UTBMS codes / Governance, risk & compliance
UTBMS Governance, Risk & Compliance Codes
177 codes, G1xx-G8xx. Published by the LEDES Oversight Committee (LOC) in 2015.
A three-level code set (category, phase, task) mapping legal work to the OCEG GRC Capability Model.
When to use it: Compliance, governance, and risk advisory work that the counseling codes are too coarse to describe.
The full list: 177 codes
| Code | Name | Definition |
|---|---|---|
| G100 | Context | OCEG GC000 |
| G110 | External Context | OCEG GC100 |
| G111 | Analyze the External Business Context | Identify and analyze the relevant external business context factors.Encompasses high-level strategic recommendations and analysis of legal, regulatory, and geopolitical climate for requirements generally in the industries in which the organization operates. OCEG GC101 |
| G112 | Analyze External Stakeholder and Influencer Needs | Identify key external stakeholders, and influencers of opinion, and analyze and prioritize their needs and requirements.Encompasses all analysis of issuing authorities of requirements and opportunities to influence the thinking of regulators and legislators affecting the industry in which the organization operates. OCEG GC102 |
| G120 | Internal Context | OCEG GC200 |
| G121 | Define the Internal Context | Identify the key structures and assets that define the Internal Context.Encompasses new legal entity creation, mergers, acquisitions, joint ventures, and dissolution. OCEG GC201 |
| G122 | Determine Changes Needed to Align the Internal Context and GRC capability | Identify possible changes to the internal context that may affect design aspects of the GRC capability or ensure alignment.Encompasses maintenance of legal entities, resolutions for changes to boards, officers, directors and organizational structure. OCEG GC202 |
| G130 | Culture | OCEG GC300 |
| G131 | Analyze Ethical Culture | Analyze the existing climate (observable, formal elements in the organization) and individual mindsets about the degree to which the workforce believes the organization expects and supports responsible behavior and integrity.Encompasses advising on ethics program requirements for all operating jurisdictions. OCEG GC301 |
| G132 | Analyze Ethical Leadership | Analyze whether leadership sets an appropriate "tone at the top" and models behavior in both words and deeds.Encompasses advising on permissible basis for employee evaluations and management development and training programs. OCEG GC302 |
| G133 | Analyze Risk Culture | Analyze the existing climate and individual mindsets about how the workforce perceives risk, its impact on their work and the organization as a whole.Encompasses consulting on risk components of strategic planning, executive management, and risk management programs. OCEG GC303 |
| G134 | Analyze Board Involvement | Analyze the degree to which the Board is involved and engaged in the organization.Encompasses advising on board's fiduciary duties, other legal obligations in how business is conducted and reporting irregularities. OCEG GC304 |
| G135 | Analyze Governance Culture and Management Style | Analyze the existing approach to governing, managing and enabling the workforce.Encompasses consulting on governance, delegations of authority, and organizational effectiveness. OCEG GC305 |
| G136 | Analyze Workforce Engagement | Analyze the existing workforce culture including the degree of employee satisfaction, loyalty and engagement.Encompasses consulting on workforce management, including advising on employee reimbursement, leave and benefits plans. OCEG GC306 |
| G140 | Objectives | OCEG GC400 |
| G141 | Define Mission & Vision | Create a formal statement of the organization's mission and vision.Encompasses strategic advisory services engagements and advice on permissible legal entity purposes. OCEG GC401 |
| G142 | Define Values | Create a formal statement of the core values that the organization holds and applies to its business decisions.Encompasses strategic advisory services on post-merger and post-acquisition integration. OCEG GC402 |
| G143 | Define Business Objectives | Define a balanced set of measurable business objectives that are congruent with mission, vision and values.OCEG GC403 |
| G144 | Define Risk Appetite and Decision Criteria | Define the approach and criteria for making decisions about the pursuit of risk relative to reward including risk appetite, tolerance and capacity.Encompasses advisory services related to measurement of risk, including key risk indicators. OCEG GC404 |
| G145 | Define Indicators, Targets and Tolerances | Define a balanced set of leading and lagging indicators that help management understand if the organization is meeting its business objective targets within defined tolerances.Encompasses development and advisory services on metrics and key performance indicators for the organization. OCEG GC405 |
| G146 | Obtain Commitment to Mission, Vision, Values and Objectives | Obtain commitment from management and Board members about what the organization will achieve while living by its values.Encompasses approvals of the metrics and performance measurement program. OCEG GC406 |
| G147 | Communicate Mission, Vision and Values | Communicate the mission, vision and values to internal and external stakeholders.Encompasses legal review of corporate communications, shareholder communications, and public communications regarding the organization outside of communications to affect changes to the legal and geopolitical climate, internal training, and crisis response communications. OCEG GC407 |
| G200 | Organize | OCEG GO000 |
| G210 | Commitment | OCEG GO100 |
| G211 | Define GRC capability Scope | Define the scope of the GRC capability or subsystem under consideration.Encompasses advisory services on strategic planning and operational implementation of GRC capabilities, including governance, risk management, compliance, and ethics programs. OCEG GO101 |
| G212 | Define GRC capability Style and Goals | Define the overall style of the GRC capability, what it will achieve, and how it relates to business objectives.Encompasses advisory services on program measurement and integration plan for GRC capability. OCEG GO102 |
| G213 | Obtain Commitment to the GRC capability | Obtain explicit written authorization and high-level support for the GRC capability.Encompasses presentations and recommendation of GRC strategic and operational plans for organizational approval. OCEG GO103 |
| G220 | Roles | OCEG GO200 |
| G221 | Define and Enable GRC capability Oversight Roles and Accountability | Define oversight roles, responsibilities and accountability for each aspect of the GRC capability.Encompasses advisory, legal, and consulting services on implementation of oversight portion of strategic GRC plan, including job descriptions, background checks, and training on legal requirements of oversight roles. (This is distinct from the compensation, rewards, and promotion criteria for general population defined under GP5.1 et seq.) OCEG GO201 |
| G222 | Define and Enable Management Roles and Accountability | Define management roles, responsibilities and accountability for certain aspects of the GRC capability.Encompasses advisory, legal, and consulting services on implementation of management portion of strategic GRC plan, including job descriptions, background checks, and training on legal requirements and assumed voluntary mandates for GRC management positions. (This is distinct from the compensation, rewards, and promotion criteria for general population defined under GP5.1 et seq.) OCEG GO202 |
