SlideShare ist ein Scribd-Unternehmen logo
1 von 2
Downloaden Sie, um offline zu lesen
CASE STUDY
MetricStream                                              POWERING COMPLIANCE AT AN ENERGY MAJOR

                                                          Overview
                                                          The company is a major integrated energy company engaged in power production, transmission and
                                                          distribution involving natural gas, power and other energy related products. It is one of the largest
                                                          electric utilities in the US.

                                                          The company faces multiple compliance requirements from a number of regulatory bodies that impose
                                                          regulatory oversight and reporting requirements. Industry regulations from FERC, NERC and state and
                                                          regional public service commissions combined with cross-industry regulations like Sarbanes Oxley
                                                          (SOX) impact all business functions operationally as well as strategically. These compliance require-
                                                          ments affect a large number of business processes with many specialized processes being designed
                                                          solely to meet specific regulatory guidelines. The cost of ensuring compliance in terms of time and
                                                          resources is substantial. Moreover, the risk of noncompliance and other enterprise risks have to be
Customer
ONE OF THE LARGEST ELECTRIC UTILITIES IN THE US
                                                          constantly monitored and mitigated for ensuring business performance and continuity.


                                                          Challenge
Benefits                                                  The company had internally developed an application for managing SOX and Enterprise Risk Manage-
                                                          ment (ERM) processes using Microsoft Access and SQL Server technology. The system was designed
Efficiency: The overall resource requirement and pro-     to capture SOX and other risks, associated controls, control test plans, issues to highlight deficiencies
cessing times for compliance programs is expected         when controls failed testing and action plans to resolve the issues.
to come down substantially due to an integrated
compliance framework mapped to the organiza-              In the last few years, the company experienced a significant increase in the number of compliance
tional structure and responsibilities. The automated      requirements to be met as well as additional scrutiny by the various regulatory bodies to determine
workflows will take information and cases through
                                                          that the company does in fact comply with those requirements. As the internally developed applica-
the assessment, investigation, reporting and closure
process without delays. Email notifications, task list,
                                                          tion was designed for a narrow set of compliance requirements, the increasing regulatory demands
and case status reports on the users’ homepage will       started bringing forth the limitations of the application and its inherent approach.
keep pending tasks on top of the mind improving
responsiveness and proactive participation.               As newer processes and record keeping was required, they were setup manually outside of the
                                                          system as the application could not be extended. For example, the system could not map compliance
Compliance: There will be a significant reduction in      process to the general ledger balances and financial statements maintained in PeopleSoft and Cognos
the risk of noncompliance as all the regulatory stan-     applications. Keeping the automated processes in synch with the manual processes became a major
dards and requirements will be clearly identified         overhead as new accounts were created.
and mapped to the processes, controls, activities
and documents needed for compliance. Well-defined
                                                          Another major limitation was that the internal application allowed only for a simplistic and linear orga-
and automated assessments, issue reporting and
remediation management workflows will ensure
                                                          nizational setup and did not support the varying reporting relationships and information flows between
sustainable compliance.                                   testers, process owners and those who managed the overall compliance process for their business
                                                          units.
Visibility: With MetricStream, the company
executives as well as functional managers will have       The compliance surveys and certifications across various departments, locations and business units
complete visibility into compliance programs at their     involved manual distribution, gathering and consolidation of responses. Lack of automation made this
respective levels of responsibilities. This transpar-     activity excessively tedious and error prone with a number of documents being physically circulated
ency will make compliance and risk management a           and manually signed in the company.
predictable process.
                                                          The internal application did not support the periodic cycles and frequency of activities and record
                                                          keeping for ongoing compliance leading to inefficient data reentry activities. Moreover, the application
                                                          did not enforce appropriate authorizations to limit users from viewing information and records that
                                                          they did not have privileges for violating a key compliance requirement.


                                                          Solution
                                                          MetricStream is enabling the company to adopt an integrated compliance strategy through an
                                                          enterprise-level framework for managing all regulatory requirements and ERM programs. The solution
                                                          will provide comprehensive functionality for managing SOX compliance and ERM as well as FERC and
                                                          NERC regulations and corporate policies for standard of conduct.

                                                          The company will defined and maintain a centralized structure of the overall compliance and control
                                                          hierarchy based on regulatory standards and requirements. It includes processes and assets in scope,
                                                          associated risks, controls to address the risks and mechanisms to assess the controls. It covers
                                                          associated policies and procedures, reporting requirements and filing templates and schedules for
                                                          various regulations.
MetricStream
                                                        Based on the compliance requirements and associated risk, the assessment plans will be scheduled
Why MetricStream                                        periodically or triggered based occurrence of certain adverse events. The system will integrate with
                                                        other enterprises applications and implements rigorous change control to ensure all records, pro-
An integrated platform and application environment      cesses and documentation always stay in sync.
to manage compliance with multiple regulations,
corporate policies and industry standards.              The system supports risk assessment and computations based on configurable methodologies and
                                                        algorithms and will provide a clear view into organizations risk profile enabling managers to prioritize
Comprehensive workflow-based functionality for SOX      their response strategies and mitigation plans.
compliance and the flexibility to extend the common
framework and best practices for FERC and NERC
compliance.                                             “The MetricStream solutions will streamline our financial controls processes for SOX compliance as
                                                        well as enabled us to employ best practices frameworks for managing compliance with FERC and
Ability to support complex organizational models and    NERC,” says a senior compliance officer of the company. For instance, risks such as failure to have a
granular access controls while providing an easy-       functioning Incident Response System or to meet Independent Functioning Guideline will be
to-use portal-based interface for end-users for quick   documented with their controls as well as their periodic assessment plans. “The framework will cover
adoption.                                               our incident response mechanism to report incidents to the Electricity Sector - Information Sharing
                                                        and Analysis Center (ES-ISAC) based on reporting criteria, thresholds and procedures contained in
Powerful reporting and analytics for complete vis-
ibility into risk and compliance data on executive
dashboards, control charts and risk heat maps.
                                                              “MetricStream solutions will streamline our financial controls processes for SOX compli-
                                                             ance as well as enable us to employ best practices frameworks for managing compliance
                                                                          with FERC and NERC.” says the spokesperson of the Company.



