Ever since the financial crisis of 2007, many global banks have had to pay multi-billion dollar fines due to compliance breaches and control failures. While some of the causes for fines were abominable, many were a result of carelessness or failure to share data between governance, risk and compliance processes within the organization. This was shared by a survey conducted by Wolters Kluwer, a global information services company based in the Netherlands.

Integration of Governance, Risk and Compliance (GRC)

Earlier, organizations viewed governance, risk and compliance (GRC) in separate silos. Governance was probably overseen by a company secretary, risk by a chief risk officer and compliance by a compliance officer and so on. However, now organizations are beginning to work toward a holistic and integrated framework that views all these three lines of defense as mutually related and interdependent functions. Consequently, several organizations have already initiated efforts to converge governance, risk and compliance policies under a single umbrella.

There are two aspects to GRC implementation:

  1. Developing the policies and framework holistically in consultation with all stakeholders involved
  2. Communicating about them to employees for their acceptance and execution

Most often, the focus is on the first part, with a lot of time and resources invested to ensure that the framework is well designed. The second part, that is, effective communication and training, is not executed in a manner that will ensure positive results.

However, for GRC policies to be successfully implemented at all levels in the organization, employees at all levels have to be clearly educated about the policies, how it fits into the broad framework and why they should abide by them. They need to know why this policy matters to them as individuals and to the organization in general. It is not sufficient if this information is conveyed to the employees in the form of written guidelines, but organizations need to ensure that employees understood and are equipped with the skills to execute the policies effectively. So, what is the effective way this can be done?  Online training approach could be a good option.

Why is online training a good choice for successful GRC implementation?

When employees are handled out a detailed manual about rules, regulations, compliance requirement, and the risk awareness document, it is very unlikely that they remember every rule and guideline. The aspects pertaining to governance, risk, compliance and employees’ responsibility need to be presented in a manner that will make it easy for employees to relate to the job. Online training will be a good choice for corporates for the following reasons:

Feasibility to roll out compliance training to employees at all levels

Very often, while the senior- and middle-level managers are aware of the compliance requirements, the front-line staff at the lower levels in the hierarchy may not fully understand the implications of noncompliance of policies. If traditional methods are adopted, a limited number of managers are trained, who in turn are expected to educate others as it is not feasible to have face-to-face training for all employees. However, with e-learning, employees at all levels can be educated and informed about new changes with respect to governance, risk and compliance matters. This makes the initiative inclusive and positively affects the morale of these segments of employees.

Capacity of online programs to provide an interactive element for better employee engagement

E-learning has the ability to provide information in a small and easily understandable format. The language, instructional strategies and interactive elements can be designed to suit the target audiences. Most importantly, employees can engage with the content, repeat modules or parts of the course that they did not understand well and skip those that may be too basic. Instead of being a passive recipient of information, employees can interact with the content, test themselves and assess their knowledge about the subject.

Ability to explain through scenarios and case studies that are likely to stick

The best way to explain what is right and what is wrong is through examples. It is possible to create scenarios and case studies taking instances from day-to-day job situations of the employees. When policies are explained in the context of their jobs, it is easier for employees to understand and appreciate their value. Also, the heavy legal jargon is broken down to a language that appeals better to the employees. As a result, it improves the overall understanding about the policy.

Option to translate courses into multiple languages to reach global audience

If your organization works with associates, or has offices abroad, compliance training is essential for employees located in those regions as well. If their knowledge of English is limited and the importance of understanding compliance requirements is critical, it is best that the compliance training is done in the language that is easily understood. In such situations, courses have to be translated into other languages. This can be easily done in online courses. The course quality is assured and the content will be standardized across the organization.

Feature to test employees on their knowledge and maintain records about employee progress

It is not enough if employees attend or undergo a training program. It’s important to have a method to measure the extent to which they have gained knowledge about the new policies. This can be done through both formative and summative assessments in online courses. The process is embedded into the course and if the course is hosted into an LMS, this data is captured and stored for generating reports. One can also get an idea about who has taken the course, who needs to take the course, and evaluate the next steps based on the results.

Possibility of providing reinforcement training periodically to mitigate compliance breaches

While employee knowledge about certain policies may be strong, they might forget some of them and what they remember may not be directly relevant to their job situation at that point of time. As a result, some aspects of the policies may be forgotten. Therefore, refresher training is recommended to employees every six months. Having the course online makes it easy to roll out refresher training to employees. It is cost effective even if certain portions of the course have to be revised or re-aligned to a changed situation.

So, if you are planning to roll out GRC initiatives in your organization, including online methods along with traditional methods would be a good idea. It is a good option to bring awareness among your employees about the new policies to ensure their acceptance and adherence across the company.

Dr. Ayesha Habeeb Omer is the co-founder and Chief Operating Officer of CommLab India.