| G223 | Define and Enable Leadership Roles and Accountability | Define individuals to serve in leadership roles to champion the GRC capability or certain aspects of the system and establish methods to ensure they possess the desired character ethics.Encompasses advisory, legal, and consulting services on implementation of leadership roles in strategic GRC plan, including job descriptions, background checks, and training on legal requirements and assumed voluntary mandates for GRC leadership positions. (This is distinct from the compensation, rewards, and promotion criteria for general population defined under GP5.1 et seq.) OCEG GO203 |
| G224 | Define and Enable GRC Capability Operational Roles | Define the roles required to deliver, operate, and execute GRC Capability practices.Encompasses advisory, legal, and consulting services on implementation of operational GRC roles, including job descriptions, background checks, training on legal requirements and assumed voluntary mandates for GRC operational positions and monitoring compliance with certifications. (This is distinct from the compensation, rewards, and promotion criteria for general population defined under GP5.1 et seq.) OCEG GO204 |
| G225 | Define and Enable Assurance Roles and Accountability | Define assurance roles, responsibilities and accountability for certain aspects of the GRC capability (e.g., chief audit executive, external auditor)Encompasses advisory, legal, and consulting services on implementation of assurance roles, including job descriptions, training on legal requirements and assumed voluntary mandates for GRC assurance, and monitoring compliance with certifications and licensure requirements. (This is distinct from the compensation, rewards, and promotion criteria for general population defined under GP5.1 et seq.) OCEG GO205 |
| G230 | Accountability | OCEG GO300 |
| G231 | Allocate Accountability to Individuals and Committees | Allocate GRC roles and responsibilities to individuals and committees.Encompasses documentation and implementation of delegation of authority, segregation of duties, and approval process workflows. OCEG GO301 |
| G232 | Define GRC Capability Processes and Integrate with Business Processes | Define GRC Capability processes and synchronize with existing business processes.Encompasses documentation and advisory services on implementation planning for GRC business process workflows. OCEG GO302 |
| G233 | Define Measurement and Evaluation Approach | Define an approach to measure and evaluate the effectiveness, efficiency, and responsiveness of the GRC capability.Encompasses development and advisory services on metrics and key performance indicators for the GRC capabilities of the organization. OCEG GO303 |
| G234 | Define Organizational Change Management Approach | Define an approach to ready the organization for any changes that the GRC capability may require to people, processes, and technology.Encompasses advisory services on design and implementation planning for change management program rather than implementation of a particular change initiative. OCEG GO304 |
| G235 | Develop, Maintain and Authorize a Business Case | Develop a business case for the GRC capability and obtain authorization from senior management and the Board.Encompasses advisory services on development and presentation of GRC program level business case as well as business cases for individual GRC initiatives. OCEG GO305 |
| G300 | Assess | OCEG GA000 |
| G310 | Identification | OCEG GA100 |
| G311 | Review Business Objectives, Processes and Resources | Identify and review key business objectives, processes and resources that are relevant given the scope of the capability (e.g., if the scope is the entire organization, then all business objectives, processes and resources are relevant; if the scope is a single department, then some subset of business objectives, processes and resources are relevant).Encompasses consulting on legal, risk, compliance, ethics and audit function capabilities design (performance, and improvement fall under GM2 and GM3). OCEG GA101 |
| G312 | Identify External Sources and Forces | Imagine and identify external sources and forces that may produce a requirement or cause a desirable or undesirable effect on objectives.Encompasses researching and profiling the predilections, temperament of, and enforcement trends emanating from existing and emerging sources and forces in the legal and geopolitical climate at a holistic level. (Captures more granular research than GC1.2, but not down to individual profiles prepared and specific activities monitored under GP6.1 et seq.) OCEG GA102 |
| G313 | Identify Internal Sources and Forces | Imagine and identify internal sources and forces that may produce a requirement or cause a desirable or undesirable effect on objectives.Encompasses evaluation of scope and impact of previously implemented business models and implications of implemented changes in human capital, technology, processes, and organizational structure. OCEG GA103 |
| G314 | Identify Opportunities & Threats | Given the sources and forces, identify opportunities and threats that affect the achievement of objectives. Opportunities are events and conditions that, on balance, contribute to reward (which is a measure of the desirable effect of uncertainty on objectives) -- while threats are events and conditions that, on balance, contribute to risk (which is a measure of the undesirable effect of uncertainty on objectives).Encompasses advisory services, and legal opinions on opportunity and threat assessments, including competitive IP portfolios, pending IP applications, proposed laws, regulations, treaties, executive orders, judicial decisions, M&A targets, and divestiture recommendations. (This initial identification is distinct from ongoing monitoring and tracking as captured in GP6.3). OCEG GA104 |
| G315 | Identify Mandatory & Voluntary Requirements | Given sources and forces, identify mandatory and voluntary requirements that must be addressed.Encompasses research and notifications about existing legal climate of new jurisdictions, new products, new operations, or a combination of these based on enacted laws, regulations, executive orders, treaties, and judicial decisions. As well as advisory guidance on standards participation, desired certifications, warranties, and representations. (This initial identification is distinct from ongoing monitoring and tracking as captured in GP6.3). OCEG GA105 |
| G316 | Identify Interrelatedness & Trends | Identify how opportunities, threats and requirements relate to one another and how they have been trending both internally and externally with industry peers.Encompasses legal analysis of the integration between trans-national (i.e., non-governmental bodies), multi-national, national, regional, territorial and local levels of legal and regulatory mandates, treaties, reciprocal agreements, judicial opinion, administrative decisions, guidance, and conflicts between applicable requirements, enforcement and litigation trends. OCEG GA106 |
| G317 | Conduct High Level Analysis of Risk/Reward | Conduct a high-level analysis of inherent, current and planned residual risk/reward so that the most relevant items are prioritized in future, more detailed analysis.Encompasses legal information on theoretical exposure for single instance and pattern of non-compliance with requirements. (This analysis of theoretical exposure is distinct from actual impact on specific organization as captured in GA2.1 et seq.). OCEG GA107 |
