Meet CaddiBox + Caddi webinarReplayLegal AI ROI webinarReplayADVISE AIOct 20–22Booth 204AI for Mid-Sized LawNov 5Legal InnovatorsNov 17–18

UTBMS codes / Governance, risk & compliance

UTBMS Governance, Risk & Compliance Codes

177 codes, G1xx-G8xx. Published by the LEDES Oversight Committee (LOC) in 2015.

A three-level code set (category, phase, task) mapping legal work to the OCEG GRC Capability Model.

When to use it: Compliance, governance, and risk advisory work that the counseling codes are too coarse to describe.

The full list: 177 codes

CodeNameDefinition
G100ContextOCEG GC000
G110External ContextOCEG GC100
G111Analyze the External Business ContextIdentify and analyze the relevant external business context factors.Encompasses high-level strategic recommendations and analysis of legal, regulatory, and geopolitical climate for requirements generally in the industries in which the organization operates. OCEG GC101
G112Analyze External Stakeholder and Influencer NeedsIdentify key external stakeholders, and influencers of opinion, and analyze and prioritize their needs and requirements.Encompasses all analysis of issuing authorities of requirements and opportunities to influence the thinking of regulators and legislators affecting the industry in which the organization operates. OCEG GC102
G120Internal ContextOCEG GC200
G121Define the Internal ContextIdentify the key structures and assets that define the Internal Context.Encompasses new legal entity creation, mergers, acquisitions, joint ventures, and dissolution. OCEG GC201
G122Determine Changes Needed to Align the Internal Context and GRC capabilityIdentify possible changes to the internal context that may affect design aspects of the GRC capability or ensure alignment.Encompasses maintenance of legal entities, resolutions for changes to boards, officers, directors and organizational structure. OCEG GC202
G130CultureOCEG GC300
G131Analyze Ethical CultureAnalyze the existing climate (observable, formal elements in the organization) and individual mindsets about the degree to which the workforce believes the organization expects and supports responsible behavior and integrity.Encompasses advising on ethics program requirements for all operating jurisdictions. OCEG GC301
G132Analyze Ethical LeadershipAnalyze whether leadership sets an appropriate "tone at the top" and models behavior in both words and deeds.Encompasses advising on permissible basis for employee evaluations and management development and training programs. OCEG GC302
G133Analyze Risk CultureAnalyze the existing climate and individual mindsets about how the workforce perceives risk, its impact on their work and the organization as a whole.Encompasses consulting on risk components of strategic planning, executive management, and risk management programs. OCEG GC303
G134Analyze Board InvolvementAnalyze the degree to which the Board is involved and engaged in the organization.Encompasses advising on board's fiduciary duties, other legal obligations in how business is conducted and reporting irregularities. OCEG GC304
G135Analyze Governance Culture and Management StyleAnalyze the existing approach to governing, managing and enabling the workforce.Encompasses consulting on governance, delegations of authority, and organizational effectiveness. OCEG GC305
G136Analyze Workforce EngagementAnalyze the existing workforce culture including the degree of employee satisfaction, loyalty and engagement.Encompasses consulting on workforce management, including advising on employee reimbursement, leave and benefits plans. OCEG GC306
G140ObjectivesOCEG GC400
G141Define Mission & VisionCreate a formal statement of the organization's mission and vision.Encompasses strategic advisory services engagements and advice on permissible legal entity purposes. OCEG GC401
G142Define ValuesCreate a formal statement of the core values that the organization holds and applies to its business decisions.Encompasses strategic advisory services on post-merger and post-acquisition integration. OCEG GC402
G143Define Business ObjectivesDefine a balanced set of measurable business objectives that are congruent with mission, vision and values.OCEG GC403
G144Define Risk Appetite and Decision CriteriaDefine the approach and criteria for making decisions about the pursuit of risk relative to reward including risk appetite, tolerance and capacity.Encompasses advisory services related to measurement of risk, including key risk indicators. OCEG GC404
G145Define Indicators, Targets and TolerancesDefine a balanced set of leading and lagging indicators that help management understand if the organization is meeting its business objective targets within defined tolerances.Encompasses development and advisory services on metrics and key performance indicators for the organization. OCEG GC405
G146Obtain Commitment to Mission, Vision, Values and ObjectivesObtain commitment from management and Board members about what the organization will achieve while living by its values.Encompasses approvals of the metrics and performance measurement program. OCEG GC406
G147Communicate Mission, Vision and ValuesCommunicate the mission, vision and values to internal and external stakeholders.Encompasses legal review of corporate communications, shareholder communications, and public communications regarding the organization outside of communications to affect changes to the legal and geopolitical climate, internal training, and crisis response communications. OCEG GC407
G200OrganizeOCEG GO000
G210CommitmentOCEG GO100
G211Define GRC capability ScopeDefine the scope of the GRC capability or subsystem under consideration.Encompasses advisory services on strategic planning and operational implementation of GRC capabilities, including governance, risk management, compliance, and ethics programs. OCEG GO101
G212Define GRC capability Style and GoalsDefine the overall style of the GRC capability, what it will achieve, and how it relates to business objectives.Encompasses advisory services on program measurement and integration plan for GRC capability. OCEG GO102
G213Obtain Commitment to the GRC capabilityObtain explicit written authorization and high-level support for the GRC capability.Encompasses presentations and recommendation of GRC strategic and operational plans for organizational approval. OCEG GO103
G220RolesOCEG GO200
G221Define and Enable GRC capability Oversight Roles and AccountabilityDefine oversight roles, responsibilities and accountability for each aspect of the GRC capability.Encompasses advisory, legal, and consulting services on implementation of oversight portion of strategic GRC plan, including job descriptions, background checks, and training on legal requirements of oversight roles. (This is distinct from the compensation, rewards, and promotion criteria for general population defined under GP5.1 et seq.) OCEG GO201