                                                        NERC’s Indications, Analysis and Warning (IAW) Program. And we will conduct periodic assessments
                                                        to ensure clearly defined and documented procedure for reporting security incidents, appropriate roles
                                                        definition to deal with reporting and responding to security incidents, and a well defined line of com-
                                                        munication and escalation path for reporting security incidents,” explains the executive. Hundreds of
                                                        such processes, risk and controls will be documented and assessed using the MetricStream solution.

                                                        Handling and reporting of noncompliance issues will be streamlined by automated workflows that
                                                        document the issue and exceptions that pose a risk of noncompliance. The system will take them
                                                        through a systematic mechanism of investigation and remedial corrective action.

                                                        Embedded best practices for the energy industry combined with decision tree and workflow func-
                                                        tionality will support identification of reportable events as well as the type of report that needs to be
                                                        filed. The process of reporting will be simplified as the system automatically generates mandatory
                                                        reports in formats and layouts prescribed by the agencies. The reports are generated in standard file
                                                        types such as MS Word and can be reviewed before being submitted. “Selfreporting of noncompli-
                                                        ance issues is critical for our business and if NERC finds noncompliance during their auditing, they can
                                                        impose heavy fines”, says the compliance officer.

                                                        MetricStream supports a complex organizational model to cover all the entities, business units and
                                                        departments, as well as their mappings to various standards and requirements. With the granular
                                                        access controls, the company will ensure confidentiality and the attorney-client privilege principle for
                                                        sensitive information and records.

                                                        The automated surveys and certifications powered by electronic signatures will be efficient, con-
                                                        sistent and reliable. The solution will ensure accountability by enforcing the flow of information and
                                                        records and documenting attestations and representations at appropriate stages and by responsible
                                                        personnel that roll-up for executive certifications.

                                                        Executive dashboards will provide enterprise wide visibility into the compliance and risk management
                                                        process and highlight issues that need to be addressed in risk heat maps. The solution will provide the
                                                        ability to track risk profiles, control ownership, assessment plans, remediation status, etc. on graphi-
                                                        cal charts that can be accessed globally and display real-time information.



For more information, visit
www.metricstream.com

Copyright 2011. All Rights Reserved.

Weitere ähnliche Inhalte

Was ist angesagt?

Compliance, Risk and Audit - BCBS
Compliance, Risk and Audit - BCBS Compliance, Risk and Audit - BCBS
Compliance, Risk and Audit - BCBS MetricStream Inc
 
Link Resources Nuclear Energy
Link Resources Nuclear EnergyLink Resources Nuclear Energy
Link Resources Nuclear EnergyLink Resources
 
Crowe-ACAMS AML System Planning
Crowe-ACAMS AML System PlanningCrowe-ACAMS AML System Planning
Crowe-ACAMS AML System PlanningBrett Rosynek
 
Audit of it infrastructure
Audit of it infrastructureAudit of it infrastructure
Audit of it infrastructurepramod_kmr73
 
Ch10-Software Engineering 9
Ch10-Software Engineering 9Ch10-Software Engineering 9
Ch10-Software Engineering 9Ian Sommerville
 
SEC Regulation SCI, ARP Reviews and Audits
SEC Regulation SCI, ARP Reviews and AuditsSEC Regulation SCI, ARP Reviews and Audits
SEC Regulation SCI, ARP Reviews and AuditsJohn Rapa
 
IT Control Objectives for SOX
IT Control Objectives for SOXIT Control Objectives for SOX
IT Control Objectives for SOXMahesh Patwardhan
 
Information System Audit and Control
Information System Audit and ControlInformation System Audit and Control
Information System Audit and ControlAsad Raza
 
NAIC MAR Compliance Solutions
NAIC MAR Compliance Solutions NAIC MAR Compliance Solutions
NAIC MAR Compliance Solutions MetricStream Inc
 
Government contract business systems compliance guidance
Government contract business systems compliance guidanceGovernment contract business systems compliance guidance
Government contract business systems compliance guidanceGlen Alleman
 
How much does it cost to be Secure?
How much does it cost to be Secure?How much does it cost to be Secure?
How much does it cost to be Secure?mbmobile
 
