Protiviti -- Governance Portal (GP)

11 August 2013

Type of solution

The Governance Portal is used by clients to manage one or more of the following: internal audit, operational risk, compliance risk, enterprise risk, financial controls assurance, IT governance. Specific solutions include Solvency II, Basel II, COSO, privacy and COBIT and are tailored to the unique needs of a particular GRC domain. GP provides these targeted GRC solutions while enabling convergence of multiple GRC practices into a single enterprise platform.

Description of solution

The GP provides a structured process for identifying risks, modelling potential interactions, determining likelihood of occurrence, documenting and testing mitigating controls and estimating the financial impact. It enables a continuous compliance approach and assists organisations with tracking action plans and changes to meet both internal management objectives and external regulatory requirements.

It integrates content and consulting expertise into a comprehensive software solution, giving organisations the visibility and insight needed to manage and mitigate critical risk and compliance issues.

Core and integrated components of the platform include policy management, risk and control management, event and loss management, GRC management and analytics, audit management.

The GP supports rich, graphical reporting and flexible ad hoc analysis.  The GP assessment engine provides a mechanism to launch campaigns, assessments, certifications, diagnostics and etraining to support ERM initiatives. The GP is currently available in eight strategic and geographically significant languages including: Dutch, Japanese, Portuguese, Spanish, French, Arabic (inclusive of RTL), Chinese and Italian. All translations in the above languages are available on a common installation.

It is a browser-based application supported by an n-tiered, service-oriented and federated architecture. The platform is offered to clients both as on-premise and SaaS offerings.

Date first developed

Governance Portal v 1.0 was released in 2003.

Was the solution developed specifically for the insurance industry?

No.

If not, is the solution designed for both banks and re/insurance companies?

Yes.

How much is your own technology and how much is adapted or licensed from others?

The GP architecture consists of the following components:

  • client layer – browser-based UI that uses Silverlight (for browser-based processing) and other web 2.0 user interface metaphors
  • application logic – business objects and web services built on top of Microsoft .NET / Microsoft Internet Information Server (IIS) web server
  • data repository – Microsoft SQL server 2008 database.

All development in each layer of the architecture above is done by Protiviti's in-house development team.

Does your solution integrate with third-party systems or in-house systems?

Yes. The GP supports integration of data via Excel-based content uploads, web services API and other periodic upload utilities such as XML feeds.  Each of these approaches can map third-party metadata to any GP element such as risk and control status, indicator (KRI or KPI) measurements or action plans. Further, each of these periodic inputs can launch auto remediation/review tasks and trigger notifications to appropriate individuals driving standardised response behaviour across the enterprise.

Out-of-the-box integrations that demonstrate these capabilities include Thomson Reuters' Accelus regulatory updates (through automated XML upload), Risk Business' KRIeX library (via web services API), Protiviti's in-house application – Knowledge Leader.  Knowledge Leader (www.knowledgeleader.com) is Protiviti's subscription website for internal audit, IT audit, risk management and compliance tools, articles, audit programmes and other materials.

These integration capabilities can be used to support integrations of custom ERP data, CCM, IT-related data (e.g. vulnerability scans configuration management database exceptions) as well as other performance and risk indicators.

Describe any features specific to insurance and specific to Solvency II

For specific Insurance-related risk and governance objectives such as for solvency, the Governance Portal allows clients to:

  • map risks to individual processes and balance sheet accounts, enabling a risk-based approach throughout the organisation including performance management and compensation
  • document and track management practices, processes, systems and controls
  • manage the annual own risk and solvency assessment (ORSA) exercise
  • deploy surveys and checklists to business owners for certifications on material changes to risk and business strategy
  • define roles and responsibilities and segregation of duties
  • drive certification and review of policy updates through workflow.

A large insurance client has implemented the GP to support its GRC programme.  Seven teams – spanning risk, financial controls, Solvency II, information security, internal compliance, business continuity management and audit – are using a single integrated platform to support 4,500 global users.

Implementation

How long does the solution take to implement?

A typical implementations are two to three months in duration and involve between 160 and 500 hours. Clients' circumstances, scope and the state of their existing data are the drivers in overall project timing and cost.

How much training and support is necessary?

To accommodate clients' individual needs, Protiviti offers three implementation models to best suit clients' needs: training only; baseline (20-30 days); and fully managed. After the platform is implemented and the users are trained on the software, Protiviti provides "rolling with the sun" support desk coverage to its worldwide client base.

Types of user

Types of company/organisation

Consumer products & services, energy, government, healthcare & life sciences, industrial products, private equity and technology, media & communication – from Fortune 500 clients to smaller institutions.

Types of users within companies/organisations

CFOs, chief audit executive and controller, CRO, chief compliance officer, chief information officer, operational performance officer.

Areas/countries with the most users

US, Europe, Asia-Pacific, Middle East, Latin America.

Sales Contact person(s) and details

Name: James Ensminger
Tel:  (312) 476-6321
Email:  [email protected]