G222Define and Enable Management Roles and AccountabilityDefine management roles, responsibilities and accountability for certain aspects of the GRC capability.Encompasses advisory, legal, and consulting services on implementation of management portion of strategic GRC plan, including job descriptions, background checks, and training on legal requirements and assumed voluntary mandates for GRC management positions. (This is distinct from the compensation, rewards, and promotion criteria for general population defined under GP5.1 et seq.) OCEG GO202
G223Define and Enable Leadership Roles and AccountabilityDefine individuals to serve in leadership roles to champion the GRC capability or certain aspects of the system and establish methods to ensure they possess the desired character ethics.Encompasses advisory, legal, and consulting services on implementation of leadership roles in strategic GRC plan, including job descriptions, background checks, and training on legal requirements and assumed voluntary mandates for GRC leadership positions. (This is distinct from the compensation, rewards, and promotion criteria for general population defined under GP5.1 et seq.) OCEG GO203
G224Define and Enable GRC Capability Operational RolesDefine the roles required to deliver, operate, and execute GRC Capability practices.Encompasses advisory, legal, and consulting services on implementation of operational GRC roles, including job descriptions, background checks, training on legal requirements and assumed voluntary mandates for GRC operational positions and monitoring compliance with certifications. (This is distinct from the compensation, rewards, and promotion criteria for general population defined under GP5.1 et seq.) OCEG GO204
G225Define and Enable Assurance Roles and AccountabilityDefine assurance roles, responsibilities and accountability for certain aspects of the GRC capability (e.g., chief audit executive, external auditor)Encompasses advisory, legal, and consulting services on implementation of assurance roles, including job descriptions, training on legal requirements and assumed voluntary mandates for GRC assurance, and monitoring compliance with certifications and licensure requirements. (This is distinct from the compensation, rewards, and promotion criteria for general population defined under GP5.1 et seq.) OCEG GO205
G230AccountabilityOCEG GO300
G231Allocate Accountability to Individuals and CommitteesAllocate GRC roles and responsibilities to individuals and committees.Encompasses documentation and implementation of delegation of authority, segregation of duties, and approval process workflows. OCEG GO301
G232Define GRC Capability Processes and Integrate with Business ProcessesDefine GRC Capability processes and synchronize with existing business processes.Encompasses documentation and advisory services on implementation planning for GRC business process workflows. OCEG GO302
G233Define Measurement and Evaluation ApproachDefine an approach to measure and evaluate the effectiveness, efficiency, and responsiveness of the GRC capability.Encompasses development and advisory services on metrics and key performance indicators for the GRC capabilities of the organization. OCEG GO303
G234Define Organizational Change Management ApproachDefine an approach to ready the organization for any changes that the GRC capability may require to people, processes, and technology.Encompasses advisory services on design and implementation planning for change management program rather than implementation of a particular change initiative. OCEG GO304
G235Develop, Maintain and Authorize a Business CaseDevelop a business case for the GRC capability and obtain authorization from senior management and the Board.Encompasses advisory services on development and presentation of GRC program level business case as well as business cases for individual GRC initiatives. OCEG GO305
G300AssessOCEG GA000
G310IdentificationOCEG GA100
G311Review Business Objectives, Processes and ResourcesIdentify and review key business objectives, processes and resources that are relevant given the scope of the capability (e.g., if the scope is the entire organization, then all business objectives, processes and resources are relevant; if the scope is a single department, then some subset of business objectives, processes and resources are relevant).Encompasses consulting on legal, risk, compliance, ethics and audit function capabilities design (performance, and improvement fall under GM2 and GM3). OCEG GA101
G312Identify External Sources and ForcesImagine and identify external sources and forces that may produce a requirement or cause a desirable or undesirable effect on objectives.Encompasses researching and profiling the predilections, temperament of, and enforcement trends emanating from existing and emerging sources and forces in the legal and geopolitical climate at a holistic level. (Captures more granular research than GC1.2, but not down to individual profiles prepared and specific activities monitored under GP6.1 et seq.) OCEG GA102
G313Identify Internal Sources and ForcesImagine and identify internal sources and forces that may produce a requirement or cause a desirable or undesirable effect on objectives.Encompasses evaluation of scope and impact of previously implemented business models and implications of implemented changes in human capital, technology, processes, and organizational structure. OCEG GA103
G314Identify Opportunities & ThreatsGiven the sources and forces, identify opportunities and threats that affect the achievement of objectives. Opportunities are events and conditions that, on balance, contribute to reward (which is a measure of the desirable effect of uncertainty on objectives) -- while threats are events and conditions that, on balance, contribute to risk (which is a measure of the undesirable effect of uncertainty on objectives).Encompasses advisory services, and legal opinions on opportunity and threat assessments, including competitive IP portfolios, pending IP applications, proposed laws, regulations, treaties, executive orders, judicial decisions, M&A targets, and divestiture recommendations. (This initial identification is distinct from ongoing monitoring and tracking as captured in GP6.3). OCEG GA104
G315Identify Mandatory & Voluntary RequirementsGiven sources and forces, identify mandatory and voluntary requirements that must be addressed.Encompasses research and notifications about existing legal climate of new jurisdictions, new products, new operations, or a combination of these based on enacted laws, regulations, executive orders, treaties, and judicial decisions. As well as advisory guidance on standards participation, desired certifications, warranties, and representations. (This initial identification is distinct from ongoing monitoring and tracking as captured in GP6.3). OCEG GA105