Global Bank Brings Compliance Risks under Control
Global Bank Brings Compliance Risks under Control Global Bank Brings Compliance Risks under Control
Global Bank Brings Compliance Risks under Control MetricStream Inc
 
Hausi Müller - Towards Self-Adaptive Software-Intensive Systems
Hausi Müller - Towards Self-Adaptive Software-Intensive SystemsHausi Müller - Towards Self-Adaptive Software-Intensive Systems
Hausi Müller - Towards Self-Adaptive Software-Intensive SystemsCHOOSE
 
What is a Firewall Risk Assessment?
What is a Firewall Risk Assessment?What is a Firewall Risk Assessment?
What is a Firewall Risk Assessment?VISTA InfoSec
 

Was ist angesagt? (20)

Compliance, Risk and Audit - BCBS
Compliance, Risk and Audit - BCBS Compliance, Risk and Audit - BCBS
Compliance, Risk and Audit - BCBS
 
Link Resources Nuclear Energy
Link Resources Nuclear EnergyLink Resources Nuclear Energy
Link Resources Nuclear Energy
 
(2005) Securing Manufacturing Environment using Biometrics
(2005) Securing Manufacturing Environment using Biometrics(2005) Securing Manufacturing Environment using Biometrics
(2005) Securing Manufacturing Environment using Biometrics
 
Crowe-ACAMS AML System Planning
Crowe-ACAMS AML System PlanningCrowe-ACAMS AML System Planning
Crowe-ACAMS AML System Planning
 
Profile_Kishore Sundar
Profile_Kishore SundarProfile_Kishore Sundar
Profile_Kishore Sundar
 
DFARS & CMMC Overview
DFARS & CMMC Overview DFARS & CMMC Overview
DFARS & CMMC Overview
 
Audit of it infrastructure
Audit of it infrastructureAudit of it infrastructure
Audit of it infrastructure
 
Ch10-Software Engineering 9
Ch10-Software Engineering 9Ch10-Software Engineering 9
Ch10-Software Engineering 9
 
SEC Regulation SCI, ARP Reviews and Audits
SEC Regulation SCI, ARP Reviews and AuditsSEC Regulation SCI, ARP Reviews and Audits
SEC Regulation SCI, ARP Reviews and Audits
 
IT Control Objectives for SOX
IT Control Objectives for SOXIT Control Objectives for SOX
IT Control Objectives for SOX
 
Information System Audit and Control
Information System Audit and ControlInformation System Audit and Control
Information System Audit and Control
 
NAIC MAR Compliance Solutions
NAIC MAR Compliance Solutions NAIC MAR Compliance Solutions
NAIC MAR Compliance Solutions
 
Corporate Cyber Program
Corporate Cyber ProgramCorporate Cyber Program
Corporate Cyber Program
 
Government contract business systems compliance guidance
Government contract business systems compliance guidanceGovernment contract business systems compliance guidance
Government contract business systems compliance guidance
 
How much does it cost to be Secure?
How much does it cost to be Secure?How much does it cost to be Secure?
How much does it cost to be Secure?
 
IT and part 11
IT and part 11IT and part 11
IT and part 11
 
Security and-visibility
Security and-visibilitySecurity and-visibility
Security and-visibility
 
Global Bank Brings Compliance Risks under Control
Global Bank Brings Compliance Risks under Control Global Bank Brings Compliance Risks under Control
Global Bank Brings Compliance Risks under Control
 
Hausi Müller - Towards Self-Adaptive Software-Intensive Systems
Hausi Müller - Towards Self-Adaptive Software-Intensive SystemsHausi Müller - Towards Self-Adaptive Software-Intensive Systems
Hausi Müller - Towards Self-Adaptive Software-Intensive Systems
 
What is a Firewall Risk Assessment?
What is a Firewall Risk Assessment?What is a Firewall Risk Assessment?
What is a Firewall Risk Assessment?
 

Andere mochten auch

Enterprise risk management
Enterprise risk managementEnterprise risk management
Enterprise risk managementMetricStream Inc
 
Your Cause Employee Philanthropy Program
Your Cause Employee Philanthropy ProgramYour Cause Employee Philanthropy Program
Your Cause Employee Philanthropy Programkbuckland
 
ComplianceOnline Virtual Seminar - IFRS and Effective Fraud Prevention Strate...
ComplianceOnline Virtual Seminar - IFRS and Effective Fraud Prevention Strate...ComplianceOnline Virtual Seminar - IFRS and Effective Fraud Prevention Strate...
ComplianceOnline Virtual Seminar - IFRS and Effective Fraud Prevention Strate...ComplianceOnline
 
I 9 compliance- how to avoid errors
I 9 compliance- how to avoid errorsI 9 compliance- how to avoid errors
I 9 compliance- how to avoid errorscomplianceonline123
 
ComplianceOnline PPT Format 2015 SEC’s New Whistleblower Rules 5.12.2015
ComplianceOnline PPT Format 2015 SEC’s New Whistleblower Rules 5.12.2015ComplianceOnline PPT Format 2015 SEC’s New Whistleblower Rules 5.12.2015
ComplianceOnline PPT Format 2015 SEC’s New Whistleblower Rules 5.12.2015Craig Taggart MBA
 
Health insurance compliance
Health insurance complianceHealth insurance compliance
Health insurance complianceMetricStream Inc
 
