Home / Current Issue / Paper 1704406
A Governance, Risk, and Compliance (GRC) Model to Simplify Regulatory Compliance for North American Businesses
Subject area: Management and Commerce · Area of research: Regulatory Compliance
Abstract
Navigating complex regulatory landscapes is a persistent challenge for businesses in North America. To address this issue, this study proposes a Governance, Risk, and Compliance (GRC) model designed to simplify regulatory compliance for businesses operating in the United States and Canada. This model integrates governance principles, risk management frameworks, and compliance strategies into a unified system, enabling organizations to align operational objectives with regulatory requirements efficiently. The proposed GRC model incorporates a three-tiered approach: governance ensures strategic oversight and accountability, risk management identifies and mitigates compliance risks, and compliance streamlines adherence to regulations. By leveraging advanced technologies such as artificial intelligence, blockchain, and predictive analytics, the model enhances accuracy and efficiency in regulatory processes. Key features include automated compliance monitoring, real-time reporting, and scenario-based risk assessment, enabling proactive decision-making and reducing the likelihood of non-compliance penalties. This study emphasizes the importance of a tailored approach, accounting for sector-specific regulations, such as financial services, healthcare, and manufacturing. Comparative analysis of U.S. and Canadian regulatory frameworks highlights critical similarities and differences, offering region-specific implementation strategies. The GRC model fosters collaboration across organizational departments, ensuring seamless integration of governance and compliance functions into the broader operational framework. Pilot testing in North American businesses demonstrates the model?s effectiveness in reducing compliance costs, improving transparency, and enhancing stakeholder confidence. The study also addresses implementation challenges, such as organizational resistance and technological integration, offering practical solutions to facilitate adoption. By aligning governance, risk, and compliance practices into a cohesive framework, this model provides a strategic pathway for North American businesses to achieve regulatory compliance while fostering operational excellence. This research contributes to the field by presenting a scalable, technology-driven solution to the evolving complexities of regulatory adherence.
Keywords
Governance, Risk, Compliance (GRC), Regulatory Compliance, North American Businesses, Risk Management, Artificial Intelligence, Blockchain, Predictive Analytics, Operational Efficiency, Stakeholder Confidence, Strategic Oversight
References
[1] Aaronson, S. A., & Leblond, P. (2018). Another digital divide: The rise of data realms and its implications for the WTO. Journal of International Economic Law, 21(2), 245-272.
[2] Abdel-Rahman, M. (2023). Advanced cybersecurity measures in IT service operations and their crucial role in safeguarding enterprise data in a connected world. Eigenpub Review of Science and Technology, 7(1), 138-158.
[3] Abraham, C., Chatterjee, D., & Sims, R. R. (2019). Muddling through cybersecurity: Insights from the US healthcare industry. Business horizons, 62(4), 539-548.
[4] Adepoju, P. A., Austin-Gabriel, B., Ige, A. B., Hussain, N. Y., Amoo, O. O., & Afolabi, A. I. (2022). Machine learning innovations for enhancing quantum-resistant cryptographic protocols in secure communication. Open Access Research Journal of Multidisciplinary Studies. https://doi.org/10.53022/oarjms.2022.4.1.0075
[5] Afolabi, A. I., Hussain, N. Y., Austin-Gabriel, B., Ige, A. B., & Adepoju, P. A. (2023). Geospatial AI and data analytics for satellite-based disaster prediction and risk assessment. Open Access Research Journal of Engineering and Technology. https://doi.org/10.53022/oarjet.2023.4.2.0058
[6] Afolabi, A. I., Ige, A. B., Akinade, A. O., & Adepoju, P. A. (2023). Virtual reality and augmented reality: A comprehensive review of transformative potential in various sectors. Magna Scientia Advanced Research and Reviews. https://doi.org/10.30574/msarr.2023.7.2.0039
[7] Akinade, A. O., Adepoju, P. A., Ige, A. B., & Afolabi, A. I. (2022). Advancing segment routing technology: A new model for scalable and low-latency IP/MPLS backbone optimization. Open Access Research Journal of Science and Technology.