G316Identify Interrelatedness & TrendsIdentify how opportunities, threats and requirements relate to one another and how they have been trending both internally and externally with industry peers.Encompasses legal analysis of the integration between trans-national (i.e., non-governmental bodies), multi-national, national, regional, territorial and local levels of legal and regulatory mandates, treaties, reciprocal agreements, judicial opinion, administrative decisions, guidance, and conflicts between applicable requirements, enforcement and litigation trends. OCEG GA106
G317Conduct High Level Analysis of Risk/RewardConduct a high-level analysis of inherent, current and planned residual risk/reward so that the most relevant items are prioritized in future, more detailed analysis.Encompasses legal information on theoretical exposure for single instance and pattern of non-compliance with requirements. (This analysis of theoretical exposure is distinct from actual impact on specific organization as captured in GA2.1 et seq.). OCEG GA107
G318Conduct High Level Analysis of Requirements Impact/ConformanceConduct a high-level analysis of inherent, current and planned level of conformance with requirements, including rough economic analysis, so that the most relevant items are prioritized in future, more detailed analysis.Encompasses legal analysis of potential impacts from legal climate for players in the industry or market generally, as well as, advisory opinions on impacts of standards participation, certifications, warranties, and representations across industry. (This analysis of theoretical exposure is distinct from actual impact on specific organization as captured in GA2.1 et seq.). OCEG GA108
G319Assign Accountability to Monitor ChangesAssign accountability for monitoring the underlying sources that may lead to events and conditions that positively or negatively effect objectives.Encompasses creation of the relationship for advisory, legal or consulting services designed to monitor changes. (This creation of the relationship is distinct from actual performance of the services as captured in GP6.3). OCEG GA109
G320AnalysisOCEG GA200
G321Analyze Approach to RequirementsAnalyze the current and planned actions and controls to address requirements including costs.Encompasses fact finding to determine current approaches to compliance. OCEG GA201
G322Analyze Inherent Risk/RewardAnalyze the effects of threats and opportunities without consideration of current actions or controls.Encompasses legal opinions of potential impacts from legal climate for this client, as well as, advisory opinions on impacts of standards participation, certifications, warranties, and representations. Encompasses legal opinions regarding potential impacts of IP invalidity and contract unenforceability. OCEG GA202
G323Analyze Current Approaches to Risk/RewardIdentify the presence and effectiveness of current actions and controls that are in place to address the effect of threats and opportunities.Encompasses legal opinions on whether current approaches are sufficient for compliance and likely outcome of enforcement actions, as well as, advisory opinions on compliance with standards participation, certifications, warranties, and representations for this client. Encompasses legal opinions regarding suitability of current IP protection practices and standard contract provisions to abate or mitigate threats and seize opportunities. OCEG GA203
G324Determine Current Residual Risk/RewardDetermine the current level of risk/reward remaining given the presence and effectiveness of current actions and controls.Internal legal and management opinion -- external charges should not apply. OCEG GA204
G325Prioritize Threats, Opportunities and RequirementsPrioritize and categorize threats, opportunities and requirements to determine approach and resource allocation.Encompasses advisory services, audit recommendations, and legal opinions regarding the independent priority of threats, opportunities and requirements, including priority assessment as one component of the business case for action. OCEG GA205
G330PlanningOCEG GA300
G331Explore Options to Address RequirementsWhen current level of conformance is not acceptable, or when existing actions and controls are not optimal, explore additional actions and controls to address requirements.Encompasses project, program, personnel, and technology advisory services for implementation of compliance programs for discrete initiatives. OCEG GA301
G332Explore Options to Address Risk/RewardWhen the current residual risk is unacceptable or when current approach can be improved, explore alternative actions and controls to address risk/reward.Encompasses project, program, personnel, and technology options assessment services for implementation of risk management programs for discrete risks/rewards. OCEG GA302
G333Determine Planned Residual Risk/Reward and ConformanceDetermine the level of risk/reward and conformance that will remain after planned actions and controls are established and operating effectively.Internal legal and management opinion -- external charges should not apply. OCEG GA303
G334Address Inherently High RiskIdentify current and planned actions and controls that specifically address inherently high risk and that, should they cease to perform effectively, will expose the organization to unacceptable levels of risk.Internal legal and management opinion -- external charges should not apply. OCEG GA304
G335Develop Key IndicatorsDevelop key indicators that inform management about the level of performance, risk and conformance.Encompasses advisory and technological services in developing indicators and implementing the monitoring, alerts, and reporting on those indicators. OCEG GA305
G336Develop Integrated PlanDevelop a plan to govern, assure and manage the approach to addressing performance, risk and compliance.Encompasses advisory services, audit recommendations, and legal opinions regarding the relative priority of threats, opportunities and requirements, including priority assessment as one component of the business case for action. OCEG GA306
G400ProactOCEG GP400
G410Proactive Actions & ControlsOCEG GP100
G411Establish Proactive Management Actions and ControlsEstablish proactive management actions and controls that incent desirable, and prevent undesirable, events and conditions.Encompasses development of contract templates and playbooks with standard acceptable provisions (negotiated changes to contracts fall under GR1.1 and specific provisions that shift financial risk fall under GP7.1 et seq.), standard due diligence requests for M&A transactions, IP disclosure procedures, assignment practices, and incentive programs. Also includes the accountability and authorization process for waivers, exceptions and variances to company-adopted standards. Lastly, includes any expected management actions and controls to be promulgated through supply chain, joint venture, and business partner programs. OCEG GP101