The Unexpected Benefits of a Unified Approach to Governance, Risk, and Compli...
The Unexpected Benefits of a Unified Approach to Governance, Risk, and Compli...The Unexpected Benefits of a Unified Approach to Governance, Risk, and Compli...
The Unexpected Benefits of a Unified Approach to Governance, Risk, and Compli...Enterprise Technology Management (ETM)
 
Xoriant - Financial services expertise
Xoriant - Financial services expertiseXoriant - Financial services expertise
Xoriant - Financial services expertiseXoriant Corporation
 

Andere mochten auch (10)

Enterprise risk management
Enterprise risk managementEnterprise risk management
Enterprise risk management
 
Your Cause Employee Philanthropy Program
Your Cause Employee Philanthropy ProgramYour Cause Employee Philanthropy Program
Your Cause Employee Philanthropy Program
 
ComplianceOnline Virtual Seminar - IFRS and Effective Fraud Prevention Strate...
ComplianceOnline Virtual Seminar - IFRS and Effective Fraud Prevention Strate...ComplianceOnline Virtual Seminar - IFRS and Effective Fraud Prevention Strate...
ComplianceOnline Virtual Seminar - IFRS and Effective Fraud Prevention Strate...
 
State of Global Good
State of Global GoodState of Global Good
State of Global Good
 
Red Flags of Money Laundering
Red Flags of Money LaunderingRed Flags of Money Laundering
Red Flags of Money Laundering
 
I 9 compliance- how to avoid errors
I 9 compliance- how to avoid errorsI 9 compliance- how to avoid errors
I 9 compliance- how to avoid errors
 
ComplianceOnline PPT Format 2015 SEC’s New Whistleblower Rules 5.12.2015
ComplianceOnline PPT Format 2015 SEC’s New Whistleblower Rules 5.12.2015ComplianceOnline PPT Format 2015 SEC’s New Whistleblower Rules 5.12.2015
ComplianceOnline PPT Format 2015 SEC’s New Whistleblower Rules 5.12.2015
 
Health insurance compliance
Health insurance complianceHealth insurance compliance
Health insurance compliance
 
The Unexpected Benefits of a Unified Approach to Governance, Risk, and Compli...
The Unexpected Benefits of a Unified Approach to Governance, Risk, and Compli...The Unexpected Benefits of a Unified Approach to Governance, Risk, and Compli...
The Unexpected Benefits of a Unified Approach to Governance, Risk, and Compli...
 
Xoriant - Financial services expertise
Xoriant - Financial services expertiseXoriant - Financial services expertise
Xoriant - Financial services expertise
 

Ähnlich wie ONE OF THE LARGEST ELECTRIC UTILITIES IN THE US

Governance, Risk and Compliance- Energy Industry
Governance, Risk and Compliance- Energy Industry Governance, Risk and Compliance- Energy Industry
Governance, Risk and Compliance- Energy Industry MetricStream Inc
 
A Financial Planning Leader Streamlines Audit, Risk and Compliance
A Financial Planning Leader Streamlines Audit, Risk and Compliance A Financial Planning Leader Streamlines Audit, Risk and Compliance
A Financial Planning Leader Streamlines Audit, Risk and Compliance MetricStream Inc
 
BCBS Associate Achieves Superior Compliance, Audit & Issue Management
BCBS Associate Achieves Superior Compliance, Audit & Issue Management BCBS Associate Achieves Superior Compliance, Audit & Issue Management
BCBS Associate Achieves Superior Compliance, Audit & Issue Management MetricStream Inc
 
Regulatory relationship-management
Regulatory relationship-managementRegulatory relationship-management
Regulatory relationship-managementMetricStream Inc
 
Smart Grid Operational Services Supply Chain Fact Sheet
Smart Grid Operational Services Supply Chain Fact SheetSmart Grid Operational Services Supply Chain Fact Sheet
Smart Grid Operational Services Supply Chain Fact SheetGord Reynolds
 
Six Keys to Securing Critical Infrastructure and NERC Compliance
Six Keys to Securing Critical Infrastructure and NERC ComplianceSix Keys to Securing Critical Infrastructure and NERC Compliance
Six Keys to Securing Critical Infrastructure and NERC ComplianceLumension
 
The Use of Spreadsheets: As it relates to Section 404 of the Sarbanes-Oxley Act.
The Use of Spreadsheets: As it relates to Section 404 of the Sarbanes-Oxley Act.The Use of Spreadsheets: As it relates to Section 404 of the Sarbanes-Oxley Act.
The Use of Spreadsheets: As it relates to Section 404 of the Sarbanes-Oxley Act.gueste080564
 
The Use of Spreadsheets: As it relates to Section 404 of the Sarbanes-Oxley Act.
The Use of Spreadsheets: As it relates to Section 404 of the Sarbanes-Oxley Act.The Use of Spreadsheets: As it relates to Section 404 of the Sarbanes-Oxley Act.
The Use of Spreadsheets: As it relates to Section 404 of the Sarbanes-Oxley Act.renetta
 
Technology Controls in Business - End User Computing
Technology Controls in Business - End User ComputingTechnology Controls in Business - End User Computing
Technology Controls in Business - End User Computingguestc1bca2
 
