent capability baseline, and no way to roll local practice up into an enterprise view. Leadership could not reliably answer foundational questions: whether IT risks were being assessed consistently, whether incidents were being managed and learned from, or whether policies were current, owned and actually followed across functions. This highlighted the need for a GRC platform for IT risk and incident management that could establish governance consistency across domains.

Two constraints shaped the approach.

First, the firm chose to build on existing internal talent rather than outsource the work, which created a knowledge gap given limited prior experience with a structured, platform-based risk methodology.

Second, with strong external drivers in play, there was a real risk of slipping into a "compliance-by-compliance" mindset; the firm was explicit that the goal was governance that creates value, not a checklist.

Working from its enterprise risk profile, compliance obligations, threat landscape and IT sourcing model, the firm scoped the platform to the risk, incident and policy domains most material to its situation.

Capabilities Brought onto the GRC Platform

IT Risk Management
Risk governance & optimization Risk identification Assessment Treatment & monitoring
Incident Management
Service request & incident handling Problem management Continuity & resilience
Policy Management
Policy & management framework Compliance with external requirements

Five Critical Success Factors

Identified at the outset of the program.

Involvement beyond the IT department. The firm made clear from the start that this was an enterprise initiative concerning the value of I&T across the whole organization, not an IT project.

Enterprise-wide platform and methodology enablement. Multiple training cycles established a common language and a shared understanding of the model before configuration began.

Multidisciplinary teams per domain. Each in-scope domain was assigned a team drawn from different departments, so knowledge moved across silos and ownership was shared.

Capability-building workshops. Beyond general enablement, focused workshops developed deeper fluency in each risk, incident and policy domain and in how it would be governed on the platform.

Targeted external advisory. An external advisor transferred methodology and experience and designed the tools that accelerated implementation, while ownership stayed inside the organization.

A Structured, Phased Approach

The program opened with platform and methodology enablement so that everyone shared the same concepts, language and a common way of linking enterprise goals to risk and control objectives. The in-scope domains were then grouped into phases, each with a cross-functional team. A critical first step was configuring a reference model on the GRC platform that, in a simple way, clarified the scope and its alignment to enterprise goals, created a shared model and common repositories, and set out how the model would mature across three horizons:

Current State
No systemic view of I&T
Informal IT-risk, incident and policy practices; scattered information and considerable undocumented knowledge.
Horizon 1
Reference model defined
Risk/control objectives aligned to enterprise goals; priority objectives and practices defined, starting with core processes.
Horizon 2
Alignment reinforced
Practices extended beyond process to organizational structures, information, people, policies and culture across operational areas and functions.
Horizon 3
Holistic model
Consolidation into a holistic governance, management and operating model, with a complete view across processes, people, information, policy, culture and supporting systems.
Three-Step Domain Method

Workshops were practical rather than theoretical, feeding directly into implementation. A three-step method was applied to each domain in scope:

Step 1
Know / Understand
Learn the objective and its metrics, study the underlying process, and understand how capability will be assessed.
Step 2
Map / Document
Adapt objectives and metrics to the firm's reality, assess current capability, map leading practices and activities to operational documentation, and populate the platform repositories.
Step 3
Review / Improve
Review the remaining governance dimensions, update documentation, and identify and record quick wins and improvement opportunities.
Implementation Phases
1
Phase 1 — Problem definition and baseline
Many useful practices already existed, but were structured by department rather than aligned to a coherent model. The teams built a documentation model mapping the firm's reality to leading practice, creating a repository on the platform for each dimension of governance:
  • Alignment goals, objectives and metrics — the executive risk dashboard
  • Processes — e.g., the IT-risk workflow and the incident and problem-management flows, supported through an IT controls and incident tracking solution configured within the platform
  • Organizational structures — e.g., risk owners, the incident-response function, the policy authority
  • Information flows and items — e.g., the risk register, incident tickets, the policy register
  • People, skills and competencies
  • Policies and procedures — central to the policy-management scope
  • Culture, ethics and behavior
  • Services, infrastructure and applications
Each repository served both as a self-assessment instrument and as a living record of best practice; the program team monitored the level of implementation of each dimension and reported to the CIO weekly. Where a leading practice existed it was documented and mapped to operational evidence; where it did not, an improvement opportunity was logged for future implementation. By the end of the phase, roughly 150 improvement opportunities had been identified from the gap between current state and leading practice.
2
Phase 2 — Target capability, gap analysis and road map
Identifying capability levels mattered because it showed the firm that it was not only implementing new practice but also aligning existing practice with best practice. A target capability level was formalized for each in-scope domain, gaps were analyzed and prioritized, and a road map was defined. Engaging top management here was decisive: it secured their understanding of the current state of I&T governance, their acceptance of the target state, and their approval of the initiatives needed to reach it.
3
Phase 3 — Planning initiatives
Because this was not a compliance program, improvement opportunities were grouped into coherent initiatives rather than treated as a checklist. Related opportunities — across different dimensions of a domain, and across different domains — were bundled according to implementation logic. Each initiative was chartered with a proposed sponsor, the areas involved, objectives, scope, expected results and the opportunities it addressed, and quick wins were separated out for early momentum.
4
Phase 4 — Implementation
Initiatives were designed around their requirements, independent of the team that would deliver them, so they could be launched as internal projects or, where necessary, used to define requests for proposals (RFPs) for external entities. The program team then monitored initiative performance and the closing of the underlying best-practice gap, so it was always possible to see the degree of implementation for each domain in scope. Compliance obligations were treated as inputs to the same platform rather than a parallel workstream, so regulatory exposure surfaced alongside IT risk and incident data, contributing to reducing operational risk using GRC tools instead of isolated compliance activities.