[8] Akinade, A. O., Adepoju, P. A., Ige, A. B., & Afolabi, A. I. (2023). Evaluating AI and ML in cybersecurity: A USA and global perspective. GSC Advanced Research and Reviews. https://doi.org/10.30574/gscarr.2023.17.1.0409
[9] Alawida, M., Omolara, A. E., Abiodun, O. I., & Al-Rajab, M. (2022). A deeper look into cybersecurity issues in the wake of Covid-19: A survey. Journal of King Saud University-Computer and Information Sciences, 34(10), 8176-8206.
[10] Al-Hassan, A., Burfisher, M. E., Chow, M. J. T., Ding, D., Di Vittorio, F., Kovtun, D., ... & Youssef, K. (2020). Is the whole greater than the sum of its parts? Strengthening caribbean regional integration. International Monetary Fund.
[11] Aliyu, A., Maglaras, L., He, Y., Yevseyeva, I., Boiten, E., Cook, A., & Janicke, H. (2020). A holistic cybersecurity maturity assessment framework for higher education institutions in the United Kingdom. Applied Sciences, 10(10), 3660.
[12] Amin, Z. (2019). A practical road map for assessing cyber risk. Journal of Risk Research, 22(1), 32-43.
[13] Ani, U. P. D., He, H., & Tiwari, A. (2017). Review of cybersecurity issues in industrial critical infrastructure: manufacturing in perspective. Journal of Cyber Security Technology, 1(1), 32-74.
[14] Armenia, S., Angelini, M., Nonino, F., Palombi, G., & Schlitzer, M. F. (2021). A dynamic simulation approach to support the evaluation of cyber risks and security investments in SMEs. Decision Support Systems, 147, 113580.
[15] Atkins, S., & Lawson, C. (2021). An improvised patchwork: success and failure in cybersecurity policy for critical infrastructure. Public Administration Review, 81(5), 847-861.
[16] Atkins, S., & Lawson, C. (2021). Cooperation amidst competition: cybersecurity partnership in the US financial services sector. Journal of Cybersecurity, 7(1), tyab024.
[17] Austin-Gabriel, B., Hussain, N. Y., Ige, A. B., Adepoju, P. A., & Afolabi, A. I. (2023). Natural language processing frameworks for real-time decision-making in cybersecurity and business analytics. International Journal of Science and Technology Research Archive. https://doi.org/10.53771/ijstra.2023.4.2.0018
[18] Austin-Gabriel, B., Hussain, N. Y., Ige, A. B., Adepoju, P. A., & Afolabi, A. I. (2023). Natural language processing frameworks for real-time decision-making in cybersecurity and business analytics. International Journal of Science and Technology Research Archive. https://doi.org/10.53771/ijstra.2023.4.2.0018
[19] Austin-Gabriel, B., Hussain, N. Y., Ige, A. B., Adepoju, P. A., Amoo, O. O., & Afolabi, A. I. (2021). Advancing zero trust architecture with AI and data science for enterprise cybersecurity frameworks. Open Access Research Journal of Engineering and Technology. https://doi.org/10.53022/oarjet.2021.1.1.0107
[20] Austin-Gabriel, B., Hussain, N. Y., Ige, A. B., Adepoju, P. A., Amoo, O. O., & Afolabi, A. I. (2021). Advancing zero trust architecture with AI and data science for enterprise cybersecurity frameworks. Open Access Research Journal of Engineering and Technology. https://doi.org/10.53022/oarjet.2021.1.1.0107
[21] Bamberger, K. A., & Mulligan, D. K. (2015). Privacy on the ground: driving corporate behavior in the United States and Europe. MIT Press.
[22] Beardwood, J. (2023). Cyberbreaches in Critical Infrastructure: It’s not just about Personal Data Breaches Anymore (Part 1)—A comparison of the new security regime for critical infrastructures in Canada, USA and EU. Computer Law Review International, 24(4), 109-114.
[23] Bello, O. A., Folorunso, A., Ejiofor, O. E., Budale, F. Z., Adebayo, K., & Babatunde, O. A. (2023). Machine Learning Approaches for Enhancing Fraud Prevention in Financial Transactions. International Journal of Management Technology, 10(1), 85-108.
[24] Bello, O. A., Folorunso, A., Ogundipe, A., Kazeem, O., Budale, A., Zainab, F., & Ejiofor, O. E. (2022). Enhancing Cyber Financial Fraud Detection Using Deep Learning Techniques: A Study on Neural Networks and Anomaly Detection. International Journal of Network and Communication Research, 7(1), 90-113.
