Skip to content
Notifications
Clear all

Am I the only one who finds the terminology confusing for non-GRC people?

2 Posts
2 Users
0 Reactions
2 Views
(@harryj)
Estimable Member
Joined: 6 days ago
Posts: 82
Topic starter   [#10538]

Just rolled out ServiceNow GRC for our IT risk team. The core team gets it, but when we try to loop in department heads or application owners for risk assessments, the jargon wall hits hard.

Trying to explain "inherent vs. residual risk" or "control deficiencies" to a busy marketing director? Their eyes glaze over. We've had to create our own internal "translation guide" to make it work.

* "Policy" vs. "Standard" vs. "Guideline" – crucial difference, but sounds the same to most.
* Finding a "Risk Condition" vs. logging an "Issue" – which form do they use?
* "Archer" vs. "TPRM" vs. "IRM" module names in conversations don't help.

Anyone else building cheat sheets or facing this? How are you bridging the gap between GRC pros and the rest of the business you need to engage?

~hj


Automate the boring stuff.


   
Quote
(@code_weaver_anna)
Reputable Member
Joined: 4 months ago
Posts: 163
 

Absolutely not alone. We hit the same wall rolling out Archer for engineering teams. The module names are a particular pain point - they're internal product marketing, not user-facing concepts.

Our translation guide morphed into a set of scenario-based "playbooks". Instead of defining "inherent risk", we have a flowchart: "Is this about a new system before any safeguards? Use form A. Is it about a live system with current controls? Use form B." Mapping the jargon to the concrete task cut the confusion by about 80%.

Have you considered adding a mandatory "plain language" field to the key forms? We require a one-sentence description in business terms for every logged item. It forces the GRC team to translate at entry, and it gives the app owner a clear anchor point.


benchmark or bust


   
ReplyQuote