| G318 | Conduct High Level Analysis of Requirements Impact/Conformance | Conduct a high-level analysis of inherent, current and planned level of conformance with requirements, including rough economic analysis, so that the most relevant items are prioritized in future, more detailed analysis.Encompasses legal analysis of potential impacts from legal climate for players in the industry or market generally, as well as, advisory opinions on impacts of standards participation, certifications, warranties, and representations across industry. (This analysis of theoretical exposure is distinct from actual impact on specific organization as captured in GA2.1 et seq.). OCEG GA108 |
| G319 | Assign Accountability to Monitor Changes | Assign accountability for monitoring the underlying sources that may lead to events and conditions that positively or negatively effect objectives.Encompasses creation of the relationship for advisory, legal or consulting services designed to monitor changes. (This creation of the relationship is distinct from actual performance of the services as captured in GP6.3). OCEG GA109 |
| G320 | Analysis | OCEG GA200 |
| G321 | Analyze Approach to Requirements | Analyze the current and planned actions and controls to address requirements including costs.Encompasses fact finding to determine current approaches to compliance. OCEG GA201 |
| G322 | Analyze Inherent Risk/Reward | Analyze the effects of threats and opportunities without consideration of current actions or controls.Encompasses legal opinions of potential impacts from legal climate for this client, as well as, advisory opinions on impacts of standards participation, certifications, warranties, and representations. Encompasses legal opinions regarding potential impacts of IP invalidity and contract unenforceability. OCEG GA202 |
| G323 | Analyze Current Approaches to Risk/Reward | Identify the presence and effectiveness of current actions and controls that are in place to address the effect of threats and opportunities.Encompasses legal opinions on whether current approaches are sufficient for compliance and likely outcome of enforcement actions, as well as, advisory opinions on compliance with standards participation, certifications, warranties, and representations for this client. Encompasses legal opinions regarding suitability of current IP protection practices and standard contract provisions to abate or mitigate threats and seize opportunities. OCEG GA203 |
| G324 | Determine Current Residual Risk/Reward | Determine the current level of risk/reward remaining given the presence and effectiveness of current actions and controls.Internal legal and management opinion -- external charges should not apply. OCEG GA204 |
| G325 | Prioritize Threats, Opportunities and Requirements | Prioritize and categorize threats, opportunities and requirements to determine approach and resource allocation.Encompasses advisory services, audit recommendations, and legal opinions regarding the independent priority of threats, opportunities and requirements, including priority assessment as one component of the business case for action. OCEG GA205 |
| G330 | Planning | OCEG GA300 |
| G331 | Explore Options to Address Requirements | When current level of conformance is not acceptable, or when existing actions and controls are not optimal, explore additional actions and controls to address requirements.Encompasses project, program, personnel, and technology advisory services for implementation of compliance programs for discrete initiatives. OCEG GA301 |
| G332 | Explore Options to Address Risk/Reward | When the current residual risk is unacceptable or when current approach can be improved, explore alternative actions and controls to address risk/reward.Encompasses project, program, personnel, and technology options assessment services for implementation of risk management programs for discrete risks/rewards. OCEG GA302 |
| G333 | Determine Planned Residual Risk/Reward and Conformance | Determine the level of risk/reward and conformance that will remain after planned actions and controls are established and operating effectively.Internal legal and management opinion -- external charges should not apply. OCEG GA303 |
| G334 | Address Inherently High Risk | Identify current and planned actions and controls that specifically address inherently high risk and that, should they cease to perform effectively, will expose the organization to unacceptable levels of risk.Internal legal and management opinion -- external charges should not apply. OCEG GA304 |
| G335 | Develop Key Indicators | Develop key indicators that inform management about the level of performance, risk and conformance.Encompasses advisory and technological services in developing indicators and implementing the monitoring, alerts, and reporting on those indicators. OCEG GA305 |
| G336 | Develop Integrated Plan | Develop a plan to govern, assure and manage the approach to addressing performance, risk and compliance.Encompasses advisory services, audit recommendations, and legal opinions regarding the relative priority of threats, opportunities and requirements, including priority assessment as one component of the business case for action. OCEG GA306 |
| G400 | Proact | OCEG GP400 |
| G410 | Proactive Actions & Controls | OCEG GP100 |
| G411 | Establish Proactive Management Actions and Controls | Establish proactive management actions and controls that incent desirable, and prevent undesirable, events and conditions.Encompasses development of contract templates and playbooks with standard acceptable provisions (negotiated changes to contracts fall under GR1.1 and specific provisions that shift financial risk fall under GP7.1 et seq.), standard due diligence requests for M&A transactions, IP disclosure procedures, assignment practices, and incentive programs. Also includes the accountability and authorization process for waivers, exceptions and variances to company-adopted standards. Lastly, includes any expected management actions and controls to be promulgated through supply chain, joint venture, and business partner programs. OCEG GP101 |
| G412 | Establish Preventive Process Controls | Establish preventive process control activities and procedures to reduce the likelihood and/or impact of adverse events, noncompliance and misconduct.Encompasses development of all departmental procedures to ensure engagement of service providers is done consistently with policy directives. Also encompasses, all design of processes and accountability for securing facility and operational permits and licenses. Also includes any expected preventive process controls to be promulgated through supply chain, joint venture, and business partner programs. OCEG GP102 |
| G413 | Establish Preventive Human Capital Controls | Establish preventive human capital controls to reduce the likelihood and/or impact of adverse events, noncompliance and misconduct.Encompasses all advisory services, recommendations, and legal opinions on establishing particular roles, all job descriptions, background checks, delegations of authority, divisions of responsibility between roles, and lines of reporting. Also includes any expected human capital controls to be promulgated through supply chain, joint venture, and business partner programs. OCEG GP103 |