[25] Bello, O. A., Folorunso, A., Onwuchekwa, J., & Ejiofor, O. E. (2023). A Comprehensive Framework for Strengthening USA Financial Cybersecurity: Integrating Machine Learning and AI in Fraud Detection Systems. European Journal of Computer Science and Information Technology, 11(6), 62-83.
[26] Bello, O. A., Folorunso, A., Onwuchekwa, J., Ejiofor, O. E., Budale, F. Z., & Egwuonwu, M. N. (2023). Analysing the Impact of Advanced Analytics on Fraud Detection: A Machine Learning Perspective. European Journal of Computer Science and Information Technology, 11(6), 103-126.
[27] Bello, S. A., Oyedele, L. O., Akinade, O. O., Bilal, M., Delgado, J. M. D., Akanbi, L. A., ... & Owolabi, H. A. (2021). Cloud computing in construction industry: Use cases, benefits and challenges. Automation in Construction, 122, 103441.
[28] Bodeau, D. J., McCollum, C. D., & Fox, D. B. (2018). Cyber threat modeling: Survey, assessment, and representative framework. Mitre Corp, Mclean, 2021-11.
[29] Buchanan, B. (2016). The cybersecurity dilemma: Hacking, trust, and fear between nations. Oxford University Press.
[30] Callaghan, R. (2018). The impact of protectionism on the completion and duration of cross-border acquisitions (Doctoral dissertation, Open Access Te Herenga Waka-Victoria University of Wellington).
[31] Cherdantseva, Y., Burnap, P., Blyth, A., Eden, P., Jones, K., Soulsby, H., & Stoddart, K. (2016). A review of cyber security risk assessment methods for SCADA systems. Computers & security, 56, 1-27.
[32] Clarke, R. A., & Knake, R. K. (2019). The Fifth Domain: Defending our country, our companies, and ourselves in the age of cyber threats. Penguin.
[33] Clemente, J. F. (2018). Cyber security for critical energy infrastructure (Doctoral dissertation, Monterey, CA; Naval Postgraduate School).
[34] Cohen, N., Hulvey, R., Mongkolnchaiarunya, J., Novak, A., Morgus, R., & Segal, A. (2022). Cybersecurity as an Engine for Growth. New America..
[35] Cohen, S. A. (2019). Cybersecurity for critical infrastructure: addressing threats and vulnerabilities in Canada.
[36] Dalal, A., Abdul, S., & Mahjabeen, F. (2016). Leveraging Artificial Intelligence for Cyber Threat Intelligence: Perspectives from the US, Canada, and Japan. Revista de Inteligencia Artificial en Medicina, 7(1), 18-28.
[37] Djenna, A., Harous, S., & Saidouni, D. E. (2021). Internet of things meet internet of threats: New concern cyber security issues of critical cyber infrastructure. Applied Sciences, 11(10), 4580.
[38] Dupont, B. (2019). The cyber-resilience of financial institutions: significance and applicability. Journal of cybersecurity, 5(1), tyz013.
[39] Dwivedi, Y. K., Hughes, D. L., Coombs, C., Constantiou, I., Duan, Y., Edwards, J. S., ... & Upadhyay, N. (2020). Impact of COVID-19 pandemic on information management research and practice: Transforming education, work and life. International journal of information management, 55, 102211.
[40] Ele, S. I., & Oko, J. O. (2016). Governance, risk and compliance (Grc): a. Journal of Integrative Humanism, 6(1), 161.
[41] Elujide, I., Fashoto, S. G., Fashoto, B., Mbunge, E., Folorunso, S. O., & Olamijuwon, J. O. (2021). Application of deep and machine learning techniques for multi-label classification performance on psychotic disorder diseases. Informatics in Medicine Unlocked, 23, 100545.
[42] Elujide, I., Fashoto, S. G., Fashoto, B., Mbunge, E., Folorunso, S. O., & Olamijuwon, J. O. (2021). Informatics in Medicine Unlocked.
[43] Feng, Y. (2019). The future of China’s personal data protection law: challenges and prospects. Asia Pacific Law Review, 27(1), 62-82.
[44] Flores, M. C. (2019). Challenges for Macroprudential Policy in the Euro Area: Cross-Border Spillovers and Governance Issues.