ConceptOne - Whitepaper - Achieving Regulatory Alpha Through Regulatory Risk ...
ConceptOne - Whitepaper - Achieving Regulatory Alpha Through Regulatory Risk ...ConceptOne - Whitepaper - Achieving Regulatory Alpha Through Regulatory Risk ...
ConceptOne - Whitepaper - Achieving Regulatory Alpha Through Regulatory Risk ...Gary S. Kaminsky
 
Automated policy compliance and
Automated policy compliance andAutomated policy compliance and
Automated policy compliance andcsandit
 
Automated policy compliance and
Automated policy compliance andAutomated policy compliance and
Automated policy compliance andcsandit
 
AUTOMATED POLICY COMPLIANCE AND CHANGE DETECTION MANAGED SERVICE IN DATA NETW...
AUTOMATED POLICY COMPLIANCE AND CHANGE DETECTION MANAGED SERVICE IN DATA NETW...AUTOMATED POLICY COMPLIANCE AND CHANGE DETECTION MANAGED SERVICE IN DATA NETW...
AUTOMATED POLICY COMPLIANCE AND CHANGE DETECTION MANAGED SERVICE IN DATA NETW...csandit
 
AUTOMATED POLICY COMPLIANCE AND CHANGE DETECTION MANAGED SERVICE IN DATA NETW...
AUTOMATED POLICY COMPLIANCE AND CHANGE DETECTION MANAGED SERVICE IN DATA NETW...AUTOMATED POLICY COMPLIANCE AND CHANGE DETECTION MANAGED SERVICE IN DATA NETW...
AUTOMATED POLICY COMPLIANCE AND CHANGE DETECTION MANAGED SERVICE IN DATA NETW...cscpconf
 
Capgemini ses - smart grid operational services - supply chain fact sheet (gr)
Capgemini   ses - smart grid operational services - supply chain fact sheet (gr)Capgemini   ses - smart grid operational services - supply chain fact sheet (gr)
Capgemini ses - smart grid operational services - supply chain fact sheet (gr)Gord Reynolds
 
PracticeLeague Compliance Management Platform
PracticeLeague Compliance Management PlatformPracticeLeague Compliance Management Platform
PracticeLeague Compliance Management PlatformParimal Chanchani
 

Ähnlich wie ONE OF THE LARGEST ELECTRIC UTILITIES IN THE US (20)

Sarbanes oxley compliance
Sarbanes oxley complianceSarbanes oxley compliance
Sarbanes oxley compliance
 
Governance, Risk and Compliance- Energy Industry
Governance, Risk and Compliance- Energy Industry Governance, Risk and Compliance- Energy Industry
Governance, Risk and Compliance- Energy Industry
 
NERC Compliance Solution
NERC Compliance Solution NERC Compliance Solution
NERC Compliance Solution
 
Audit solution airline
Audit solution airlineAudit solution airline
Audit solution airline
 
A Financial Planning Leader Streamlines Audit, Risk and Compliance
A Financial Planning Leader Streamlines Audit, Risk and Compliance A Financial Planning Leader Streamlines Audit, Risk and Compliance
A Financial Planning Leader Streamlines Audit, Risk and Compliance
 
BCBS Associate Achieves Superior Compliance, Audit & Issue Management
BCBS Associate Achieves Superior Compliance, Audit & Issue Management BCBS Associate Achieves Superior Compliance, Audit & Issue Management
BCBS Associate Achieves Superior Compliance, Audit & Issue Management
 
Regulatory relationship-management
Regulatory relationship-managementRegulatory relationship-management
Regulatory relationship-management
 
Smart Grid Operational Services Supply Chain Fact Sheet
Smart Grid Operational Services Supply Chain Fact SheetSmart Grid Operational Services Supply Chain Fact Sheet
Smart Grid Operational Services Supply Chain Fact Sheet
 
Six Keys to Securing Critical Infrastructure and NERC Compliance
Six Keys to Securing Critical Infrastructure and NERC ComplianceSix Keys to Securing Critical Infrastructure and NERC Compliance
Six Keys to Securing Critical Infrastructure and NERC Compliance
 
The Use of Spreadsheets: As it relates to Section 404 of the Sarbanes-Oxley Act.
The Use of Spreadsheets: As it relates to Section 404 of the Sarbanes-Oxley Act.The Use of Spreadsheets: As it relates to Section 404 of the Sarbanes-Oxley Act.
The Use of Spreadsheets: As it relates to Section 404 of the Sarbanes-Oxley Act.
 
The Use of Spreadsheets: As it relates to Section 404 of the Sarbanes-Oxley Act.
The Use of Spreadsheets: As it relates to Section 404 of the Sarbanes-Oxley Act.The Use of Spreadsheets: As it relates to Section 404 of the Sarbanes-Oxley Act.
The Use of Spreadsheets: As it relates to Section 404 of the Sarbanes-Oxley Act.
 
Technology Controls in Business - End User Computing
Technology Controls in Business - End User ComputingTechnology Controls in Business - End User Computing
Technology Controls in Business - End User Computing
 
ConceptOne - Whitepaper - Achieving Regulatory Alpha Through Regulatory Risk ...
ConceptOne - Whitepaper - Achieving Regulatory Alpha Through Regulatory Risk ...ConceptOne - Whitepaper - Achieving Regulatory Alpha Through Regulatory Risk ...
ConceptOne - Whitepaper - Achieving Regulatory Alpha Through Regulatory Risk ...
 