| G414 | Establish Preventive Technology Controls | Establish preventive technology controls to reduce the likelihood and/or impact of adverse events, noncompliance and misconduct.Encompasses all advisory services, recommendations, and legal opinions regarding configuration of access controls, required systems, configuration controls, master data, and business rules enforced through business rules engines to assure compliance with mandates and execution of activities in line with risk appetite. OCEG GP104 |
| G415 | Establish Preventive Physical Controls | Establish preventive physical controls to reduce the likelihood and/or impact of adverse events, noncompliance and misconduct.Encompasses all advisory services, recommendations, and legal opinions regarding physical controls (i.e., badges, biometric devices, RFID, gates, clean rooms, barriers, cabinets, etc.), related to security of and access to facilities, physical assets, information assets, or IP, and required to protect environment, and human health and safety. OCEG GP105 |
| G420 | Codes of Conduct | OCEG GP200 |
| G421 | Develop the Code of Conduct | Work with appropriate stakeholders to develop a code of conduct that addresses the organizational mission, vision, values, key policies and expected business conduct.Encompasses advisory services related to all aspects of determining and updating the content for the Code of Conduct. OCEG GP201 |
| G422 | Implement and Manage the Code of Conduct | Distribute and manage a code of conduct to ensure that all relevant stakeholders receive the code of conduct, certify that they will follow it that the practices and principles are honored, observed, and enforced, and that it continues to be relevant.Encompasses all advisory, training, and consultative services for implementation of the Code of Conduct, including recommendations for updating the Code of Conduct (developing updates falls under GP2.1) and reconciling multiple Codes of Conduct. OCEG GP202 |
| G423 | Develop and Implement Ethical Decision-Making Guidelines | Work with appropriate stakeholders to develop and implement guidelines on how to choose a course of action consistent with the organization's mission, vision, values, key policies and expected business conduct when the circumstances are not explicitly covered by the code of conduct, policies, or procedures.Encompasses all advisory, training, and consultative services for development and implementation of Ethical Decision-making Guidelines, including reconciling multiple guidelines. OCEG GP203 |
| G430 | Policies | OCEG GP300 |
| G431 | Establish Policy Structure | Establish an organizing structure for identifying and creating policies that support the GRC capability.Encompasses advisory, legal and consulting services on required and desired policies, processes, procedures, accountability, and the standards for policy development and representation. OCEG GP301 |
| G432 | Develop Policies | Develop a mix of preventative and directive policies to address requirements, risks, and other program objectives.Encompasses advisory, legal and consulting services on the substantive content and scope of policies. OCEG GP302 |
| G433 | Implement and Manage Policies | Implement, communicate, and manage policies to ensure that they operate and continue to be relevant.Encompasses advisory, legal, training, and consulting services on the implementation of policies, including the recommendations for new or changes to policies (actual policy revisions falls under GP3.2). OCEG GP303 |
| G440 | Education | OCEG GP400 |
| G441 | Define an Awareness and Education Plan | Develop a plan to inform and educate the Board, management, the workforce and the extended enterprise about their GRC responsibilities and expected conduct.Encompasses all advisory, legal, and consulting services for developing an enterprise level plan of education and awareness across each training requirement, including training of the extended enterprise (e.g., across the supply chain, joint ventures, and business partners). OCEG GP401 |
| G442 | Define a Curriculum Plan | Develop a job specific curriculum and appropriate training program for the Board, senior management, the workforce and the extended enterprise to fulfill their GRC responsibilities.Encompasses all advisory, legal, and consulting services for role-specific training for employees, contractors and the extended enterprise (e.g., across the supply chain, joint ventures, and business partners). OCEG GP402 |
| G443 | Develop or Acquire Content | Develop or acquire content that does not exist in the curriculum or education plan and modify any content that needs updating in current learning objects.Encompasses all advisory, legal, and consulting services regarding the substantive content requirements of any awareness, curriculum or education plans. OCEG GP403 |
| G444 | Implement Education | Implement and manage the education program to ensure that each target audience achieves learning objectives and can transfer knowledge and skills to their jobs.Encompasses all advisory, legal, and consulting services engaged to deliver awareness or educational programs. OCEG GP404 |
| G445 | Provide Helpline | Establish ways for the workforce and other stakeholders to seek guidance about future conduct and ask general questions about GRC responsibilities, including the option for anonymity in locations where that is required or allowed.Encompasses all advisory, legal, consulting services regarding establishing helpline information. Also encompasses provision of outsourced helpline services. (Any content for scripts or guidance used by outsourced or insourced helpline provider falls under GP4.3 and any processes, procedures, or protocols for the helpline service falls under this number rather than GP1.2, and accountability is established under this number rather than GP1.2 for policies, or O3 for individuals). OCEG GP405 |
| G446 | Provide Integrated Support | Establish ways for the workforce to get questions about GRC requirements answered within their usual work environment.Encompasses all advisory, legal, consulting services regarding establishing self-help information and information when inquiries are raised through internal personnel or the organizational command structure. (Any content for scripts or guidance used by internal personnel falls under GP4.3 but any processes, procedures, or protocols for the provision of integrated support like open door policies falls GP 1.2 rather than this number.) OCEG GP406 |
| G450 | Incentives | OCEG GP500 |
| G451 | Hire and Promote Based on Conduct Expectations | Consider articulate desirable conduct when defining jobs, career paths and performance review criteria of employees and business partners - and use these same criteria for promoting individuals.Encompasses advisory, legal, and consulting services on job descriptions, career paths, and performance review criteria for all business partners and individuals without specific GRC responsibilities. (This is general population requirements which may be a subset of but are distinct from those created under GO2.0 et seq.) OCEG GP501 |
| G452 | Develop Compensation and Remuneration that Consider Conduct Expectations | Design compensation plans and bonus structures for employees and business partners that align with desired conduct and do not reward undesirable conduct.Encompasses advisory, legal, and consulting services on compensation and bonus programs for all business partners and individuals without specific GRC responsibilities. (This is general population requirements which may be a subset of but are distinct from those created under GO2.0 et seq.) OCEG GP502 |