G412Establish Preventive Process ControlsEstablish preventive process control activities and procedures to reduce the likelihood and/or impact of adverse events, noncompliance and misconduct.Encompasses development of all departmental procedures to ensure engagement of service providers is done consistently with policy directives. Also encompasses, all design of processes and accountability for securing facility and operational permits and licenses. Also includes any expected preventive process controls to be promulgated through supply chain, joint venture, and business partner programs. OCEG GP102
G413Establish Preventive Human Capital ControlsEstablish preventive human capital controls to reduce the likelihood and/or impact of adverse events, noncompliance and misconduct.Encompasses all advisory services, recommendations, and legal opinions on establishing particular roles, all job descriptions, background checks, delegations of authority, divisions of responsibility between roles, and lines of reporting. Also includes any expected human capital controls to be promulgated through supply chain, joint venture, and business partner programs. OCEG GP103
G414Establish Preventive Technology ControlsEstablish preventive technology controls to reduce the likelihood and/or impact of adverse events, noncompliance and misconduct.Encompasses all advisory services, recommendations, and legal opinions regarding configuration of access controls, required systems, configuration controls, master data, and business rules enforced through business rules engines to assure compliance with mandates and execution of activities in line with risk appetite. OCEG GP104
G415Establish Preventive Physical ControlsEstablish preventive physical controls to reduce the likelihood and/or impact of adverse events, noncompliance and misconduct.Encompasses all advisory services, recommendations, and legal opinions regarding physical controls (i.e., badges, biometric devices, RFID, gates, clean rooms, barriers, cabinets, etc.), related to security of and access to facilities, physical assets, information assets, or IP, and required to protect environment, and human health and safety. OCEG GP105
G420Codes of ConductOCEG GP200
G421Develop the Code of ConductWork with appropriate stakeholders to develop a code of conduct that addresses the organizational mission, vision, values, key policies and expected business conduct.Encompasses advisory services related to all aspects of determining and updating the content for the Code of Conduct. OCEG GP201
G422Implement and Manage the Code of ConductDistribute and manage a code of conduct to ensure that all relevant stakeholders receive the code of conduct, certify that they will follow it that the practices and principles are honored, observed, and enforced, and that it continues to be relevant.Encompasses all advisory, training, and consultative services for implementation of the Code of Conduct, including recommendations for updating the Code of Conduct (developing updates falls under GP2.1) and reconciling multiple Codes of Conduct. OCEG GP202
G423Develop and Implement Ethical Decision-Making GuidelinesWork with appropriate stakeholders to develop and implement guidelines on how to choose a course of action consistent with the organization's mission, vision, values, key policies and expected business conduct when the circumstances are not explicitly covered by the code of conduct, policies, or procedures.Encompasses all advisory, training, and consultative services for development and implementation of Ethical Decision-making Guidelines, including reconciling multiple guidelines. OCEG GP203
G430PoliciesOCEG GP300
G431Establish Policy StructureEstablish an organizing structure for identifying and creating policies that support the GRC capability.Encompasses advisory, legal and consulting services on required and desired policies, processes, procedures, accountability, and the standards for policy development and representation. OCEG GP301
G432Develop PoliciesDevelop a mix of preventative and directive policies to address requirements, risks, and other program objectives.Encompasses advisory, legal and consulting services on the substantive content and scope of policies. OCEG GP302
G433Implement and Manage PoliciesImplement, communicate, and manage policies to ensure that they operate and continue to be relevant.Encompasses advisory, legal, training, and consulting services on the implementation of policies, including the recommendations for new or changes to policies (actual policy revisions falls under GP3.2). OCEG GP303
G440EducationOCEG GP400
G441Define an Awareness and Education PlanDevelop a plan to inform and educate the Board, management, the workforce and the extended enterprise about their GRC responsibilities and expected conduct.Encompasses all advisory, legal, and consulting services for developing an enterprise level plan of education and awareness across each training requirement, including training of the extended enterprise (e.g., across the supply chain, joint ventures, and business partners). OCEG GP401
G442Define a Curriculum PlanDevelop a job specific curriculum and appropriate training program for the Board, senior management, the workforce and the extended enterprise to fulfill their GRC responsibilities.Encompasses all advisory, legal, and consulting services for role-specific training for employees, contractors and the extended enterprise (e.g., across the supply chain, joint ventures, and business partners). OCEG GP402
G443Develop or Acquire ContentDevelop or acquire content that does not exist in the curriculum or education plan and modify any content that needs updating in current learning objects.Encompasses all advisory, legal, and consulting services regarding the substantive content requirements of any awareness, curriculum or education plans. OCEG GP403
G444Implement EducationImplement and manage the education program to ensure that each target audience achieves learning objectives and can transfer knowledge and skills to their jobs.Encompasses all advisory, legal, and consulting services engaged to deliver awareness or educational programs. OCEG GP404
G445Provide HelplineEstablish ways for the workforce and other stakeholders to seek guidance about future conduct and ask general questions about GRC responsibilities, including the option for anonymity in locations where that is required or allowed.Encompasses all advisory, legal, consulting services regarding establishing helpline information. Also encompasses provision of outsourced helpline services. (Any content for scripts or guidance used by outsourced or insourced helpline provider falls under GP4.3 and any processes, procedures, or protocols for the helpline service falls under this number rather than GP1.2, and accountability is established under this number rather than GP1.2 for policies, or O3 for individuals). OCEG GP405