Automated policy compliance and
Automated policy compliance andAutomated policy compliance and
Automated policy compliance and
 
Automated policy compliance and
Automated policy compliance andAutomated policy compliance and
Automated policy compliance and
 
AUTOMATED POLICY COMPLIANCE AND CHANGE DETECTION MANAGED SERVICE IN DATA NETW...
AUTOMATED POLICY COMPLIANCE AND CHANGE DETECTION MANAGED SERVICE IN DATA NETW...AUTOMATED POLICY COMPLIANCE AND CHANGE DETECTION MANAGED SERVICE IN DATA NETW...
AUTOMATED POLICY COMPLIANCE AND CHANGE DETECTION MANAGED SERVICE IN DATA NETW...
 
AUTOMATED POLICY COMPLIANCE AND CHANGE DETECTION MANAGED SERVICE IN DATA NETW...
AUTOMATED POLICY COMPLIANCE AND CHANGE DETECTION MANAGED SERVICE IN DATA NETW...AUTOMATED POLICY COMPLIANCE AND CHANGE DETECTION MANAGED SERVICE IN DATA NETW...
AUTOMATED POLICY COMPLIANCE AND CHANGE DETECTION MANAGED SERVICE IN DATA NETW...
 
Capgemini ses - smart grid operational services - supply chain fact sheet (gr)
Capgemini   ses - smart grid operational services - supply chain fact sheet (gr)Capgemini   ses - smart grid operational services - supply chain fact sheet (gr)
Capgemini ses - smart grid operational services - supply chain fact sheet (gr)
 
PracticeLeague Compliance Management Platform
PracticeLeague Compliance Management PlatformPracticeLeague Compliance Management Platform
PracticeLeague Compliance Management Platform
 
Society of Petroleum Engineers : Model Based Engineering
Society of Petroleum Engineers : Model Based EngineeringSociety of Petroleum Engineers : Model Based Engineering
Society of Petroleum Engineers : Model Based Engineering
 

Mehr von MetricStream Inc

Next generation-risk-management-solution
Next generation-risk-management-solutionNext generation-risk-management-solution
Next generation-risk-management-solutionMetricStream Inc
 
MetricStream AppStudio Accelerates the Creation & Configuration of GRC Soluti...
MetricStream AppStudio Accelerates the Creation & Configuration of GRC Soluti...MetricStream AppStudio Accelerates the Creation & Configuration of GRC Soluti...
MetricStream AppStudio Accelerates the Creation & Configuration of GRC Soluti...MetricStream Inc
 
Financial organization-orm
Financial organization-ormFinancial organization-orm
Financial organization-ormMetricStream Inc
 
Payment giant-automates-internal-audit
Payment giant-automates-internal-auditPayment giant-automates-internal-audit
Payment giant-automates-internal-auditMetricStream Inc
 
Clinical Research Org. Intensifies Compliance by Automating Audit & CAPA
Clinical Research Org. Intensifies Compliance by Automating Audit & CAPA Clinical Research Org. Intensifies Compliance by Automating Audit & CAPA
Clinical Research Org. Intensifies Compliance by Automating Audit & CAPA MetricStream Inc
 
Supplier quality-compliance
Supplier quality-complianceSupplier quality-compliance
Supplier quality-complianceMetricStream Inc
 
Quality Audit Management – Food Industry
Quality Audit Management – Food Industry Quality Audit Management – Food Industry
Quality Audit Management – Food Industry MetricStream Inc
 
Quality Management System
Quality Management System  Quality Management System
Quality Management System MetricStream Inc
 
Internal Audit Solution - MetricStream
Internal Audit Solution - MetricStream Internal Audit Solution - MetricStream
Internal Audit Solution - MetricStream MetricStream Inc
 

Mehr von MetricStream Inc (13)

Next generation-risk-management-solution
Next generation-risk-management-solutionNext generation-risk-management-solution
Next generation-risk-management-solution
 
MetricStream AppStudio Accelerates the Creation & Configuration of GRC Soluti...
MetricStream AppStudio Accelerates the Creation & Configuration of GRC Soluti...MetricStream AppStudio Accelerates the Creation & Configuration of GRC Soluti...
MetricStream AppStudio Accelerates the Creation & Configuration of GRC Soluti...
 
Financial organization-orm
Financial organization-ormFinancial organization-orm
Financial organization-orm
 
Payment giant-automates-internal-audit
Payment giant-automates-internal-auditPayment giant-automates-internal-audit
Payment giant-automates-internal-audit
 
Clinical Research Org. Intensifies Compliance by Automating Audit & CAPA
Clinical Research Org. Intensifies Compliance by Automating Audit & CAPA Clinical Research Org. Intensifies Compliance by Automating Audit & CAPA
Clinical Research Org. Intensifies Compliance by Automating Audit & CAPA
 
Supplier quality-compliance
Supplier quality-complianceSupplier quality-compliance
Supplier quality-compliance
 
Quality Audit Management – Food Industry
Quality Audit Management – Food Industry Quality Audit Management – Food Industry
Quality Audit Management – Food Industry
 