| G453 | Develop Rewards Programs | Establish a reward program for all employees, business partners and other stakeholders that recognizes individuals and organizational units for exhibiting desired conduct.Encompasses advisory, legal, and consulting services on reward programs for all business partners and individuals without specific GRC responsibilities. (This is general population requirements which may be a subset of but are distinct from those created under GO2.0 et seq.) OCEG GP503 |
| G460 | Stakeholder Relations | OCEG GP600 |
| G461 | Understand Stakeholders | Research and analyze the organizations and key individuals involved within various stakeholder constituencies in order to understand their concerns and how best to relate to them.Encompasses researching and profiling the predilections, temperament of, and enforcement trends of individual stakeholders within organizations that constitute sources and forces in the legal and geopolitical climate. (Captures more granular research than GC1.2, GA1.2 or GA1.3.) OCEG GP601 |
| G462 | Develop Stakeholder Relations Plans | Develop stakeholder relations plans, including communications plans, for each stakeholder constituency.Encompasses developing stakeholder relations plans for individual stakeholders as well as organizations that constitute sources and forces in the legal and geopolitical climate. (Addresses action plans rather than understanding as described in GC1.2, GA1.2, and GA1.3.) OCEG GP602 |
| G463 | Identify and Track Activity by Requirement Issuing Authorities | Determine which government agencies, standards organizations, and other entities that issue mandates, standards or guidance have significant effect on the organization's GRC requirements and track their activities.Encompasses delivery of advisory, legal or consulting monitoring/tracking services and subscriptions to feeds of newly proposed and enacted laws, regulations, guidance, judicial opinions, and standards (Addresses execution rather than creating the relationship as described in GA1.9.) OCEG GP603 |
| G464 | Comment on Planned or Proposed Items | Actively participate in the development of mandates, standards, and guidance through various comment pathways.Encompasses delivery of advisory, legal or consulting government affairs and standards development services initiated by others. (Addresses execution rather than creating the relationship as described in GA1.9.) OCEG GP604 |
| G465 | Propose Mandates, Standards or Guidance | Actively propose development of mandates, standards, and guidance to issuing authorities.Encompasses delivery of advisory, legal or consulting government affairs and standards development services initiated by the organization. (Addresses execution rather than creating the relationship as described in GA1.9.) OCEG GP605 |
| G470 | Risk Financing | OCEG GP700 |
| G471 | Assess Risk Financing Need and Options | Assess the need or desire for financing risk and the options available.Encompasses advisory, legal or consulting services related to identify insurance, captives, indemnification, limitation of liability, joint defense, structured settlements, collections, bankruptcy, and other financing options for various risks. OCEG GP701 |
| G472 | Set Risk Financing Objectives | Set the risk sharing objectives and limits for the given risk or portfolio of risk.Internal legal and management opinion -- external charges should not apply. OCEG GP702 |
| G473 | Design Risk Financing Strategy | Design a portfolio of risk-sharing instruments and approaches.Encompasses advisory, legal or consulting services related to recommendations on approaches for insurance, captives, indemnification, limitation of liability, joint defense, structured settlements, collections, bankruptcy, and other financing options for various risks. (Developing the strategy which is encompassed here is distinct from invoking the strategy as a response to a realized risk as provided in GR1.1). OCEG GP703 |
| G474 | Implement Risk Financing Strategy | Implement the risk sharing instruments or structures and acquire insurance.Encompasses advisory, legal or consulting services related to implementing insurance, captives, indemnification, limitation of liability, joint defense, structured settlements, collections, bankruptcy, and other financing options for various risks. (Putting the strategy in place through appropriate contract provisions which is encompassed here is distinct from invoking those provisions as a response to a realized risk as provided in GR1.1 or the development of other contracting standard provisions under GP1.1). OCEG GP704 |
| G500 | Detect | OCEG GD000 |
| G510 | Unnamed in source | The LOC spreadsheet does not name this phase. OCEG GD100 |
| G511 | Establish Detective Actions and Controls | Establish detective actions and controls to detect and discern progress toward objectives as well as real and potential undesirable events and conditions.Encompasses advisory, legal and consulting services related to establishing detective actions and controls like fraud reporting and vendor audit programs. (This number covers establishing the actions and controls whereas GD2.1 covers utilization of them.) OCEG GD101 |
| G512 | Establish Detective Process Controls | Establish process control activities and procedures that detect adverse events, noncompliance and misconduct.Encompasses, all design of processes for monitoring financial transactions, transfers of physical assets, and the detection and notification of unauthorized disclosure of private information. Also includes any expected detective process controls like quality inspections to be promulgated through supply chain, joint venture, and business partner programs. (This number covers establishing process controls whereas GD2.1 covers execution of the processes.) OCEG GD102 |
| G513 | Establish Detective Human Capital Controls | Establish human capital control activities and procedures that detect adverse events, noncompliance and misconduct.Encompasses, all design of human capital controls for reporting observed adverse events, noncompliance and misconduct, including exit interviews. (This number covers establishing human capital controls whereas GD2.1 covers execution of them.) OCEG GD103 |
| G514 | Establish Detective Physical Controls | Install physical controls necessary to provide surveillance of physical preventive controls and areas where noncompliance or unethical conduct can be physically observed.Encompasses all advisory services, recommendations, and legal opinions regarding physical controls (i.e., surveillance equipment, entry/exit monitoring devices, alarm systems, emissions detectors, quality inspections, etc.), related to security of and access to facilities, physical assets, information assets, and the detection of unauthorized disclosure of private information. (This number covers establishing physical controls whereas GD2.1 covers execution of them.) OCEG GD104 |
| G515 | Establish Detective Technology Controls | Implement and monitor automated detective technology controls to promptly identify actual or potential misconduct.Encompasses all advisory services, recommendations, legal opinions and consulting services regarding technological controls (i.e., software, business rules, algorithms, dashboards, electronic alerts, etc.), related to detection of misconduct or noncompliance. (This number covers establishing technology controls whereas GD2.1 covers execution of them.) OCEG GD105 |