[45] Georgiadou, A., Mouzakitis, S., & Askounis, D. (2021). Assessing mitre att&ck risk using a cyber-security culture framework. Sensors, 21(9), 3267.
[46] Govindji, S., Peko, G., & Sundaram, D. (2018). A context adaptive framework for IT governance, risk, compliance and security. In Context-Aware Systems and Applications, and Nature of Computation and Communication: 6th International Conference, ICCASA 2017, and 3rd International Conference, ICTCC 2017, Tam Ky, Vietnam, November 23-24, 2017, Proceedings 6 (pp. 14-24). Springer International Publishing.
[47] Haugh, T. (2018). Harmonizing governance, risk management, and compliance through the paradigm of behavioral ethics risk. U. Pa. J. Bus. L., 21, 873.
[48] Houser, K. A., & Bagby, J. W. (2023). The data trust solution to data sharing problems. Vand. J. Ent. & Tech. L., 25, 113.
[49] Hussain, N. Y., Austin-Gabriel, B., Ige, A. B., Adepoju, P. A., & Afolabi, A. I. (2023). Generative AI advances for data-driven insights in IoT, cloud technologies, and big data challenges. Open Access Research Journal of Multidisciplinary Studies. https://doi.org/10.53022/oarjms.2023.6.1.0040
[50] Hussain, N. Y., Austin-Gabriel, B., Ige, A. B., Adepoju, P. A., Amoo, O. O., & Afolabi, A. I. (2021). AI-driven predictive analytics for proactive security and optimization in critical infrastructure systems. Open Access Research Journal of Science and Technology. https://doi.org/10.53022/oarjst.2021.2.2.0059
[51] Ige, A. B., Austin-Gabriel, B., Hussain, N. Y., Adepoju, P. A., Amoo, O. O., & Afolabi, A. I. (2022). Developing multimodal AI systems for comprehensive threat detection and geospatial risk mitigation. Open Access Research Journal of Science and Technology, 6(1), 63. https://doi.org/10.53022/oarjst.2022.6.1.0063
[52] Igo, S. E. (2020). The known citizen: A history of privacy in modern America. Harvard University Press.
[53] Ike, C. C., Ige, A. B., Oladosu, S. A., Adepoju, P. A., & Afolabi, A. I. (2023). Advancing machine learning frameworks for customer retention and propensity modeling in e-commerce platforms. GSC Advanced Research and Reviews. https://doi.org/10.30574/gscarr.2023.14.2.0017
[54] Ike, C. C., Ige, A. B., Oladosu, S. A., Adepoju, P. A., Amoo, O. O., & Afolabi, A. I. (2021). Redefining zero trust architecture in cloud networks: A conceptual shift towards granular, dynamic access control and policy enforcement. Magna Scientia Advanced Research and Reviews, 2(1), 074–086. https://doi.org/10.30574/msarr.2021.2.1.0032
[55] Jathanna, R., & Jagli, D. (2017). Cloud computing and security issues. International Journal of Engineering Research and Applications, 7(6), 31-38.
[56] Judijanto, L., Hindarto, D., & Wahjono, S. I. (2023). Edge of Enterprise Architecture in Addressing Cyber Security Threats and Business Risks. International Journal Software Engineering and Computer Science (IJSECS), 3(3), 386-396.
[57] Kaplan, R. S., & Mikes, A. (2016). Risk management—The revealing hand. Journal of Applied Corporate Finance, 28(1), 8-18.
[58] Kovacevic, A., & Nikolic, D. (2015). Cyber attacks on critical infrastructure: Review and challenges. Handbook of research on digital crime, cyberspace security, and information assurance, 1-18.
[59] Lalithambikai, S., & Usha, G. (2023): 18 cyber security unveiled: navigating evolving threats and innovations. fusion of knowledge, 109.
[60] Lanz, Z. (2022). Cybersecurity risk in US critical infrastructure: An analysis of publicly available US government alerts and advisories. International Journal of Cybersecurity Intelligence & Cybercrime, 5(1), 43-70.
[61] Lehto, M. (2022). Cyber-attacks against critical infrastructure. In Cyber security: Critical infrastructure protection (pp. 3-42). Cham: Springer International Publishing.