Msfairchildcasestudy
MsfairchildcasestudyMsfairchildcasestudy
Msfairchildcasestudy
 
Quality Management System
Quality Management System  Quality Management System
Quality Management System
 
Iso9000 compliance
Iso9000 complianceIso9000 compliance
Iso9000 compliance
 
Internal Audit Solution - MetricStream
Internal Audit Solution - MetricStream Internal Audit Solution - MetricStream
Internal Audit Solution - MetricStream
 
Energy Risk Management
Energy Risk Management  Energy Risk Management
Energy Risk Management
 
Internal Audit Solution
Internal Audit Solution Internal Audit Solution
Internal Audit Solution
 

Kürzlich hochgeladen

Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation SlidesKeppelCorporation
 
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLSeo
 
Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Roland Driesen
 
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999Tina Ji
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageMatteo Carbone
 
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesMysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesDipal Arora
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayNZSG
 
Call Girls in Gomti Nagar - 7388211116 - With room Service
Call Girls in Gomti Nagar - 7388211116  - With room ServiceCall Girls in Gomti Nagar - 7388211116  - With room Service
Call Girls in Gomti Nagar - 7388211116 - With room Servicediscovermytutordmt
 
GD Birla and his contribution in management
GD Birla and his contribution in managementGD Birla and his contribution in management
GD Birla and his contribution in managementchhavia330
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...lizamodels9
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Neil Kimberley
 
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Lviv Startup Club
 
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒anilsa9823
 
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779Delhi Call girls
 
Best Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in IndiaBest Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in IndiaShree Krishna Exports
 
Unlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdfUnlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdfOnline Income Engine
 
M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.Aaiza Hassan
 
Pharma Works Profile of Karan Communications
Pharma Works Profile of Karan CommunicationsPharma Works Profile of Karan Communications
Pharma Works Profile of Karan Communicationskarancommunications
 
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurVIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurSuhani Kapoor
 
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
Tech Startup Growth Hacking 101  - Basics on Growth MarketingTech Startup Growth Hacking 101  - Basics on Growth Marketing
Tech Startup Growth Hacking 101 - Basics on Growth MarketingShawn Pang
 

Kürzlich hochgeladen (20)

Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
 
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
 
Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...
 
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
 
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesMysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 May
 
Call Girls in Gomti Nagar - 7388211116 - With room Service
Call Girls in Gomti Nagar - 7388211116  - With room ServiceCall Girls in Gomti Nagar - 7388211116  - With room Service
Call Girls in Gomti Nagar - 7388211116 - With room Service
 
GD Birla and his contribution in management
GD Birla and his contribution in managementGD Birla and his contribution in management
GD Birla and his contribution in management
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023
 
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
 
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒
 
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
 
Best Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in IndiaBest Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in India
 
Unlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdfUnlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdf
 
M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.
 
Pharma Works Profile of Karan Communications
Pharma Works Profile of Karan CommunicationsPharma Works Profile of Karan Communications
Pharma Works Profile of Karan Communications
 
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurVIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
 
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
Tech Startup Growth Hacking 101  - Basics on Growth MarketingTech Startup Growth Hacking 101  - Basics on Growth Marketing
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
 