| G516 | Consolidate and Analyze Control Findings | Consolidate and analyze all information gathered through various means of detection to identify patterns of misconduct, adverse events and other weaknesses that would otherwise go unnoticed.Encompasses all advisory and consulting services related to the methods to be used to aggregate and analyze detected events as well as execution of the analysis, including discerning patterns, weaknesses and benchmarked comparisons. OCEG GD106 |
| G520 | Notification | OCEG GD200 |
| G521 | Capture Notifications | Implement a notification system that will alert the organization to incidents or suspicions of legal noncompliance, violations of company policies, and concerns or perceptions about perceived unethical conduct, GRC capability weaknesses and performance at all levels.Encompasses all advisory services, recommendations, legal opinions and consulting services regarding methods of notification, including establishing a hotline and restrictions or mandates for anonymous reporting. OCEG GD201 |
| G523 | Filter and Route Notifications | Vet and route notifications for handling, regardless of the pathway through which a given notification is received.Internal legal and management opinion -- external charges should not apply. OCEG GD203 |
| G524 | Adhere to Data Protection Requirements | Ensure that the hotline pathway for notification complies with specific requirements established in the locale where the notice originates and where the organization operates.Encompasses all advisory services, recommendations, legal opinions and consulting services regarding restrictions or mandates for anonymous reporting, cross-border data transfers, and privacy. OCEG GD204 |
| G530 | Inquiry | OCEG GD300 |
| G531 | Establish Multiple Pathways to Obtain Workforce and Stakeholder Views | Define opportunities for obtaining workforce and stakeholder views about risk, the GRC capability, conduct and organizational commitment to its stated values.Encompasses advisory, legal and consulting services related to surveying and interviewing for workforce and stakeholder views, including outsourced surveys and HR processes. OCEG GD301 |
| G532 | Establish an Organization-Wide Integrated Approach to Surveys | Establish a survey approach that reduces the burden on survey subjects and provides a consolidated view of information obtained from the workforce and other stakeholders.Encompasses advisory, legal and consulting services related to an integrated approach to surveying. OCEG GD302 |
| G533 | Establish an Integrated Approach to Self-Assessments | Establish a self-assessment approach that integrates assessment of GRC capability-related responsibilities and outcomes with other self-assessments imposed on management.Encompasses advisory, legal and consulting services related to an integrated approach to self-assessment, including programs expanded to include the extended enterprise. OCEG GD303 |
| G534 | Gather information through observations and conversations | Establish informal methods of gathering views through observations, group meetings, focus groups and individual conversations.Encompasses advisory, legal and consulting services related to observations, group discussions and individual interviews conducted by outside providers, including depositions or other sworn testimony. OCEG GD304 |
| G535 | Report Information and Findings | Provide information and findings from all methods of inquiry to management.Encompasses advisory, legal and consulting services related to reporting aggregated information obtained through surveys, discussions, and self-assessments. OCEG GD305 |
| G600 | Respond | OCEG GR000 |
| G610 | Responsive Actions & Controls | OCEG GR100 |
| G611 | Establish Responsive Actions and Controls | Establish responsive actions and controls that reward desirable conduct; punish undesirable conduct; and correct the identified weaknesses in the capability.Encompasses advisory, legal and consulting services related to establishing responsive actions and controls like media relations, internal conflicts resolution, litigation, litigation holds, and bankruptcy filings. (This number covers establishing the actions and controls as well as execution of actions and controls other than those covered by GR2-GR4.) OCEG GR101 |
| G612 | Establish Corrective Process Controls | Establish corrective process control activities to stop, slow and recover from adverse events, and deter future adverse events.Encompasses advisory, legal and consulting services related to establishing corrective process controls. (This number covers establishing the process controls; execution of corrective controls falls under GR5.1.) OCEG GR102 |
| G613 | Establish Corrective Human Capital Controls | Establish corrective human capital controls that stop, slow and recover from adverse events, and deter future adverse events.Encompasses advisory, legal and consulting services related to establishing corrective human capital controls like suspending authority, overriding reporting structures, and marshalling corrective action teams. (This number covers establishing the human capital controls; execution of corrective controls falls under GR5.1.) OCEG GR103 |
| G614 | Establish Corrective Technology Controls | Establish corrective technology controls that stop, slow and recover from adverse events, and deter future adverse events.Encompasses advisory, legal and consulting services related to establishing corrective technology controls, including access restrictions, suspension of system processes, and retention of documents and records. (This number covers establishing the technology controls; execution of corrective controls falls under GR5.1.) OCEG GR104 |
| G615 | Establish Corrective Physical Controls | Establish corrective physical controls that stop, slow and recover from adverse events, and deter future adverse events.Encompasses advisory, legal and consulting services related to establishing corrective physical controls, including access restrictions, lock-down procedures, hardening infrastructure and fire suppression. (This number covers establishing the physical controls; execution of corrective controls falls under GR5.1.) OCEG GR105 |
| G616 | Monitor and Report Corrective Controls | Monitor and report the progress of corrective control activities.Encompasses advisory, legal and consulting services related to monitoring and reporting corrective controls. (This number covers establishing the monitoring and reporting activities as well as execution monitoring and reporting.) OCEG GR106 |
| G620 | Internal Investigation | OCEG GR200 |
| G621 | Define the Inquiry and Investigation Process | Establish procedures for inquiring further into, and investigating, complaints or reports about compliance or ethical issues, as well as for issues detected during ongoing monitoring or periodic evaluation of the GRC capability.Encompasses advisory, legal and consulting services related to establishing a defensible inquiry and investigation process and analyzing trends and patterns, including a taxonomy for classifying topics and severity of inquiries and issues, escalation process for routing, and procedures for maintaining confidentiality and anonymity. OCEG GR201 |
| G622 | Prepare to Investigate | Prepare to undertake the activities of the investigation phase of the issue resolution process.Encompasses engaging advisors, lawyers, investigators, and consultants to perform inquiries and investigations, including obtaining appropriate disclosures of conflicts and independence and coordinating with various departments and stakeholders to be engaged in the process. OCEG GR202 |