[62] Michael, K., Kobran, S., Abbas, R., & Hamdoun, S. (2019, November). Privacy, data rights and cybersecurity: Technology for good in the achievement of sustainable development goals. In 2019 IEEE International Symposium on Technology and Society (ISTAS) (pp. 1-13). IEEE.
[63] Mishra, A., Alzoubi, Y. I., Anwar, M. J., & Gill, A. Q. (2022). Attributes impacting cybersecurity policy development: An evidence from seven nations. Computers & Security, 120, 102820.
[64] Möller, D. P. (2023). Cybersecurity in digital transformation. In Guide to Cybersecurity in Digital Transformation: Trends, Methods, Technologies, Applications and Best Practices (pp. 1-70). Cham: Springer Nature Switzerland.
[65] Newlands, G., Lutz, C., Tamò-Larrieux, A., Villaronga, E. F., Harasgama, R., & Scheitlin, G. (2020). Innovation under pressure: Implications for data privacy during the Covid-19 pandemic. Big Data & Society, 7(2), 2053951720976680.
[66] Nicho, M., Khan, S., & Rahman, M. S. M. K. (2017, September). Managing information security risk using integrated governance risk and compliance. In 2017 International Conference on Computer and Applications (ICCA) (pp. 56-66). IEEE.
[67] Oladosu, S. A., Ige, A. B., Ike, C. C., Adepoju, P. A., Amoo, O. O., & Afolabi, A. I. (2023). AI-driven security for next-generation data centers: Conceptualizing autonomous threat detection and response in cloud-connected environments. GSC Advanced Research and Reviews, 15(2), 162-172. https://doi.org/10.30574/gscarr.2023.15.2.0136
[68] Oladosu, S. A., Ige, A. B., Ike, C. C., Adepoju, P. A., Amoo, O. O., & Afolabi, A. I. (2022). Next-generation network security: Conceptualizing a unified, AI-powered security architecture for cloud-native and on-premise environments. International Journal of Science and Technology Research Archive, 3(2), 270-280. https://doi.org/10.53771/ijstra.2022.3.2.0143
[69] Oladosu, S. A., Ige, A. B., Ike, C. C., Adepoju, P. A., Amoo, O. O., & Afolabi, A. I. (2022). Revolutionizing data center security: Conceptualizing a unified security framework for hybrid and multi-cloud data centers. Open Access Research Journal of Science and Technology. https://doi.org/10.53022/oarjst.2022.5.2.0065
[70] Oladosu, S. A., Ige, A. B., Ike, C. C., Adepoju, P. A., Amoo, O. O., & Afolabi, A. I. (2022). Reimagining multi-cloud interoperability: A conceptual framework for seamless integration and security across cloud platforms. Open Access Research Journal of Science and Technology. https://doi.org/10.53022/oarjst.2022.4.1.0026
[71] Oladosu, S. A., Ike, C. C., Adepoju, P. A., Afolabi, A. I., Ige, A. B., & Amoo, O. O. (2021). The future of SD-WAN: A conceptual evolution from traditional WAN to autonomous, self-healing network systems. Magna Scientia Advanced Research and Reviews. https://doi.org/10.30574/msarr.2021.3.2.0086
[72] Oladosu, S. A., Ike, C. C., Adepoju, P. A., Afolabi, A. I., Ige, A. B., & Amoo, O. O. (2021). Advancing cloud networking security models: Conceptualizing a unified framework for hybrid cloud and on-premises integrations. Magna Scientia Advanced Research and Reviews. https://doi.org/10.30574/msarr.2021.3.1.0076
[73] Onoja, J. P., & Ajala, O. A. (2022). Innovative telecommunications strategies for bridging digital inequities: A framework for empowering underserved communities. GSC Advanced Research and Reviews, 13(01), 210–217. https://doi.org/10.30574/gscarr.2022.13.1.0286
[74] Onoja, J. P., & Ajala, O. A. (2023). AI-driven project optimization: A strategic framework for accelerating sustainable development outcomes. GSC Advanced Research and Reviews, 15(01), 158–165. https://doi.org/10.30574/gscarr.2023.15.1.0118
[75] Onoja, J. P., Ajala, O. A., & Ige, A. B. (2022). Harnessing artificial intelligence for transformative community development: A comprehensive framework for enhancing engagement and impact. GSC Advanced Research and Reviews, 11(03), 158–166. https://doi.org/10.30574/gscarr.2022.11.3.0154
[76] Onoja, J. P., Ajala, O. A., & Ige, A. B. (2022). Harnessing artificial intelligence for transformative community development: A comprehensive framework for enhancing engagement and impact. GSC Advanced Research and Reviews. https://doi.org/10.30574/gscarr.2022.11.3.0154
[77] Papazafeiropoulou, A., & Spanaki, K. (2016). Understanding governance, risk and compliance information systems (GRC IS): The experts view. Information Systems Frontiers, 18, 1251-1263.