From Fragmentation to a Single Source of Truth

At the organization level, the program's defining outcome was consolidation: four business functions — HR, IT Infrastructure, Finance and Projects — that each maintained their own disconnected spreadsheets, incident logs and policy files were brought onto one GRC platform, feeding a single, governed source of truth for IT risk, incidents and policy.

Organization-level before/after — from fragmented, siloed controls to a GRC-platform single source of truth
Figure 1. Organization-level before/after — from fragmented, siloed controls to a GRC-platform single source of truth.

Results from the Program

Results from the program can be quantified in a number of ways:

~70
Staff completed platform & methodology enablement
30+
Capability-building workshops delivered
~150
Improvement opportunities identified
10
Structured initiatives chartered & launched
Metric Result
Platform & methodology enablement ~70 staff completed enablement across consulting, delivery, operations and risk functions
Capability-building seminars 30+ workshops delivered on the in-scope risk, incident and policy domains
Reference model A reference model for IT risk, incident and policy management defined and configured on the GRC platform
Executive risk dashboard Dashboard defined with alignment metrics (~25) and objective-level metrics (~120)
Capability assessment Current capability assessed across the 7 in-scope risk, incident and policy domains
Governance dimensions documented Leading practices documented across all governance dimensions (process, structures, information, people, policy, culture, systems)
Improvement opportunities ~150 improvement opportunities identified from the gap between current state and leading practice
Improvement initiatives 10 structured initiatives chartered, sponsored and launched

Qualitatively, the internal team is now recognized for its ability to run the platform and apply leading risk, incident and policy practice autonomously. Leadership gained a single, defensible view of I&T risk and control — and the same risk, incident or policy is no longer tracked four different ways across the four functions.

Enterprise Governance Over Departmental Documentation

The Traditional (Bottom-Up) Approach
Org-Chart Driven
The firm's earlier attempts mirrored its org chart, with each department systematizing its own activities. That effort never scaled: formalizing every operational activity from the bottom up could not keep pace with internal complexity or the speed of external change, and never produced an enterprise view.
The Systemic (Top-Down) Approach
GRC Platform Enabled
The GRC platform enabled a systemic view of I&T — a reference model that goes beyond the IT department and values the transformation of governance and management practices over the endless documentation of operational detail.

The main benefits realized were:

Alignment with external requirements
Adopting leading practice on a single platform allowed existing practices to be mapped and a continuous-improvement system to be established, informing operational areas and external partners of the governance and management practices expected of them.
A holistic view of I&T
Looking beyond the process dimension surfaced human factors (turnover, experience and knowledge gaps and communication) that a process-only assessment would have missed.
Value beyond compliance
By refusing a compliance-by-compliance strategy, the firm turned an external mandate into genuine value-creation capability.
Employee enablement
Training was the mechanism that made I&T governance a shared responsibility rather than a specialist silo.
"It became clear to a significant number of employees that the responsibility for good governance and management of I&T goes beyond the direct responsibilities of the IT department. When managed effectively on a single GRC platform, I&T contributes to a real transformation of internal culture — and the whole organization, not just IT, can harness it for value creation."
WhatsApp Icon
Xponential Digital Logo Xponential Digital
WhatsApp Icon Start Chat