| G623 | Conduct Investigations | Conduct investigations consistent with the plan and communicate with relevant stakeholders while maintaining appropriate privileged status.Encompasses advisory, legal, eDiscovery, and consulting services delivered while conducting inquiries and investigations, including document location and production. OCEG GR203 |
| G624 | Report Results of Investigations | Communicate investigation results to appropriate management, oversight bodies and, as appropriate, to other stakeholders and regulators.Encompasses advisory, legal and consulting services reporting the results of inquiries and investigations. OCEG GR204 |
| G630 | Third-Party Investigations | OCEG GR300 |
| G631 | Prepare for and Address Third Party Inquiries | Identify and respond to questions from third parties.Encompasses engaging advisors, lawyers, investigators, and consultants to respond to third-party inquiries and investigations, including obtaining appropriate disclosures of conflicts and independence. OCEG GR301 |
| G632 | Prepare to Identify Third Party Investigations | Establish methods to ensure the right people know about initiated third party investigations.Internal legal and management opinion -- external charges should not apply. OCEG GR302 |
| G633 | Prepare to Manage Third Party Investigations | Establish policies, procedures, and responsibility for managing various types of third party investigations.Encompasses advisory, legal, eDiscovery, and consulting services to respond to third-party inquiries and investigations, including media relations, disclosure of conflicts and independence, procedures for confidentiality and privilege, and coordinating with various departments and stakeholders to be engaged in the process. OCEG GR303 |
| G634 | Prepare to Select Team for Third-Party Investigation | Establish procedures for selecting the team of individuals that will represent the organization during a specific investigation.Encompasses engaging preferred providers as advisors, lawyers, investigators, eDiscovery providers, and consultants to prepare an appropriate response. OCEG GR304 |
| G635 | Prepare to Respond to Specific Third-Party Investigations | Establish procedures for developing a response to a specific investigation.Encompasses advisory, legal, eDiscovery, and consulting services delivered while responding to specific third-party inquiries and investigations, including document location and production. OCEG GR305 |
| G640 | Crisis Response | OCEG GR400 |
| G641 | Develop Crisis Response and Continuity Plans | Develop the plans for responding to various types of crises and recovering from business disruption.Encompasses advisory, legal, investigative, and consulting services engaged to develop emergency operating procedures, crisis response, business continuity and disaster recovery plans, including providing business impact analysis. OCEG GR401 |
| G642 | Identify Crisis Readiness and Response Teams | Define personnel who will be responsible for crisis preparedness and those who will be deployed as crisis response teams for each type of identified crisis.Encompasses identifying advisors, lawyers, investigators, and consultants to be engaged as part of the response team for various crises and costs associated with having 24x7 contact methods. OCEG GR402 |
| G643 | Test Plans and Procedures | Test and evaluate the various crisis plans and procedures.Encompasses involvement of advisors, lawyers, investigators, and consultants in testing crisis response, business continuity, and disaster recovery plans and procedures. OCEG GR403 |
| G644 | Coordinate Plans | Coordinate the various continuity and response plans in anticipation of business disruption that may span more than one facility.Encompasses involvement of advisors, lawyers, investigators, and consultants in reconciling multiple crisis response, business continuity, and disaster recovery plans and procedures. OCEG GR404 |
| G650 | Remediation | OCEG GR500 |
| G651 | Remediate the GRC capability | Resolve each reported issue/incident, document the outcome, and propose appropriate changes to the GRC capability to avoid similar issues in the future.Encompasses advisory, legal and consulting services related to remediating the GRC capability, including identification of patterns of root causes, recommendations for new or modifications to actions, risks or controls or changes to prioritization of risks or remediation plans. OCEG GR501 |
| G652 | Discipline Individuals | Discipline individuals for misconduct.Internal legal and management action -- external charges should not apply. OCEG GR502 |
| G653 | Disclose Issue Resolution | When required or appropriate, disclose findings and resolution of investigations to stakeholders.Encompasses advisory, legal and consulting services related to communicating with internal and external stakeholders, including regulators, enforcement authorities, and third-party investigators. OCEG GR503 |
| G660 | Rewards | OCEG GR600 |
| G700 | Measure | OCEG GM000 |
| G710 | Context Monitoring | OCEG GM100 |
| G711 | Monitor External Context | Continually monitor changes in the external environment that may have a direct, indirect or cumulative effect on the organization.Internal legal and management activity -- external charges should not apply. (Relevant external monitoring is covered under GC1.2, GA1.9, and GP6.1, time spent here would essentially be business development write-offs providing newsletters, general advisories, etc.) OCEG GM101 |
| G712 | Monitor Internal Context | Continually monitor changes in the internal environment that may have a direct, indirect or cumulative effect on the organization.Internal legal and management opinion -- external charges should not apply (time spent here would essentially be non-chargeable business development activities associated with knowing your client). OCEG GM102 |
| G720 | Unnamed in source | The LOC spreadsheet does not name this phase. OCEG GM200 |
| G721 | Monitor and Evaluate Capability Design | Establish a schedule for periodic re-evaluation of the appropriateness of the capability design in light of objectives, opportunities, threats and requirements.Encompasses advisory, legal, or consulting services (excluding audit services) in evaluating the suitability of the GRC program design and performance for the purpose of making recommendations for improvement to an existing program. OCEG GM201 |
| G722 | Review and Reconsider Risks | Review any previously assessed or newly identified risks and reconsider, or assess for the first time, their priority based on the best information currently available.Internal legal and management activity -- external charges should not apply. (Relevant external risk management assessment is covered under GM4) OCEG GM202 |
| G723 | Identify Relevant Actions and Controls | Review the related actions and controls in place to address high priority objectives, threats, opportunities and requirements.Encompasses advisory, legal, or consulting services (excluding audit services) in evaluating the suitability of the design and performance of existing actions and controls for the purpose of making recommendations for improvement or changes to those actions and controls. OCEG GM203 |
