28.01.2025
Blog
Regulatory
Resilience
Enterprise Service Management

Governance, Risk and Compliance in Service Management

Organisations strive to build a robust and resilient IT infrastructure that meets the demands of a dynamic business environment. A well-designed GRC programme helps them to pursue their business objectives with sustainability and integrity, manage risks effectively and carry out all activities in accordance with applicable regulations and legal requirements. Find out how service management tools can support this in the following article.

Dr. Verena Pawolski
Consultant OpenText Consulting Services

Many organisations still document emergency and communication plans in Word or Excel files, which makes it difficult to link them to business processes. A GRC approach is significantly enhanced by the integration of an IT service management tool and offers organisations numerous additional benefits: By using such a tool, all relevant information – such as emergency plans, business processes, services and contracts – can be centrally consolidated in a Configuration Management Database (CMDB). This centralised database provides transparency regarding dependencies and interrelationships within the organisation, which makes it considerably easier to plan and implement measures. 

What is GRC? 

GRC stands for Governance, Risk and Compliance and describes a holistic, integrated approach that supports organisations in acting ethically and adhering to internal and external requirements. In doing so, GRC takes into account an organisation’s risk appetite – that is, its willingness to take risks. 

A key component of GRC is governance – the internal guidelines a company sets for itself in order to achieve objectives such as growth, new markets, sustainability or operational resilience. This is not just about setting objectives, but also about communicating them clearly and putting them into practice. Risks play an important role, as companies must clearly define their risk appetite. 

The ‘Risk’ component focuses on the analysis, assessment and minimisation of risks. Companies determine which risks they are willing to take and develop strategies to reduce them. Regular analyses, system-based monitoring and fixed schedules for reassessing risks are essential in this regard. Risk and governance are closely interlinked, as clear objectives always take risk appetite into account. 

Compliance ensures adherence to legal and regulatory requirements. Industry- and region-specific regulations such as BAIT, VAIT, DORA or KRITIS define requirements, particularly for critical infrastructure such as energy or water. With the NIS2 Directive, even more organisations are affected by these regulations to ensure the smooth operation of IT systems and infrastructure. 

Practical implementation in IT service management 

Compliance issues are closely linked to risk management, particularly in the field of IT. Organisations must develop contingency plans, identify risks and make their IT infrastructure resilient. At the same time, regulations often specify which measures are required within the governance framework, such as the filing of contingency plans. Implementing effective emergency management proves difficult if contingency plans and communication strategies are managed solely in Word or Excel documents. In such cases, the necessary context is often missing, and it becomes difficult to align these plans with the overarching business processes.  

When all these issues are considered within the context of IT service management or enterprise service management, their benefits become clear. Contingency plans designed to support specific services, as well as business processes based on these services, can be linked to a CMDB. This CMDB is an essential component of an IT Service Management suite and forms the basis for the implementation of contingency measures. The workflow engine of service management suites enables the step-by-step and (partially) automated execution of such contingency plans. For example, when a measure from a contingency plan is implemented, it often involves change management issues. Through changes or releases, specific measures can be carried out that alter the infrastructure of the environment. These changes are documented in the CMDB and are incorporated into future contingency plans or used to improve existing ones. 

Integration is key 

This foundation is already present in Business Continuity Management (BCM), particularly in contingency plans, risk registers and other relevant documents. The same applies to SecOps and contract management. Here, too, tasks can be assigned, which is a fundamental function of service management: allocating tasks and ensuring that the right people are informed. This can be achieved through automated emails or via Teams chat groups, which are used in IT service management to notify the relevant people quickly. 

In risk management, monitoring systems, vulnerability management and SIEM can be used to monitor risks. When security incidents are handled as part of Security Event Management and Security Incident Management, these issues are integrated into the IT service management context, which is based on the CMDB and works in conjunction with other IT incidents. Risk management is closely intertwined with IT service management processes, which also helps to ensure compliance with regulatory requirements. 

