The areas of Governance, Risk and Compliance (GRC) and innovation are under-explored in research generally, and specifically in sustainability-oriented research. In this paper we propose a practice-based concept of Compliance-Innovation and set out its significance for sustainability. Development of the concept is based on a literature review and exploratory qualitative research with eighteen practitioners. The concept acknowledges the central role of knowledge integration across business domains as the basis of modern competitive advantage. The absence of such integration in the GRC and innovation domains, revealed in practice, opens opportunities. The governing force for such integration is presented here as sustainability, when applied as a strategic orientation for business. We outline how the integration of GRC and innovation domains drive commercial exploitation for environmental sustainability and business sustainability. Building on the concept of Absorptive Capacity we identify both external and internal sources of knowledge as determinants of organization's selected sustainability goals, which are relevant across the phases of organizations' innovation activities throughout its Innovation Value Chain. We argue that a quality-based orientation is necessary to derive value from the networks employed in applying the concept in practice.
Motivated by a gap in the literature linking compliance and innovation, this paper develops the novel concept of Compliance-Innovation (C-I). Based on a review of the literature and interviews with experienced practitioners, we characterise C-I as a transformational process to drive organisational improvements in sustainability and competitiveness. We explain how the organisational mechanism that permits identification and exploitation of knowledge for commercial purposes, i.e. Absorptive Capacity, may be enlarged through application of C-I because both external and internal contexts are appropriately and comprehensively incorporated. C-I's roots lie in the integration of quality and compliance knowledge into a central IT repository, and its potential for commercial exploitation through, for example, the Six Sigma approach is outlined - indicating its usefulness for orienting business focus, performance and innovation.
The organisational capacities to absorb, adapt and reconfigure resources in response to market challenges, regulatory reform and complex stakeholders and their expectations is necessary to achieve the strategic growth businesses need. Through the Mind-of-the Product (MotP) concept we outline how the variety of targets demanding business attention can cohere to support innovation grounded in compliance-centred processes. The MotP is developed as a foundational leadership concept for integrating organisational knowing, innovation and knowledge management.
Strategic growth can be delivered through Innovative Compliance a process through which conformity with requirements - compliance - drives improvements in quality, productivity and competitiveness. In this process GRC is an engine for growth by facilitating commercialisation of knowledge and business sustainability. The integration of Governance, Risk & Compliance (GRC) with Innovation activities and business strategy is what we mean by strategic growth. Maintaining attention and focus on growth is a challenge for business in the face of increasing demands on Boards and Directors to address not only considerably more but increasingly complex types of risks. At the same time, capacity to adapt and reconfigure resources in response to market challenges, regulatory reform and complex stakeholder influences and expectations is necessary to achieve the strategic growth businesses need. Innovation can be driven by a company's GRC orientation in the context of its corporate GRC memory as well as its business strategy supported appropriately with technology. We term this orientation Innovative Compliance. One vital element for Innovative Compliance is access to timely regulatory-compliance data structured in line with a business's product, market and geography focus: decision makers need actionable information. Modern IT makes this increasingly possible which is particularly welcome since much of the regulation aimed at business is not provided in a format or through channels or in a timely fashion to meet businesses' information needs. A further necessity for Innovative Compliance is the ability of business to assimilate and transform regulatory and compliance data so that it can be exploited for commercial ends. This depends on an organisation's Absorptive Capacity. In specifically GRC terms Absorptive Capacity gets at the ability to nail the various intersections of three fast moving business targets i.e. (i) new regulations (ii) product evolution (new & improved) and (iii) intra-organisational strategic imperatives. IT must simultaneously support all three aspects. Knowledge integration is the basis of modern competitive advantage and the strategic growth orientation of the business is the governing force for such integration. Modern Compliance Knowledge Management Systems can support this imperative. To operationalize Innovative Compliance executives must bring together teams of knowledge workers who are differentiated by their knowledge bases and support them to integrate the knowledge across the bases. The nature and extent of integration must resonate with the business reality of growth-oriented GRC functional experts, whatever their title, domain or expertise. In the absence of such integration - GRC, Innovation, IT and Strategy - productive growth opportunities are being missed.
