Can compliance be a selling point?
- 30 March, 2006 09:32
- Comments
The first Australian bank or financial institution to crack the compliance and governance code could profit handsomely from the hard work.
Unisys predicts the first financial organization that can realistically tick all the boxes in relation to governance and compliance will be in a position to offer security as a "value-added" service to competitors in the banking industry.
Banks are fast-tracking their efforts to comply with the Sarbanes-Oxley Act's internal control reporting requirements by the July 15, 2006, deadline. Robert Dewar, Unisys financial services managing partner, said models have been designed showing how Australian banks and financial institutions can share infrastructure information and processes to not only meet compliance, but cover the costs of doing so.
"The discussion in boardrooms now is about the opportunity to utilize this very costly and expensive [compliance] infrastructure and set of capabilities that organizations are putting in place, and what is the opportunity to either create a new service offering or product," Dewar said.
"I think the key driver of 'utility security' is the large, legislative and compliance requirements around enterprise security and governance, [because] there are very serious and ongoing investments financial institutions have to make.
"As a result, some organizations could share infrastructure information and processes to achieve a shared utility thereby reducing the cost of meeting compliance.
"If a security utility is created that every one can participate in by sharing costs and information, then every one can benefit."
However, Hydrasight analyst Michael Warrilow disagreed.
Warrilow said every single security vendor is chasing the "holy grail" of compliance and not one has cracked it yet.
He said compliance, as a whole, creates nothing more for a bank or financial institution than an expensive "tick in the box". However, the smarter banks are using compliance legislation as a performance capability, rather than a cost centre.
"The road to compliance is the secret sauce that no bank will give away and the banks are cautious about letting any vendor know what they are doing," Warrilow said.
"What happens when security becomes a shared service is there is no competitive advantage from using appropriate security. Will a customer swap banks because they are Sarbanes-Oxley compliant?
"It is just the cost of doing business and banks want to drive costs down, but the smart ones will use compliance as a way to improve performance and use compliance as a performance capability rather than just see it as a cost."
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
- Blurring boundaries: The disappearing gap between work and home life
- The State of Data Security
- SOA Best Practices and Design Patterns
- Avaya Deploys the Avaya Desktop Video Device with the Avaya Flare® Experience
- TestPro achieves visibility over software defect management - Reducing project risk and improving quality
-
The NBN, service providers and you... what could go wrong?
-
NBN build gaining momentum daily: Quigley
-
FTC chairman: Do-not-track law may not be needed
-
Kindle sales soar but Amazon mum on actual numbers
-
Wall Street Beat: IPOs, M&A, chip news stir tech optimism
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Microsoft Office
-
Teach Yourself Visually Windows 7
-
MYOB Software for Dummies 6E Australian Edition
-
Windows 7 for Dummies®
-
Computers for Seniors for Dummies, 2nd Edition
-
Office 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Dummies® Dvd+book Bundle
-
Office 2007 for Dummies









Comments
Post new comment