G446Provide Integrated SupportEstablish ways for the workforce to get questions about GRC requirements answered within their usual work environment.Encompasses all advisory, legal, consulting services regarding establishing self-help information and information when inquiries are raised through internal personnel or the organizational command structure. (Any content for scripts or guidance used by internal personnel falls under GP4.3 but any processes, procedures, or protocols for the provision of integrated support like open door policies falls GP 1.2 rather than this number.) OCEG GP406
G450IncentivesOCEG GP500
G451Hire and Promote Based on Conduct ExpectationsConsider articulate desirable conduct when defining jobs, career paths and performance review criteria of employees and business partners - and use these same criteria for promoting individuals.Encompasses advisory, legal, and consulting services on job descriptions, career paths, and performance review criteria for all business partners and individuals without specific GRC responsibilities. (This is general population requirements which may be a subset of but are distinct from those created under GO2.0 et seq.) OCEG GP501
G452Develop Compensation and Remuneration that Consider Conduct ExpectationsDesign compensation plans and bonus structures for employees and business partners that align with desired conduct and do not reward undesirable conduct.Encompasses advisory, legal, and consulting services on compensation and bonus programs for all business partners and individuals without specific GRC responsibilities. (This is general population requirements which may be a subset of but are distinct from those created under GO2.0 et seq.) OCEG GP502
G453Develop Rewards ProgramsEstablish a reward program for all employees, business partners and other stakeholders that recognizes individuals and organizational units for exhibiting desired conduct.Encompasses advisory, legal, and consulting services on reward programs for all business partners and individuals without specific GRC responsibilities. (This is general population requirements which may be a subset of but are distinct from those created under GO2.0 et seq.) OCEG GP503
G460Stakeholder RelationsOCEG GP600
G461Understand StakeholdersResearch and analyze the organizations and key individuals involved within various stakeholder constituencies in order to understand their concerns and how best to relate to them.Encompasses researching and profiling the predilections, temperament of, and enforcement trends of individual stakeholders within organizations that constitute sources and forces in the legal and geopolitical climate. (Captures more granular research than GC1.2, GA1.2 or GA1.3.) OCEG GP601
G462Develop Stakeholder Relations PlansDevelop stakeholder relations plans, including communications plans, for each stakeholder constituency.Encompasses developing stakeholder relations plans for individual stakeholders as well as organizations that constitute sources and forces in the legal and geopolitical climate. (Addresses action plans rather than understanding as described in GC1.2, GA1.2, and GA1.3.) OCEG GP602
G463Identify and Track Activity by Requirement Issuing AuthoritiesDetermine which government agencies, standards organizations, and other entities that issue mandates, standards or guidance have significant effect on the organization's GRC requirements and track their activities.Encompasses delivery of advisory, legal or consulting monitoring/tracking services and subscriptions to feeds of newly proposed and enacted laws, regulations, guidance, judicial opinions, and standards (Addresses execution rather than creating the relationship as described in GA1.9.) OCEG GP603
G464Comment on Planned or Proposed ItemsActively participate in the development of mandates, standards, and guidance through various comment pathways.Encompasses delivery of advisory, legal or consulting government affairs and standards development services initiated by others. (Addresses execution rather than creating the relationship as described in GA1.9.) OCEG GP604
G465Propose Mandates, Standards or GuidanceActively propose development of mandates, standards, and guidance to issuing authorities.Encompasses delivery of advisory, legal or consulting government affairs and standards development services initiated by the organization. (Addresses execution rather than creating the relationship as described in GA1.9.) OCEG GP605
G470Risk FinancingOCEG GP700
G471Assess Risk Financing Need and OptionsAssess the need or desire for financing risk and the options available.Encompasses advisory, legal or consulting services related to identify insurance, captives, indemnification, limitation of liability, joint defense, structured settlements, collections, bankruptcy, and other financing options for various risks. OCEG GP701
G472Set Risk Financing ObjectivesSet the risk sharing objectives and limits for the given risk or portfolio of risk.Internal legal and management opinion -- external charges should not apply. OCEG GP702
G473Design Risk Financing StrategyDesign a portfolio of risk-sharing instruments and approaches.Encompasses advisory, legal or consulting services related to recommendations on approaches for insurance, captives, indemnification, limitation of liability, joint defense, structured settlements, collections, bankruptcy, and other financing options for various risks. (Developing the strategy which is encompassed here is distinct from invoking the strategy as a response to a realized risk as provided in GR1.1). OCEG GP703
G474Implement Risk Financing StrategyImplement the risk sharing instruments or structures and acquire insurance.Encompasses advisory, legal or consulting services related to implementing insurance, captives, indemnification, limitation of liability, joint defense, structured settlements, collections, bankruptcy, and other financing options for various risks. (Putting the strategy in place through appropriate contract provisions which is encompassed here is distinct from invoking those provisions as a response to a realized risk as provided in GR1.1 or the development of other contracting standard provisions under GP1.1). OCEG GP704
G500DetectOCEG GD000
G510Unnamed in sourceThe LOC spreadsheet does not name this phase. OCEG GD100
G511Establish Detective Actions and ControlsEstablish detective actions and controls to detect and discern progress toward objectives as well as real and potential undesirable events and conditions.Encompasses advisory, legal and consulting services related to establishing detective actions and controls like fraud reporting and vendor audit programs. (This number covers establishing the actions and controls whereas GD2.1 covers utilization of them.) OCEG GD101
