Compliance and risk professionals know that having an enterprise-wide view of risks is far more effective than trying to manage risks in a fragmented way, and that achieving this objective through automation is far more efficient and cost-effective than manual processes and controls. Even knowing that, however, many organizations’ enterprise risk management (ERM) capabilities still aren’t as integrated as they need to be, leaving them vulnerable to legal, financial, regulatory, and reputational risks.

That was just one of many key findings to come from a recent governance, risk, and compliance (GRC) benchmark report conducted by Compliance Week, in partnership with Riskonnect, an integrated risk management solutions provider. The survey polled 113 compliance, risk, and audit executives from around the world—including the United States, Europe, Asia-Pacific, and Latin America—to get a better sense of the state of organizations’ risk management capabilities; how effective they are at mapping risks; what GRC metrics they track; and much more.

Jaclyn Jaeger is a freelance contributor to Compliance Week after working for the company for 15 years. She writes on a wide variety of topics, including ethics and compliance, risk management, legal,...