07.10.2025
Blog
Resilience

A holistic approach to GRC: contracts, documents and compliance seamlessly integrated

Today, more than ever, organisations in the private and public sectors face the challenge of embedding governance, risk and compliance (GRC) issues into their day-to-day business processes. Contracts, documents, licence management and compliance with guidelines are key building blocks which, when working together, deliver significant added value. In our webcast, we demonstrated exactly how this can be achieved through the intelligent combination of OpenText SMAX and Core Content – in a practical, integrated and future-proof way.

Dr. Verena Pawolski
Consultant, OpenText Consulting Services

Contract Management at a Glance

A key feature is the contract overview. Users want to be able to see at a glance:

  • Which contracts are in place?
  • Are there any framework or sub-contracts?
  • What types of contracts are there and when do they expire?

SMAX provides precisely this overview. Through linked contracts, you can navigate the entire contract tree – from the main contract down to sub-contracts – and view the relevant information at any time.

When it comes to the finer details, things often become tedious: finding the right contact person, gathering documents, contacting departments. This is where the integration with OpenText’s Core Content comes in. You can open the relevant documents directly from within SMAX – without having to switch systems. The same document management system is also linked to Salesforce and SAP, so that all systems access the same documents. This prevents interface issues and version conflicts, and ensures seamless collaboration.

Core Content: More than just a document repository

Core Content brings structure and transparency to document management. A customisable dashboard allows you to organise favourites, important folders or workflows. Contracts, project documents or knowledge articles are therefore always quickly accessible.

Key features at a glance:

  • Versioning and comparison: Changes to documents are automatically detected and logged. New versions can be compared with older ones, with changes clearly highlighted.
  • Access management: Fine-grained permissions determine who is allowed to read, edit or share a document. Whether at group or document level – control remains with the organisation.
  • Workflows: Reviews, approvals and even signatures (e.g. via DocuSign) can be triggered automatically. This ensures that every change is reviewed and documented.

An example: A heading in a contract is amended. Core Content automatically generates a new version, triggers a workflow and forwards the change to the relevant person for review. It could hardly be more transparent or audit-proof.

Licence management as a compliance component

Another critical aspect of compliance is licence management. Licences are, after all, contracts that must be adhered to. With its Software Asset Management module, SMAX provides a clear overview:

  • Target view: Which licences have been purchased and are contractually in place?
  • Actual situation: Which licences are actually in use?

Using a CMDB, supplemented by automatic discovery, SMAX identifies installed software and reconciles it with the licence data. This reveals compliance breaches – whether they involve over-licensing (unnecessary costs) or under-licensing (risk of contractual breaches). A particular strength: OpenText provides a comprehensive database of licence metrics and vendor information, ensuring that detection is precise and reliable.

Compliance in incident, problem and change processes

Compliance is not merely a document or contract, but is embedded in operational processes:

  • A security incident can lead to a policy being amended.
  • A problem process uncovers repeated breaches and triggers changes.
  • A change process documents adjustments to policies or systems in an audit-proof manner.

Because SMAX operates with clearly structured workflows, compliance is automatically integrated into day-to-day operations. This reduces risks, prevents breaches and ensures that changes are traceable.

A holistic view of GRC

The combination of SMAX, Core Content and supplementary modules such as Business Continuity Management or Monitoring enables organisations and public authorities to map GRC issues comprehensively and across systems – without the need for additional stand-alone solutions.

The result:

  • A unified database
  • Seamless integration into existing systems
  • Transparent workflows
  • Reliable compliance with policies and contracts

Conclusion

The integration of contract management, document management, licence management and compliance processes into a single platform opens up entirely new possibilities for businesses: transparency, security and efficiency throughout the entire lifecycle. Governance, risk and compliance thus cease to be isolated tasks and become an integral part of day-to-day work – integrated, user-friendly and forward-looking.

Click here for the full webcast: GRC webcast recording

Read also:

Governance, Risk and Compliance in Service Management – Materna Blog

Business Continuity Management (BCM) and OpenText Service Management: A strong partnership for greater security and efficiency – Materna Blog

Keeping security incidents under control through monitoring and integration with OpenText – Materna Blog

Dr. Verena Pawolski
Consultant, OpenText Consulting Services

Dr Verena Pawolski works at Materna as a consultant in the OpenText Consulting Services division. She deals with a wide range of aspects relating to IT and enterprise service management and how these are mapped within the tool.

Related articles

Short News
Europe
Sustainability
Data & AI
28.08.2026
Green AI is not a romantic notion

Anyone wishing to operate AI in a sustainable, autonomous and responsible manner must take a holistic view of computing power, energy, governance, cybersecurity and resilience.

Read more
Blog
Verwaltung Digital
Sustainability
Public Sector
25.11.2025
Sustainability through IT: How digital services strengthen the state, society and the environment

In the sustainability sector, there is often talk of the ‘twin transformation’ – digitalisation and sustainability as a shared challenge. But how…

Read more
Blog
Sustainability
06.08.2024
‘Forest and Timber 4.0’ data room: sustainability redefined through AI

Sustainability is a concern for everyone. Materna is committed to developing and implementing sustainable solutions. The ‘CO2For-IT’ project…

Read more
Blog
Sustainability
10.04.2024
Future-proof data infrastructure: the key to effective ESG management

Given the growing importance of the European Sustainability Reporting Standards (ESRS), companies face the complex task of presenting their…

Read more
Blog
Sustainability
23.11.2023
ESG management: A digital and sustainable path to the future

To achieve long-term success, it is now essential for businesses to address their own environmental and social responsibilities. Find out how…

Read more
Blog
Sustainability
17.01.2023
From digital to sustainable transformation: ensuring the industry’s future viability

When it comes to future-proofing in industry, companies are faced with complex scenarios. Innovation and sustainable practices are essential.…

Read more
Blog
Sustainability
10.01.2023
From digital to sustainable transformation: strengthening resilience in industrial companies

How can industrial companies increase their resilience in a dynamic competitive environment and against a backdrop of global and macroeconomic…

Read more
Blog
Corporate
Sustainability
29.03.2022
Materna joins the UN Global Compact

The UN Global Compact is the world’s largest initiative for sustainable and responsible business practices. Materna has joined the initiative and…

Read more