| G724 | Analyze Potential for Failure | Analyze the potential that risk-optimizing activities will fail and the ways in which they might fail.Encompasses advisory, legal, or consulting services (excluding audit services) in evaluating the potential for and methods of failure of risk-optimizing activities for the purpose of making recommendations for improvement or changes to those actions and controls. OCEG GM204 |
| G725 | Identify Monitoring Information | Identify the information to use to support the evaluation of the performance of the risk optimizing activity(s) and/or the overall performance of the GRC capability.Encompasses advisory, legal, or consulting services (excluding audit services) in planning the collection of evidence to support the analysis and recommendations for improvement or changes to actions and controls and the overall GRC capability. OCEG GM205 |
| G726 | Perform Monitoring Activities | Perform monitoring activities to support the evaluation of the performance of the system.Encompasses advisory, legal, or consulting services (excluding audit services) in collecting evidence to support the analysis and recommendations for improvement or changes to actions and controls and the overall GRC capability. OCEG GM206 |
| G727 | Analyze and Report Monitoring Results | Analyze the results of monitoring activities to identify instant weaknesses and opportunities for systemic improvements.Encompasses advisory, legal, or consulting services (excluding audit services) in reporting findings and recommendations for improvement or changes to actions and controls and the overall GRC capability. OCEG GM207 |
| G730 | Systemic Improvement | OCEG GM300 |
| G731 | Develop Improvement Plan | Develop a prioritized plan for implementing improvements to the program.Encompasses advisory, audit, legal or consulting services in developing a portfolio of GRC capability improvement initiatives. OCEG GM301 |
| G732 | Implement Improvement Initiatives | Implement the specific action plans and initiatives intended to improve the program.Encompasses utilizing advisory, audit, legal or consulting services to implement a portfolio of GRC capability improvement action plans and initiatives. OCEG GM302 |
| G740 | Assurance | OCEG GM400 |
| G741 | Plan Assurance Assessment | Determine scope, procedures and criteria required to provide desired level of assurance.Encompasses the planning phase of auditors engaged to provide audit or assurance services. OCEG GM401 |
| G742 | Perform Assurance Assessment | Perform procedures, evaluate results against criteria and deliver report.Encompasses the delivery phase of auditors engaged to provide audit or assurance services. OCEG GM402 |
| G800 | Interact | OCEG GI000 |
| G810 | Information Management | OCEG GI100 |
| G811 | Develop a GRC Information Management Classification Structure | Determine the definitions, classifications and procedures necessary to identify and manage GRC information in the organization and extended enterprise, as part of an Information Management Plan.Encompasses advisory, legal, eDiscovery, and consulting services to develop an information management classification schema and procedures including retention, preservation, confidentiality, knowledge management, and privacy. OCEG GI101 |
| G812 | Develop GRC Information Collection Policies & Procedures | Establish the policies and procedures necessary to collect GRC information from sources within and outside the organization and extended enterprise, as part of an Information Management Plan.Encompasses advisory, legal, eDiscovery, and consulting services to develop information collection policies and procedures. OCEG GI102 |
| G813 | Develop GRC Information Access, Use and Transfer Policies & Procedures | Establish the policies and procedures necessary to access, use and transfer GRC information in the organization and extended enterprise, as part of an Information Management Plan.Encompasses advisory, legal, eDiscovery, and consulting services to develop access, use, and transfer procedures including compliance with data transfer, confidentiality and privilege restrictions and security and breach containment and notification requirements. OCEG GI103 |
| G814 | Develop GRC Information Storage & Disposition Policy & Procedures | Establish the policies and procedures necessary to store GRC information in the organization and extended enterprise in accordance with requirements and recovery objectives, as part of an Information Management Plan.Encompasses advisory, legal, eDiscovery, and consulting services to develop policies and procedures including retention, preservation, restoration, disposition of information, reconciling knowledge management, back-up, archiving and media rotation processes. OCEG GI104 |
| G820 | Communication | OCEG GI200 |
| G821 | Develop Reporting Plan | Establish a plan to ensure compliance with mandatory reporting requirements and provide desired reports to management, the Board, and stakeholders.Encompasses advisory, legal, and consulting services in establishing required reporting practices, including regulatory reporting, and desired reporting to stakeholders, including shareholders. OCEG GI201 |
| G822 | Develop Communication Plan | Define how the organization will manage GRC related communications that are not formal reports.Encompasses advisory, legal, and consulting services in establishing internal communication plans, including change management messaging. OCEG GI202 |
| G830 | Technology | OCEG GI300 |
| G831 | Assess Technology Needs and Gaps | Identify gaps and underperforming systems in existing technology environment.Encompasses advisory consulting services identifying technological requirements, gaps and opportunities whether point solutions or enterprise architecture including designation of systems of record that "own" particular information and the data flow and protocols used for exchanges emanating from those systems. OCEG GI301 |
| G832 | Develop GRC Technology Portion of GRC Strategic Plan | Develop plan for implementing technology to enable GRC processes and information flows.Encompasses advisory consulting services in developing a plan that prioritizes implementation initiatives, and implementing appropriate solutions, architectures, information flows, and protocols to enable GRC processes and information requirements. OCEG GI302 |
Search every code set
Not sure which set a line belongs to? The UTBMS code lookup searches all 625 codes and the LEDES 1998B and 98BI fields at once. Type a code or describe the work in plain English.
- UTBMS Litigation Task Codes (L1xx-L5xx)
- UTBMS eDiscovery Codes (L6xx)
- UTBMS Bankruptcy Task Codes (B1xx-B4xx)
- UTBMS Counseling Task Codes (C1xx-C4xx)
- UTBMS Project (Transactional) Task Codes (P1xx-P8xx)
- UTBMS Activity Codes (ABA 1997) (A101-A111)
- UTBMS Activity Codes (LOC 2013 Revision) (A101-A128)
- UTBMS Expense Codes (ABA 1997) (E101-E124)
- UTBMS Expense Codes (LOC 2013 X-Codes) (X101-X999)
- UTBMS Patent Task Codes (PA1xx-PA9xx)
- UTBMS Trademark Task Codes (TR1xx-TR9xx)
- UTBMS IP Expense Codes (E125-E131)
- UTBMS Patent Prosecution Codes (110000-110901)
- UTBMS M&A Task Codes (MA00-MK00)
- UTBMS Timekeeper Classification Codes (5-6 letter codes)
Who maintains this page
Caddi automates the business of law
Caddi builds and runs automations for law firms: new matter intake, filing to the DMS, time capture, pre-bill review, and AR follow-up, inside the systems your firm already runs, from iManage and NetDocuments to Clio, Aderant, and Elite 3E. Coding to the set your client mandates is the easy half. Remembering the work is the hard one.
Code text belongs to the LEDES Oversight Committee, reproduced here with a link to the source.