Everything at a glance 

GRC solutions such as those from OpenText also offer the option of managing IT contracts – such as maintenance, licence and purchase agreements – and linking them to infrastructure and services. This also enables comprehensive document management. Contracts play a central role in compliance and are relevant in many areas – be it licences, equipment or service providers. Service contracts must be stored in the CMDB so that they are accessible at all times. It is important to be familiar with the Service Level Agreements (SLAs) and to know who to contact in the event of an incident. Contract management must also be kept informed at all times of which contracts exist, what terms and conditions apply, and whether these contracts require regulatory assessment, whilst the infrastructure must also have access to these contracts. 

The close integration of business continuity management, SecOps, contracts, and governance, risk and compliance can be mapped within an IT service management tool. All these processes draw on the same IT service management processes, which are interlinked and serve as a common foundation. 

Further information is available on the Governance, Risk and Compliance with OpenText webpage. There you will also find the first part of our webcast series on the topic, as well as the latest white paper

Dr. Verena Pawolski
Consultant OpenText Consulting Services

Dr. Verena Pawolski arbeitet bei Materna als Consultant im Bereich OpenText Consulting Services. Sie beschäftigt sich mit den verschiedensten Aspekten rund um die Themen IT- und Enterprise Service Management und deren Abbildung im Tool.

Related articles

Blog
Verwaltung Digital
08.09.2026
EUDI Wallet: Why digital identities now need to be integrated into business processes

Imagine you want to take out a life insurance policy or open a bank account online, and all you have to do is log in and verify your identity via your…

Read more
Press
Dortmund/Berlin
02.09.2026
Materna and deepset are strengthening cutting-edge AI made in Germany

Materna and deepset are combining their expertise to advance the confident use of artificial intelligence in the public sector and in regulated industries. Their joint offering combines Materna’s experience in digitizing complex administrative and IT…

Read more
Blog
Enterprise Service Management
Cloud Transformation
01.09.2026
From strategy to implementation: How sovereign cloud platforms enable digital independence

Cloud sovereignty has evolved from a political buzzword into a concrete requirement for businesses and public authorities. However, once the strategic…

Read more
Blog
Digital Experience
25.08.2026
Design systems as the foundation of digital applications

Nowadays, digital products are rarely developed in isolation. Websites, apps, portals and service applications are all interconnected and must…

Read more
Blog
Resilience
20.08.2026
That is why drone detection is an IT issue

When people think of drone detection, the first things that spring to mind are radar, cameras or anti-drone systems. These technologies are…

Read more
Blog
Data & AI
18.08.2026
From Key Figures to Decisions: The Next Stage in the Evolution of Information Sharing within Organisations

Companies today measure almost everything. Capacity utilisation, project metrics, turnover, margins and forecasts are available at any time in…

Read more
Blog
Cyber Security
11.08.2026
Detecting and intercepting drones: the solutions are already available

How well are critical infrastructures protected against drone attacks? The security incident at Leipzig/Halle Airport has sent shockwaves through…

Read more
Blog
Cyber Security
11.08.2026
Cyber Security 2026: These trends are shaping both the business sector and public administration

In 2026, cyber security will be more of a focus than ever for businesses, government agencies and public institutions. According to the Lünendonk…

Read more
Blog
Enterprise Service Management
Cloud Transformation
04.08.2026
From ‘Cloud First’ to ‘Sovereignty First’: The rules of the cloud are changing

Cloud technologies are driving innovation. At the same time, the demands for control, compliance and digital sovereignty are growing. Particularly…

Read more
Short News
Corporate
Cyber Security
31.07.2026
From Rising Star to Leader: Materna has been recognised as a Leader in Strategic Security Services in the ISG Provider Lens™ Cyber Security – Services and Solutions 2026

ISG has recognised Materna as a leading provider of cyber security consultancy in Germany.

Read more