G512Establish Detective Process ControlsEstablish process control activities and procedures that detect adverse events, noncompliance and misconduct.Encompasses, all design of processes for monitoring financial transactions, transfers of physical assets, and the detection and notification of unauthorized disclosure of private information. Also includes any expected detective process controls like quality inspections to be promulgated through supply chain, joint venture, and business partner programs. (This number covers establishing process controls whereas GD2.1 covers execution of the processes.) OCEG GD102
G513Establish Detective Human Capital ControlsEstablish human capital control activities and procedures that detect adverse events, noncompliance and misconduct.Encompasses, all design of human capital controls for reporting observed adverse events, noncompliance and misconduct, including exit interviews. (This number covers establishing human capital controls whereas GD2.1 covers execution of them.) OCEG GD103
G514Establish Detective Physical ControlsInstall physical controls necessary to provide surveillance of physical preventive controls and areas where noncompliance or unethical conduct can be physically observed.Encompasses all advisory services, recommendations, and legal opinions regarding physical controls (i.e., surveillance equipment, entry/exit monitoring devices, alarm systems, emissions detectors, quality inspections, etc.), related to security of and access to facilities, physical assets, information assets, and the detection of unauthorized disclosure of private information. (This number covers establishing physical controls whereas GD2.1 covers execution of them.) OCEG GD104
G515Establish Detective Technology ControlsImplement and monitor automated detective technology controls to promptly identify actual or potential misconduct.Encompasses all advisory services, recommendations, legal opinions and consulting services regarding technological controls (i.e., software, business rules, algorithms, dashboards, electronic alerts, etc.), related to detection of misconduct or noncompliance. (This number covers establishing technology controls whereas GD2.1 covers execution of them.) OCEG GD105
G516Consolidate and Analyze Control FindingsConsolidate and analyze all information gathered through various means of detection to identify patterns of misconduct, adverse events and other weaknesses that would otherwise go unnoticed.Encompasses all advisory and consulting services related to the methods to be used to aggregate and analyze detected events as well as execution of the analysis, including discerning patterns, weaknesses and benchmarked comparisons. OCEG GD106
G520NotificationOCEG GD200
G521Capture NotificationsImplement a notification system that will alert the organization to incidents or suspicions of legal noncompliance, violations of company policies, and concerns or perceptions about perceived unethical conduct, GRC capability weaknesses and performance at all levels.Encompasses all advisory services, recommendations, legal opinions and consulting services regarding methods of notification, including establishing a hotline and restrictions or mandates for anonymous reporting. OCEG GD201
G523Filter and Route NotificationsVet and route notifications for handling, regardless of the pathway through which a given notification is received.Internal legal and management opinion -- external charges should not apply. OCEG GD203
G524Adhere to Data Protection RequirementsEnsure that the hotline pathway for notification complies with specific requirements established in the locale where the notice originates and where the organization operates.Encompasses all advisory services, recommendations, legal opinions and consulting services regarding restrictions or mandates for anonymous reporting, cross-border data transfers, and privacy. OCEG GD204
G530InquiryOCEG GD300
G531Establish Multiple Pathways to Obtain Workforce and Stakeholder ViewsDefine opportunities for obtaining workforce and stakeholder views about risk, the GRC capability, conduct and organizational commitment to its stated values.Encompasses advisory, legal and consulting services related to surveying and interviewing for workforce and stakeholder views, including outsourced surveys and HR processes. OCEG GD301
G532Establish an Organization-Wide Integrated Approach to SurveysEstablish a survey approach that reduces the burden on survey subjects and provides a consolidated view of information obtained from the workforce and other stakeholders.Encompasses advisory, legal and consulting services related to an integrated approach to surveying. OCEG GD302
G533Establish an Integrated Approach to Self-AssessmentsEstablish a self-assessment approach that integrates assessment of GRC capability-related responsibilities and outcomes with other self-assessments imposed on management.Encompasses advisory, legal and consulting services related to an integrated approach to self-assessment, including programs expanded to include the extended enterprise. OCEG GD303
G534Gather information through observations and conversationsEstablish informal methods of gathering views through observations, group meetings, focus groups and individual conversations.Encompasses advisory, legal and consulting services related to observations, group discussions and individual interviews conducted by outside providers, including depositions or other sworn testimony. OCEG GD304
G535Report Information and FindingsProvide information and findings from all methods of inquiry to management.Encompasses advisory, legal and consulting services related to reporting aggregated information obtained through surveys, discussions, and self-assessments. OCEG GD305
G600RespondOCEG GR000
G610Responsive Actions & ControlsOCEG GR100
G611Establish Responsive Actions and ControlsEstablish responsive actions and controls that reward desirable conduct; punish undesirable conduct; and correct the identified weaknesses in the capability.Encompasses advisory, legal and consulting services related to establishing responsive actions and controls like media relations, internal conflicts resolution, litigation, litigation holds, and bankruptcy filings. (This number covers establishing the actions and controls as well as execution of actions and controls other than those covered by GR2-GR4.) OCEG GR101
G612Establish Corrective Process ControlsEstablish corrective process control activities to stop, slow and recover from adverse events, and deter future adverse events.Encompasses advisory, legal and consulting services related to establishing corrective process controls. (This number covers establishing the process controls; execution of corrective controls falls under GR5.1.) OCEG GR102
