"The solution enables the bank to report top risk instances, thus informing the management and board about the organization’s exposure to critical risks, while reconciling high level statements with granular control outcomes in each process and country."
“MetricStream’s solution has helped us streamline elaborate and intricate processes of compliance and risk management with an integrated enterprise-wide system, giving us a better grip on our compliance, risks, and lowering the overall cost of compliance.”
"One of the highlights of our GRC implementation is the successful use of the survey module as a global first level assurance activity. In the last 6 months alone, we've completed close to 10,000 first line assurance verification. This is supporting our control testing and eventually helping us to demonstrate the effectiveness of our controls."
“We need a regulatory engagement management system that is capable of being used by key people in compliance and quite widely in our counterpart functions like finance, risk, and legal, but also actually in the business – either as an information delivery tool, or as a way to share information back to compliance. We also need to create a central repository of what’s going on with regulators – which we can’t do with our current technology limitations. That really impairs the efficiency of what we do, as well as the organization’s ability to see what’s going on in the whole piece.”
“With MetricStream’s role-based views that offer insights into core GRC processes and key metrics, real-time dashboards and reports, we can now track the status and trends relating to key risk and compliance programs more effectively.”
"Technology is an enabler, it helps in establishing consistent practices and standards amongst all our risk disciplines."
"We have started to aggregate risk data across the various risk taxonomies and risk types i.e. if an individual of our company or a client is showing up in more than 1 risk silo, it probably warrants an in depth review. This is obviously a much more complex system but the first results we are seeing of this holistic monitoring are quite promising. We have completely revised the controls framework for our key risk areas such as AML, Know Your Customer."
"The benefits that organizations can gain from implementing a GRC tool are streamlined operations, elimination of duplication of work and information, and contextual intelligence that allow you to make better decisions faster."
"Reliability compliance is a critical program for us. We must report on over a thousand standards and requirements for the large number of participants in our energy market. By using MetricStream solutions we will be able to enhance our compliance efforts. We selected MetricStream solutions because they were user friendly and secure, and will integrate easily with our existing systems."
"The MetricStream M7 platform which we rolled out earlier this year is really going to help us improve efficiency and help us streamline our data model."
"Dealing with risks is a part of everyone's day to day job. All of our employees at Salesforce are Risk Rangers and it takes all of us playing our part to effectively manage the risks that we face."
"Through the common controls framework we were able to accomplish a significant amount of consolidation about 93% of consolidation. We were able to reduce the 5128 requirements into a small set of about 326 controls."
“MetricStream had provided a comprehensive yet simple to use solution. And simplicity was important as we did not want something overly technical and complicated.”
“We tested MetricStream, and found that it addressed all our needs, in terms of unifying the audit universe, improving the effectiveness of internal audit function, and streamlining the internal control and governance processes.”
"We were looking to upgrade our GRC system without compromising on our GRC vision and processes. MetricStream's flexible solutions offered us that freedom along with the benefits of a tightly integrated GRC framework. Each of MetricStream's modules demonstrated comprehensive, cutting-edge capabilities that were a perfect fit to our requirements. We now look forward to managing the complete spectrum of GRC programs from a common platform."