ONE OF THE LARGEST ELECTRIC UTILITIES IN THE US

  • 1. CASE STUDY MetricStream POWERING COMPLIANCE AT AN ENERGY MAJOR Overview The company is a major integrated energy company engaged in power production, transmission and distribution involving natural gas, power and other energy related products. It is one of the largest electric utilities in the US. The company faces multiple compliance requirements from a number of regulatory bodies that impose regulatory oversight and reporting requirements. Industry regulations from FERC, NERC and state and regional public service commissions combined with cross-industry regulations like Sarbanes Oxley (SOX) impact all business functions operationally as well as strategically. These compliance require- ments affect a large number of business processes with many specialized processes being designed solely to meet specific regulatory guidelines. The cost of ensuring compliance in terms of time and resources is substantial. Moreover, the risk of noncompliance and other enterprise risks have to be Customer ONE OF THE LARGEST ELECTRIC UTILITIES IN THE US constantly monitored and mitigated for ensuring business performance and continuity. Challenge Benefits The company had internally developed an application for managing SOX and Enterprise Risk Manage- ment (ERM) processes using Microsoft Access and SQL Server technology. The system was designed Efficiency: The overall resource requirement and pro- to capture SOX and other risks, associated controls, control test plans, issues to highlight deficiencies cessing times for compliance programs is expected when controls failed testing and action plans to resolve the issues. to come down substantially due to an integrated compliance framework mapped to the organiza- In the last few years, the company experienced a significant increase in the number of compliance tional structure and responsibilities. The automated requirements to be met as well as additional scrutiny by the various regulatory bodies to determine workflows will take information and cases through that the company does in fact comply with those requirements. As the internally developed applica- the assessment, investigation, reporting and closure process without delays. Email notifications, task list, tion was designed for a narrow set of compliance requirements, the increasing regulatory demands and case status reports on the users’ homepage will started bringing forth the limitations of the application and its inherent approach. keep pending tasks on top of the mind improving responsiveness and proactive participation. As newer processes and record keeping was required, they were setup manually outside of the system as the application could not be extended. For example, the system could not map compliance Compliance: There will be a significant reduction in process to the general ledger balances and financial statements maintained in PeopleSoft and Cognos the risk of noncompliance as all the regulatory stan- applications. Keeping the automated processes in synch with the manual processes became a major dards and requirements will be clearly identified overhead as new accounts were created. and mapped to the processes, controls, activities and documents needed for compliance. Well-defined Another major limitation was that the internal application allowed only for a simplistic and linear orga- and automated assessments, issue reporting and remediation management workflows will ensure nizational setup and did not support the varying reporting relationships and information flows between sustainable compliance. testers, process owners and those who managed the overall compliance process for their business units. Visibility: With MetricStream, the company executives as well as functional managers will have The compliance surveys and certifications across various departments, locations and business units complete visibility into compliance programs at their involved manual distribution, gathering and consolidation of responses. Lack of automation made this respective levels of responsibilities. This transpar- activity excessively tedious and error prone with a number of documents being physically circulated ency will make compliance and risk management a and manually signed in the company. predictable process. The internal application did not support the periodic cycles and frequency of activities and record keeping for ongoing compliance leading to inefficient data reentry activities. Moreover, the application did not enforce appropriate authorizations to limit users from viewing information and records that they did not have privileges for violating a key compliance requirement. Solution MetricStream is enabling the company to adopt an integrated compliance strategy through an enterprise-level framework for managing all regulatory requirements and ERM programs. The solution will provide comprehensive functionality for managing SOX compliance and ERM as well as FERC and NERC regulations and corporate policies for standard of conduct. The company will defined and maintain a centralized structure of the overall compliance and control hierarchy based on regulatory standards and requirements. It includes processes and assets in scope, associated risks, controls to address the risks and mechanisms to assess the controls. It covers associated policies and procedures, reporting requirements and filing templates and schedules for various regulations.
  • 2. MetricStream Based on the compliance requirements and associated risk, the assessment plans will be scheduled Why MetricStream periodically or triggered based occurrence of certain adverse events. The system will integrate with other enterprises applications and implements rigorous change control to ensure all records, pro- An integrated platform and application environment cesses and documentation always stay in sync. to manage compliance with multiple regulations, corporate policies and industry standards. The system supports risk assessment and computations based on configurable methodologies and algorithms and will provide a clear view into organizations risk profile enabling managers to prioritize Comprehensive workflow-based functionality for SOX their response strategies and mitigation plans. compliance and the flexibility to extend the common framework and best practices for FERC and NERC compliance. “The MetricStream solutions will streamline our financial controls processes for SOX compliance as well as enabled us to employ best practices frameworks for managing compliance with FERC and Ability to support complex organizational models and NERC,” says a senior compliance officer of the company. For instance, risks such as failure to have a granular access controls while providing an easy- functioning Incident Response System or to meet Independent Functioning Guideline will be to-use portal-based interface for end-users for quick documented with their controls as well as their periodic assessment plans. “The framework will cover adoption. our incident response mechanism to report incidents to the Electricity Sector - Information Sharing and Analysis Center (ES-ISAC) based on reporting criteria, thresholds and procedures contained in Powerful reporting and analytics for complete vis- ibility into risk and compliance data on executive dashboards, control charts and risk heat maps. “MetricStream solutions will streamline our financial controls processes for SOX compli- ance as well as enable us to employ best practices frameworks for managing compliance with FERC and NERC.” says the spokesperson of the Company. NERC’s Indications, Analysis and Warning (IAW) Program. And we will conduct periodic assessments to ensure clearly defined and documented procedure for reporting security incidents, appropriate roles definition to deal with reporting and responding to security incidents, and a well defined line of com- munication and escalation path for reporting security incidents,” explains the executive. Hundreds of such processes, risk and controls will be documented and assessed using the MetricStream solution. Handling and reporting of noncompliance issues will be streamlined by automated workflows that document the issue and exceptions that pose a risk of noncompliance. The system will take them through a systematic mechanism of investigation and remedial corrective action. Embedded best practices for the energy industry combined with decision tree and workflow func- tionality will support identification of reportable events as well as the type of report that needs to be filed. The process of reporting will be simplified as the system automatically generates mandatory reports in formats and layouts prescribed by the agencies. The reports are generated in standard file types such as MS Word and can be reviewed before being submitted. “Selfreporting of noncompli- ance issues is critical for our business and if NERC finds noncompliance during their auditing, they can impose heavy fines”, says the compliance officer. MetricStream supports a complex organizational model to cover all the entities, business units and departments, as well as their mappings to various standards and requirements. With the granular access controls, the company will ensure confidentiality and the attorney-client privilege principle for sensitive information and records. The automated surveys and certifications powered by electronic signatures will be efficient, con- sistent and reliable. The solution will ensure accountability by enforcing the flow of information and records and documenting attestations and representations at appropriate stages and by responsible personnel that roll-up for executive certifications. Executive dashboards will provide enterprise wide visibility into the compliance and risk management process and highlight issues that need to be addressed in risk heat maps. The solution will provide the ability to track risk profiles, control ownership, assessment plans, remediation status, etc. on graphi- cal charts that can be accessed globally and display real-time information. For more information, visit www.metricstream.com Copyright 2011. All Rights Reserved.