28.01.2025
Blog
Regulatory
Resilience
Enterprise Service Management

Governance, Risk and Compliance in Service Management

Organisations strive to build a robust and resilient IT infrastructure that meets the demands of a dynamic business environment. A well-designed GRC programme helps them to pursue their business objectives with sustainability and integrity, manage risks effectively and carry out all activities in accordance with applicable regulations and legal requirements. Find out how service management tools can support this in the following article.

Dr. Verena Pawolski
Consultant, OpenText Consulting Services

Many organisations still document emergency and communication plans in Word or Excel files, which makes it difficult to link them to business processes. A GRC approach is significantly enhanced by the integration of an IT service management tool and offers organisations numerous additional benefits: By using such a tool, all relevant information – such as emergency plans, business processes, services and contracts – can be centrally consolidated in a Configuration Management Database (CMDB). This centralised database provides transparency regarding dependencies and interrelationships within the organisation, which makes it considerably easier to plan and implement measures. 

What is GRC? 

GRC stands for Governance, Risk and Compliance and describes a holistic, integrated approach that supports organisations in acting ethically and adhering to internal and external requirements. In doing so, GRC takes into account an organisation’s risk appetite – that is, its willingness to take risks. 

A key component of GRC is governance – the internal guidelines a company sets for itself in order to achieve objectives such as growth, new markets, sustainability or operational resilience. This is not just about setting objectives, but also about communicating them clearly and putting them into practice. Risks play an important role, as companies must clearly define their risk appetite. 

The ‘Risk’ component focuses on the analysis, assessment and minimisation of risks. Companies determine which risks they are willing to take and develop strategies to reduce them. Regular analyses, system-based monitoring and fixed schedules for reassessing risks are essential in this regard. Risk and governance are closely interlinked, as clear objectives always take risk appetite into account. 

Compliance ensures adherence to legal and regulatory requirements. Industry- and region-specific regulations such as BAIT, VAIT, DORA or KRITIS define requirements, particularly for critical infrastructure such as energy or water. With the NIS2 Directive, even more organisations are affected by these regulations to ensure the smooth operation of IT systems and infrastructure. 

Practical implementation in IT service management 

Compliance issues are closely linked to risk management, particularly in the field of IT. Organisations must develop contingency plans, identify risks and make their IT infrastructure resilient. At the same time, regulations often specify which measures are required within the governance framework, such as the filing of contingency plans. Implementing effective emergency management proves difficult if contingency plans and communication strategies are managed solely in Word or Excel documents. In such cases, the necessary context is often missing, and it becomes difficult to align these plans with the overarching business processes.  

When all these issues are considered within the context of IT service management or enterprise service management, their benefits become clear. Contingency plans designed to support specific services, as well as business processes based on these services, can be linked to a CMDB. This CMDB is an essential component of an IT Service Management suite and forms the basis for the implementation of contingency measures. The workflow engine of service management suites enables the step-by-step and (partially) automated execution of such contingency plans. For example, when a measure from a contingency plan is implemented, it often involves change management issues. Through changes or releases, specific measures can be carried out that alter the infrastructure of the environment. These changes are documented in the CMDB and are incorporated into future contingency plans or used to improve existing ones. 

Integration is key 

This foundation is already present in Business Continuity Management (BCM), particularly in contingency plans, risk registers and other relevant documents. The same applies to SecOps and contract management. Here, too, tasks can be assigned, which is a fundamental function of service management: allocating tasks and ensuring that the right people are informed. This can be achieved through automated emails or via Teams chat groups, which are used in IT service management to notify the relevant people quickly. 

In risk management, monitoring systems, vulnerability management and SIEM can be used to monitor risks. When security incidents are handled as part of Security Event Management and Security Incident Management, these issues are integrated into the IT service management context, which is based on the CMDB and works in conjunction with other IT incidents. Risk management is closely intertwined with IT service management processes, which also helps to ensure compliance with regulatory requirements. 

Everything at a glance 

GRC solutions such as those from OpenText also offer the option of managing IT contracts – such as maintenance, licence and purchase agreements – and linking them to infrastructure and services. This also enables comprehensive document management. Contracts play a central role in compliance and are relevant in many areas – be it licences, equipment or service providers. Service contracts must be stored in the CMDB so that they are accessible at all times. It is important to be familiar with the Service Level Agreements (SLAs) and to know who to contact in the event of an incident. Contract management must also be kept informed at all times of which contracts exist, what terms and conditions apply, and whether these contracts require regulatory assessment, whilst the infrastructure must also have access to these contracts. 

The close integration of business continuity management, SecOps, contracts, and governance, risk and compliance can be mapped within an IT service management tool. All these processes draw on the same IT service management processes, which are interlinked and serve as a common foundation. 

Further information is available on the Governance, Risk and Compliance with OpenText webpage. There you will also find the first part of our webcast series on the topic, as well as the latest white paper. 

Dr. Verena Pawolski
Consultant, OpenText Consulting Services

Dr Verena Pawolski works at Materna as a consultant in the OpenText Consulting Services division. She deals with a wide range of aspects relating to IT and enterprise service management and how these are mapped within the tool.

Related articles

Short News
Europe
Sustainability
Data & AI
28.08.2026
Green AI is not a romantic notion

Anyone wishing to operate AI in a sustainable, autonomous and responsible manner must take a holistic view of computing power, energy, governance, cybersecurity and resilience.

Read more
Blog
Verwaltung Digital
Sustainability
Public Sector
25.11.2025
Sustainability through IT: How digital services strengthen the state, society and the environment

In the sustainability sector, there is often talk of the ‘twin transformation’ – digitalisation and sustainability as a shared challenge. But how…

Read more
Blog
Sustainability
06.08.2024
‘Forest and Timber 4.0’ data room: sustainability redefined through AI

Sustainability is a concern for everyone. Materna is committed to developing and implementing sustainable solutions. The ‘CO2For-IT’ project…

Read more
Blog
Sustainability
10.04.2024
Future-proof data infrastructure: the key to effective ESG management

Given the growing importance of the European Sustainability Reporting Standards (ESRS), companies face the complex task of presenting their…

Read more
Blog
Sustainability
23.11.2023
ESG management: A digital and sustainable path to the future

To achieve long-term success, it is now essential for businesses to address their own environmental and social responsibilities. Find out how…

Read more
Blog
Sustainability
17.01.2023
From digital to sustainable transformation: ensuring the industry’s future viability

When it comes to future-proofing in industry, companies are faced with complex scenarios. Innovation and sustainable practices are essential.…

Read more
Blog
Sustainability
10.01.2023
From digital to sustainable transformation: strengthening resilience in industrial companies

How can industrial companies increase their resilience in a dynamic competitive environment and against a backdrop of global and macroeconomic…

Read more
Blog
Corporate
Sustainability
29.03.2022
Materna joins the UN Global Compact

The UN Global Compact is the world’s largest initiative for sustainable and responsible business practices. Materna has joined the initiative and…

Read more