G613Establish Corrective Human Capital ControlsEstablish corrective human capital controls that stop, slow and recover from adverse events, and deter future adverse events.Encompasses advisory, legal and consulting services related to establishing corrective human capital controls like suspending authority, overriding reporting structures, and marshalling corrective action teams. (This number covers establishing the human capital controls; execution of corrective controls falls under GR5.1.) OCEG GR103
G614Establish Corrective Technology ControlsEstablish corrective technology controls that stop, slow and recover from adverse events, and deter future adverse events.Encompasses advisory, legal and consulting services related to establishing corrective technology controls, including access restrictions, suspension of system processes, and retention of documents and records. (This number covers establishing the technology controls; execution of corrective controls falls under GR5.1.) OCEG GR104
G615Establish Corrective Physical ControlsEstablish corrective physical controls that stop, slow and recover from adverse events, and deter future adverse events.Encompasses advisory, legal and consulting services related to establishing corrective physical controls, including access restrictions, lock-down procedures, hardening infrastructure and fire suppression. (This number covers establishing the physical controls; execution of corrective controls falls under GR5.1.) OCEG GR105
G616Monitor and Report Corrective ControlsMonitor and report the progress of corrective control activities.Encompasses advisory, legal and consulting services related to monitoring and reporting corrective controls. (This number covers establishing the monitoring and reporting activities as well as execution monitoring and reporting.) OCEG GR106
G620Internal InvestigationOCEG GR200
G621Define the Inquiry and Investigation ProcessEstablish procedures for inquiring further into, and investigating, complaints or reports about compliance or ethical issues, as well as for issues detected during ongoing monitoring or periodic evaluation of the GRC capability.Encompasses advisory, legal and consulting services related to establishing a defensible inquiry and investigation process and analyzing trends and patterns, including a taxonomy for classifying topics and severity of inquiries and issues, escalation process for routing, and procedures for maintaining confidentiality and anonymity. OCEG GR201
G622Prepare to InvestigatePrepare to undertake the activities of the investigation phase of the issue resolution process.Encompasses engaging advisors, lawyers, investigators, and consultants to perform inquiries and investigations, including obtaining appropriate disclosures of conflicts and independence and coordinating with various departments and stakeholders to be engaged in the process. OCEG GR202
G623Conduct InvestigationsConduct investigations consistent with the plan and communicate with relevant stakeholders while maintaining appropriate privileged status.Encompasses advisory, legal, eDiscovery, and consulting services delivered while conducting inquiries and investigations, including document location and production. OCEG GR203
G624Report Results of InvestigationsCommunicate investigation results to appropriate management, oversight bodies and, as appropriate, to other stakeholders and regulators.Encompasses advisory, legal and consulting services reporting the results of inquiries and investigations. OCEG GR204
G630Third-Party InvestigationsOCEG GR300
G631Prepare for and Address Third Party InquiriesIdentify and respond to questions from third parties.Encompasses engaging advisors, lawyers, investigators, and consultants to respond to third-party inquiries and investigations, including obtaining appropriate disclosures of conflicts and independence. OCEG GR301
G632Prepare to Identify Third Party InvestigationsEstablish methods to ensure the right people know about initiated third party investigations.Internal legal and management opinion -- external charges should not apply. OCEG GR302
G633Prepare to Manage Third Party InvestigationsEstablish policies, procedures, and responsibility for managing various types of third party investigations.Encompasses advisory, legal, eDiscovery, and consulting services to respond to third-party inquiries and investigations, including media relations, disclosure of conflicts and independence, procedures for confidentiality and privilege, and coordinating with various departments and stakeholders to be engaged in the process. OCEG GR303
G634Prepare to Select Team for Third-Party InvestigationEstablish procedures for selecting the team of individuals that will represent the organization during a specific investigation.Encompasses engaging preferred providers as advisors, lawyers, investigators, eDiscovery providers, and consultants to prepare an appropriate response. OCEG GR304
G635Prepare to Respond to Specific Third-Party InvestigationsEstablish procedures for developing a response to a specific investigation.Encompasses advisory, legal, eDiscovery, and consulting services delivered while responding to specific third-party inquiries and investigations, including document location and production. OCEG GR305
G640Crisis ResponseOCEG GR400
G641Develop Crisis Response and Continuity PlansDevelop the plans for responding to various types of crises and recovering from business disruption.Encompasses advisory, legal, investigative, and consulting services engaged to develop emergency operating procedures, crisis response, business continuity and disaster recovery plans, including providing business impact analysis. OCEG GR401
G642Identify Crisis Readiness and Response TeamsDefine personnel who will be responsible for crisis preparedness and those who will be deployed as crisis response teams for each type of identified crisis.Encompasses identifying advisors, lawyers, investigators, and consultants to be engaged as part of the response team for various crises and costs associated with having 24x7 contact methods. OCEG GR402
G643Test Plans and ProceduresTest and evaluate the various crisis plans and procedures.Encompasses involvement of advisors, lawyers, investigators, and consultants in testing crisis response, business continuity, and disaster recovery plans and procedures. OCEG GR403
G644Coordinate PlansCoordinate the various continuity and response plans in anticipation of business disruption that may span more than one facility.Encompasses involvement of advisors, lawyers, investigators, and consultants in reconciling multiple crisis response, business continuity, and disaster recovery plans and procedures. OCEG GR404
G650RemediationOCEG GR500