Environmental concerns have led to a significant increase in the number and scope of compliance imperatives governing electrical, electronics, and IT products across global regulatory environments. This is, of course, in addition to general compliance and risk issues generated by the Sarbanes-Oxley Act, data protection and information privacy legislation, ethics and integrity regulations, IT governance concerns, and so on. While the latter dimensions of enterprise-wide governance, compliance, and risk (GRC) are far from straightforward, the complexity and geographical diversity of environment-based regulatory sources cause considerable problems for organisations in the electrical, electronics and IT sectors. Although a variety of enterprise-level information systems are presently available to help manage compliance and reduce risk across all areas, a majority of firms still employ ad-hoc solutions. This paper focuses on the very-much underexplored issue of environmental compliance and risk. The first objective of this exploratory study is to delineate the problems facing GRC and Environmental Health and Safety (EH&S) functions in dealing with environmental regulations globally and to identify how these problems are being solved using Environmental Compliance Management Systems (ECMS). The second objective is to propose a process-based conceptual model and related IS framework on the design and adoption of ECMS that will inform future research and, it is hoped, the IS adoption decisions of GRC and EH&S practitioners.
In recent years, environmental concerns have led to a significant increase in the number and scope of compliance imperatives across all global regulatory environments. The complexity and geographical diversity of these environments has caused considerable problems for organizations, particularly those in high-technology industries. This paper first employs institutional theory to help understand the challenges for information technology manufacturing organizations that emanate from global institutional environments. While cultural-cognitive and normative influences from society-at-large and industry-based bodies have stimulated environment-oriented corporate social responsibility initiatives, it is undoubtedly regulatory influences that have generated the deepest responses in terms of the adoption of new compliance-oriented procedures and protocols. This paper first describes the general response from the organizational field in which high-technology firms operate and notes the extent of the response, with. environmental compliance management systems being one of the institutional arrangements that organizations have adopted The findings of empirical research based on Compliance & Risks Ltd's compliance-to-product application and its deployment in Napa Inc., a Silicon Valley-based Fortune 500 company, are then offered and analyzed to illustrate the scale and scope of information systems support required to institute adequate compliance-oriented protocols and procedures in response to global regulatory influences, while also answering concerns raised by normative and cultural-cognitive sources.
The research question that underpins this paper is ‘What are the novel features of IS design practice ‘in the wild’? In order to help answer this question, a theoretical perspective that focuses on practitioners’ ‘situated practical theory’ in the ‘co-production’ of IS designs is adopted. The context for this study is that firms operating in the IT sector face particular challenges in navigating the complex web of global regulatory requirements. Accordingly, practitioners indicate the need for IT artefacts to informate and help automate compliance processes in organizations. This paper reports on the design of an innovative IT artefact called Compliance-to-Product (C2P), which is argued to be in the vanguard of a new breed of IS called Compliance Knowledge Management Systems (CKMS). The paper describes how this IT artefact was designed by a small-to-medium sized software enterprise, whose design architecture originated in the ‘situated practical theory’ of the company’s founder. However, the findings illustrate that the detailed design was ‘co-produced’ by a network of social actors from collaborating organizations and that this emerged over time. The paper’s concluding observation is that the findings pose a question for design science and the claims for its ability to shape design practice.
Addressing the complexity of the growing number of regulatory instruments emanating from global institutional environments has prompted firms in the IT sector to adopt innovative information technologies to help manage compliance and related organizational risks. This paper first employs institutional theory to help explain how a range of exogenous regulative, normative and cultural cognitive factors are influencing IT manufacturers’ adoption decisions on IT-based compliance solutions. The paper also draws on organizational theory to describe the endogenous institutional arrangements knowing organizations need to implement in order to address the challenges posed to them while operating in such environments. The findings of a case study on the adoption of what Napa Inc., a Fortune 500 IT manufacturer, considers to be the most innovative compliance management solution on the market, illustrates, that in order to be effective, such applications must support organizational sense making, decision taking and knowledge creation and management. Each of these activities are argued to be key characteristics of knowing organizations and collectively they underpin Loop III Learning, the absence of which results in suboptimal results for firms in dealing with compliance imperatives and addressing associated risks.