Magazine

One CMO’s Journey with Risk Management and Compliance – ProWellTech

Posted on the 30 December 2020 by Thiruvenkatam Chinnagounder @tipsclear
One CMO’s journey with risk management and compliance – ProWellTechOne CMO’s journey with risk management and compliance – ProWellTech

Marketers don't grow fantasizing about risk management and compliance. Personally, I've never thought twice about governance, risk, or compliance (GRC) other than making sure my team completed the required compliance or phishing training from time to time.

So when I was tasked with leading the General Data Protection Regulation (GDPR) compliance initiative at a previous employer, I was far from my comfort zone.

What I thought would be a few small requirements on how and when we emailed contacts based in Europe quickly turned into a complete overhaul of how the organization collected, processed and protected personally identifiable information ( PII).

It is the job of a risk leader to facilitate risk conversations and help guide business unit leaders to find their risk appetite.

As it turned out, I had completely underestimated the scope and importance of the project. My first mistake? Assuming compliance was "someone else's problem".

Risk management is a team sport

No single risk leader can alone assess, manage and resolve an organization's risk limit. Without the active involvement of the leaders of business units across the company in marketing, human resources, sales and more, a company can never have a healthy risk-conscious culture.

Leaders who are successful in developing that culture instill a company-wide team mentality with well-defined goals, a clear scope, and an agreed allocation of responsibilities. Ultimately, you need a buy-in similar to how a football manager needs players to accept team culture and play for peak performance. While the company's risk managers may be the quarterbacks when it comes to GRC, the team won't win without key games from linemen (sales), running backs (marketing), and receivers (sourcing).

It is the job of a risk leader to facilitate risk conversations and help guide business unit leaders to find their risk appetite. It is not their job to define risk levels that are acceptable to us, which is why CMOs, human resources and sales managers have no choice but to take an active role in defining risk for their departments.

Shifting my view on risk management

To be honest, I was only thinking about risk management in terms of asset protection and cost reduction. My crash course in Risk Liability has opened my eyes to the many ways GRC can actually accelerate deals and, in addition, generate revenue.


Back to Featured Articles on Logo Paperblog