4 Tech Trends That Will Impact Risk and Compliance Efforts in 2014

Once business organizations reach a certain size, their leaders have to start thinking systematically about how to structure reporting relationships to ensure vital information reaches the top; how to identify and account for the internal and external risks that could hobble the company; and how to ensure the organization is complying with a skein of local, state, and federal laws and regulations. This area of “governance, risk, and compliance” or GRC is the one that my company, MetricStream, helps people with. And like every executive, I try to stay aware of the trends affecting my industry.

Many of the larger trends that dominated the tech news in 2013—including social media, big data, mobility, and the cloud—promise to affect risk and compliance efforts in specific ways in the coming year. Organizations have realized the business benefits of these technologies, and will now look for effective ways of managing the associated risks and regulations. In that context, here are four key technology trends that will shape risk and compliance efforts in 2014:

Social Media Strategies Will Place Greater Emphasis on Risk Monitoring

Social media is fast gaining acceptance as a formal channel of business communication. Even the SEC has ruled that social media can be used to disclose key company information in compliance with Regulation Fair Disclosure (FD).

LinkedIn, YouTube, Google+, Pinterest, Tumblr…all these social media sites have opened up exciting ways of connecting with customers. And with Facebook and Twitter going public, there might be new paid opportunities for businesses to market themselves via social networks.

However, a series of hacker attacks this year on the Twitter accounts of prestigious news sources such as The Guardian and the Associated Press revealed how social media can be an organization’s weakest point of defense, posing risks to information security, reputation, legal/ compliance, and a number of other business areas.

Responding to these risks, the Financial Industry Regulatory Authority (FINRA), the Federal Financial Institutions Examination Council (FFIEC), and the Federal Trade Commission (FTC) have begun issuing multiple social media guidelines.

Therefore, in 2014, companies are likely to broaden their social media focus beyond marketing/ communications, to include real-time risk monitoring and compliance. It will become increasingly important to use advanced social media analytics to filter through online conversations, and detect risks and non-compliance incidents.

The Bring-Your-Own-Device (BYOD) Tug-of-War Will Intensify

A 2013 CISCO survey predicted that the number of BYOD devices in U.S. workplaces will reach 108 million by 2016 . This increasing adoption of BYOD means better efficiency and cost savings for companies, and more work-life flexibility for employees.

But what if a personal device with confidential business information gets stolen or a user-installed app on the device is compromised by malware and the security and confidentiality of business data is put at risk?

In 2014, we are likely to see a greater tension between the need to protect corporate data, and the demand for BYOD flexibility; between management oversight of BYOD activities, and employees’ privacy rights.

At some point, we will have to strike a balance by defining what is acceptable and unacceptable in BYOD; implementing mature policies and best practices; and addressing questions such as:

Author: Shellye Archambeau

Ms. Archambeau is the CEO of MetricStream, a Silicon Valley-based, Governance, Risk, Compliance (GRC) and Quality Management software company that helps companies around the world improve their business performance. Under Ms. Archambeau's leadership, MetricStream has grown into a recognized global market leader with over 1000 employees around the world. The company has been recognized for growth and innovation, and has been consistently named a leader in GRC by leading independent analyst firms. Ms. Archambeau has proven global business expertise combined with public policy passion. As a member of the board of directors for the Silicon Valley Leadership Group, a nationally recognized organization focused on fostering a cooperative effort between business and government officials to address major public policy issues affecting Silicon Valley, Ms. Archambeau has led initiatives and Washington, DC delegations to address regulatory compliance and improve governance. She served on the Board of Directors, and the Audit and Technology committees for media research company, Arbitron, Inc. [NYSE: ARB] from 2005 until acquired by Nielsen in 2013. She currently serves on the board of directors of Verizon Communications Inc. [NYSE, NASDAQ: VZ], a global leader in delivering broadband and other wireless and wireline communications services. Ms. Archambeau is a sought after speaker who has presented on GRC issues around the world to Fortune 500 corporations, members of Congress, and associations including IIA, ISACA, and NASDAQ. Ms. Archambeau is frequently quoted in top-tier media including the Wall Street Journal, New York Times, Compliance Week, Silicon Valley Business Journal, and currently pens a column on leadership and entrepreneurship for Xconomy. In April 2013, Ms. Archambeau was named the “#2 Most Influential African American in Technology” by Business Insider.