[78] Park, S. K. (2015). Special economic zones and the perpetual pluralism of global trade and labor migration. Geo. J. Int'l L., 47, 1379.
[79] Parraguez-Kobek, L., Stockton, P., & Houle, G. (2022). Cybersecurity and Critical Infrastructure Resilience in North America. Forging a Continental Future, 217.
[80] Pomerleau, P. L. (2019). Countering the Cyber Threats Against Financial Institutions in Canada: A Qualitative Study of a Private and Public Partnership Approach to Critical Infrastructure Protection. Order, (27540959).
[81] Raveling, A. J. (2023). Cybersecurity Risk Severity Assessment Methodology for Consumer Goods Manufacturers via Design Science Research (Doctoral dissertation, Colorado Technical University).
[82] Rawat, S. (2023). Navigating the Cybersecurity Landscape: Current Trends and Emerging Threats. Journal of Advanced Research in Library and Information Science, 10(3), 13-19.
[83] Recor, J., & Xu, H. (2016). GRC technology introduction. In Commercial Banking Risk Management: Regulation in the Wake of the Financial Crisis (pp. 305-331). New York: Palgrave Macmillan US.
[84] Riggs, H., Tufail, S., Parvez, I., Tariq, M., Khan, M. A., Amir, A., ... & Sarwat, A. I. (2023). Impact, vulnerabilities, and mitigation strategies for cyber-secure critical infrastructure. Sensors, 23(8), 4060.
[85] Robinson, R. (2020). Exploring strategies to ensure United States critical infrastructure of the water sector maintains proper cybersecurity (Doctoral dissertation, Colorado Technical University).
[86] Romanello Jacob, M. (2023). A new pair of glasses for conflicts of jurisdiction in Brazil: seeing the principle of proximity with Canadian lenses.
[87] Roshanaei, M. (2023). Cybersecurity Preparedness of Critical Infrastructure—A National Review. Journal of Critical Infrastructure Policy• Volume, 4(1).
[88] Sabillon, R., Cavaller, V., & Cano, J. (2016). National cyber security strategies: global trends in cyberspace. International Journal of Computer Science and Software Engineering, 5(5), 67.
[89] Saffady, W. (2023). Information Compliance: Fundamental Concepts and Best Practices. Rowman & Littlefield.
[90] Safitra, M. F., Lubis, M., & Fakhrurroja, H. (2023). Counterattacking cyber threats: A framework for the future of cybersecurity. Sustainability, 15(18), 13369.
[91] Sanaei, M. R., Movahedi Sobhani, F., & Rajabzadeh, A. (2016). Toward An E-business Governance Model Based on GRC Concept. The International Journal of Humanities, 23(3), 71-85.
[92] Shackelford, S. J., Proia, A. A., Martell, B., & Craig, A. N. (2015). Toward a global cybersecurity standard of care: Exploring the implications of the 2014 NIST cybersecurity framework on shaping reasonable national and international cybersecurity practices. Tex. Int'l LJ, 50, 305.
[93] Shackelford, S. J., Russell, S., & Haut, J. (2015). Bottoms up: A comparison of voluntary cybersecurity frameworks. UC Davis Bus. LJ, 16, 217.
[94] Shafqat, N., & Masood, A. (2016). Comparative analysis of various national cyber security strategies. International Journal of Computer Science and Information Security, 14(1), 129-136.
[95] Shameli-Sendi, A., Aghababaei-Barzegar, R., & Cheriet, M. (2016). Taxonomy of information security risk assessment (ISRA). Computers & security, 57, 14-30.
[96] Sikdar, P. (2021). Strong Security Governance Through Integration and Automation: A Practical Guide to Building an Integrated GRC Framework for Your Organization. Auerbach Publications.
