How Company Culture Helps Shape the Risk Landscape

How Company Culture Helps Shape the Risk Landscape
作者: Paul Phillips, CISA, CISM, CDPSE
发表日期: 9月19日

In today’s environment, companies all over the globe are experiencing culture risk. Yes, culture indeed has an impact on risk and every company has a unique culture. 关键是要理解它, 管理它, and leverage it when possible to obtain competitive advantage. Every company is faced with both positive and negative risk – that is, threats and vulnerabilities that could adversely impact the organization, 其声誉和股票价值, as well as opportunities that could have a positive impact. While there are many factors that impact the risks that a company faces, many times business leaders overlook and underestimate the impact of company culture.

So, what makes up company culture? Company culture is the character of a company. It sets the tone of the environment in which employees work daily. Company culture includes a variety of elements, 包括公司战略, 任务, 幻影, 价值, 政策和行为. 最近, many major organizations like Google and Microsoft are revamping 政策 and procedures to address issues such as sexual harassment, 种族歧视, and discrimination because of the negative impact these cultural behaviors have had on the overall success of the company. Policies and procedures are tools that can be used to hold individuals accountable for their behavior. The key is ensuring that everyone adheres to the rules. It is also important to visibly reward good behavior and punish bad behavior on a consistent basis.

Once 政策 and procedures are put in place, it is important to gauge their effectiveness. Are the 政策 being followed and do they need to be modified in any way? Organizations that are truly committed to the idea will institute monitoring mechanisms to ascertain this information. Oversight and reporting tools that are properly implemented will allow employees at all levels to feel free to report breaches without fear of retribution. The actions of the oversight function to move quickly and consistently on reports will encourage a culture of accountability. The lack of such functions leaves an enterprise at risk of high-turnover, 没有动力的员工, 甚至是潜在的诉讼. Tools and procedures such as anonymous hotlines, 必要的合规培训, and explicitly stated company 价值s could be viewed as ways to mitigate such risk.

简单地设置工具, 政策, and procedures could be largely ineffective if the organization’s leadership doesn’t first take a long hard look at the current state of affairs. What is the employee demographic (age, gender, educational status, etc.)? Understanding backgrounds and human behavior can be key to having a clear picture of the culture within an enterprise. 例如, studies have shown that millennials view and respond to the world, 包括工作场所, in a very different way than older professionals. Understanding people helps an organization refine its culture, including the inherent risks associated with it.

There are many factors that typically impact the culture of an organization, 包括行业法规, the competitive environment and economic climate. These factors have direct and indirect influence on how people make decisions on a daily basis. Leadership should set clear expectations about what is acceptable behavior in light of these factors. Influencing culture is not easy and can be time-consuming and costly. However, the cost of doing nothing can be even greater.

ISACA年度报告

2024
复选标记

2023
复选标记

2022
复选标记

2021
复选标记

2020
复选标记