[97] Singh, K. (2023). Artificial Intelligence & Cloud in Healthcare: Analyzing Challenges and Solutions Within Regulatory Boundaries. SSRG International Journal of Computer Science and Engineering, 10(9), 1-9.
[98] Smart, C. (2017). Regulating the Data that Drive 21st-Century Economic Growth.
[99] Trew, S. J. (2021). International Regulatory Cooperation and the Making of “Good” Regulators: A Case Study of the Canada–US Regulatory Cooperation Council (Doctoral dissertation, Carleton University).
[100] Ukwandu, E., Ben-Farah, M. A., Hindy, H., Bures, M., Atkinson, R., Tachtatzis, C., ... & Bellekens, X. (2022). Cyber-security challenges in aviation industry: A review of current and future trends. Information, 13(3), 146.
[101] Ustundag, A., Cevikcan, E., Ervural, B. C., & Ervural, B. (2018). Overview of cyber security in the industry 4.0 era. Industry 4.0: managing the digital transformation, 267-284.
[102] Voss, W. G., & Houser, K. A. (2019). Personal data and the GDPR: providing a competitive advantage for US companies. American Business Law Journal, 56(2), 287-344.
[103] Weymouth, S. (2023). Digital Globalization: Politics, Policy, and a Governance Paradox. Cambridge University Press.
[104] Yang, C., Huang, Q., Li, Z., Liu, K., & Hu, F. (2017). Big Data and cloud computing: innovation opportunities and challenges. International Journal of Digital Earth, 10(1), 13-53.
[105] Yeung, M. T., Kerr, W. A., Coomber, B., Lantz, M., & McConnell, A. (2017). Declining international cooperation on pesticide regulation: frittering away food security. Springer.
[106] Zaccari, L. (2016). Addressing a successful implementation of a governance, risk and compliance management system.
How to cite this paper
@article{1704406,
author = {Gideon Opeyemi Babatunde, Abidemi Adeleye Alabi, Sikirat Damilola Mustapha, Adebimpe Bolatito Ige},
title = {A Governance, Risk, and Compliance (GRC) Model to Simplify Regulatory Compliance for North American Businesses},
journal = {Iconic Research And Engineering Journals},
year = {2023},
volume = {6},
number = {11},
pages = {917-935},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1704406.pdf},
abstract = {Navigating complex regulatory landscapes is a persistent challenge for businesses in North America. To address this issue, this study proposes a Governance, Risk, and Compliance (GRC) model designed to simplify regulatory compliance for businesses operating in the United States and Canada. This model integrates governance principles, risk management frameworks, and compliance strategies into a unified system, enabling organizations to align operational objectives with regulatory requirements efficiently. The proposed GRC model incorporates a three-tiered approach: governance ensures strategic oversight and accountability, risk management identifies and mitigates compliance risks, and compliance streamlines adherence to regulations. By leveraging advanced technologies such as artificial intelligence, blockchain, and predictive analytics, the model enhances accuracy and efficiency in regulatory processes. Key features include automated compliance monitoring, real-time reporting, and scenario-based risk assessment, enabling proactive decision-making and reducing the likelihood of non-compliance penalties. This study emphasizes the importance of a tailored approach, accounting for sector-specific regulations, such as financial services, healthcare, and manufacturing. Comparative analysis of U.S. and Canadian regulatory frameworks highlights critical similarities and differences, offering region-specific implementation strategies. The GRC model fosters collaboration across organizational departments, ensuring seamless integration of governance and compliance functions into the broader operational framework. Pilot testing in North American businesses demonstrates the model?s effectiveness in reducing compliance costs, improving transparency, and enhancing stakeholder confidence. The study also addresses implementation challenges, such as organizational resistance and technological integration, offering practical solutions to facilitate adoption. By aligning governance, risk, and compliance practices into a cohesive framework, this model provides a strategic pathway for North American businesses to achieve regulatory compliance while fostering operational excellence. This research contributes to the field by presenting a scalable, technology-driven solution to the evolving complexities of regulatory adherence.},
keywords = {Governance, Risk, Compliance (GRC), Regulatory Compliance, North American Businesses, Risk Management, Artificial Intelligence, Blockchain, Predictive Analytics, Operational Efficiency, Stakeholder Confidence, Strategic Oversight},
month = {May},
}