G651Remediate the GRC capabilityResolve each reported issue/incident, document the outcome, and propose appropriate changes to the GRC capability to avoid similar issues in the future.Encompasses advisory, legal and consulting services related to remediating the GRC capability, including identification of patterns of root causes, recommendations for new or modifications to actions, risks or controls or changes to prioritization of risks or remediation plans. OCEG GR501
G652Discipline IndividualsDiscipline individuals for misconduct.Internal legal and management action -- external charges should not apply. OCEG GR502
G653Disclose Issue ResolutionWhen required or appropriate, disclose findings and resolution of investigations to stakeholders.Encompasses advisory, legal and consulting services related to communicating with internal and external stakeholders, including regulators, enforcement authorities, and third-party investigators. OCEG GR503
G660RewardsOCEG GR600
G700MeasureOCEG GM000
G710Context MonitoringOCEG GM100
G711Monitor External ContextContinually monitor changes in the external environment that may have a direct, indirect or cumulative effect on the organization.Internal legal and management activity -- external charges should not apply. (Relevant external monitoring is covered under GC1.2, GA1.9, and GP6.1, time spent here would essentially be business development write-offs providing newsletters, general advisories, etc.) OCEG GM101
G712Monitor Internal ContextContinually monitor changes in the internal environment that may have a direct, indirect or cumulative effect on the organization.Internal legal and management opinion -- external charges should not apply (time spent here would essentially be non-chargeable business development activities associated with knowing your client). OCEG GM102
G720Unnamed in sourceThe LOC spreadsheet does not name this phase. OCEG GM200
G721Monitor and Evaluate Capability DesignEstablish a schedule for periodic re-evaluation of the appropriateness of the capability design in light of objectives, opportunities, threats and requirements.Encompasses advisory, legal, or consulting services (excluding audit services) in evaluating the suitability of the GRC program design and performance for the purpose of making recommendations for improvement to an existing program. OCEG GM201
G722Review and Reconsider RisksReview any previously assessed or newly identified risks and reconsider, or assess for the first time, their priority based on the best information currently available.Internal legal and management activity -- external charges should not apply. (Relevant external risk management assessment is covered under GM4) OCEG GM202
G723Identify Relevant Actions and ControlsReview the related actions and controls in place to address high priority objectives, threats, opportunities and requirements.Encompasses advisory, legal, or consulting services (excluding audit services) in evaluating the suitability of the design and performance of existing actions and controls for the purpose of making recommendations for improvement or changes to those actions and controls. OCEG GM203
G724Analyze Potential for FailureAnalyze the potential that risk-optimizing activities will fail and the ways in which they might fail.Encompasses advisory, legal, or consulting services (excluding audit services) in evaluating the potential for and methods of failure of risk-optimizing activities for the purpose of making recommendations for improvement or changes to those actions and controls. OCEG GM204
G725Identify Monitoring InformationIdentify the information to use to support the evaluation of the performance of the risk optimizing activity(s) and/or the overall performance of the GRC capability.Encompasses advisory, legal, or consulting services (excluding audit services) in planning the collection of evidence to support the analysis and recommendations for improvement or changes to actions and controls and the overall GRC capability. OCEG GM205
G726Perform Monitoring ActivitiesPerform monitoring activities to support the evaluation of the performance of the system.Encompasses advisory, legal, or consulting services (excluding audit services) in collecting evidence to support the analysis and recommendations for improvement or changes to actions and controls and the overall GRC capability. OCEG GM206
G727Analyze and Report Monitoring ResultsAnalyze the results of monitoring activities to identify instant weaknesses and opportunities for systemic improvements.Encompasses advisory, legal, or consulting services (excluding audit services) in reporting findings and recommendations for improvement or changes to actions and controls and the overall GRC capability. OCEG GM207
G730Systemic ImprovementOCEG GM300
G731Develop Improvement PlanDevelop a prioritized plan for implementing improvements to the program.Encompasses advisory, audit, legal or consulting services in developing a portfolio of GRC capability improvement initiatives. OCEG GM301
G732Implement Improvement InitiativesImplement the specific action plans and initiatives intended to improve the program.Encompasses utilizing advisory, audit, legal or consulting services to implement a portfolio of GRC capability improvement action plans and initiatives. OCEG GM302
G740AssuranceOCEG GM400
G741Plan Assurance AssessmentDetermine scope, procedures and criteria required to provide desired level of assurance.Encompasses the planning phase of auditors engaged to provide audit or assurance services. OCEG GM401
G742Perform Assurance AssessmentPerform procedures, evaluate results against criteria and deliver report.Encompasses the delivery phase of auditors engaged to provide audit or assurance services. OCEG GM402
G800InteractOCEG GI000
G810Information ManagementOCEG GI100
G811Develop a GRC Information Management Classification StructureDetermine the definitions, classifications and procedures necessary to identify and manage GRC information in the organization and extended enterprise, as part of an Information Management Plan.Encompasses advisory, legal, eDiscovery, and consulting services to develop an information management classification schema and procedures including retention, preservation, confidentiality, knowledge management, and privacy. OCEG GI101
G812Develop GRC Information Collection Policies & ProceduresEstablish the policies and procedures necessary to collect GRC information from sources within and outside the organization and extended enterprise, as part of an Information Management Plan.Encompasses advisory, legal, eDiscovery, and consulting services to develop information collection policies and procedures. OCEG GI102
G813Develop GRC Information Access, Use and Transfer Policies & ProceduresEstablish the policies and procedures necessary to access, use and transfer GRC information in the organization and extended enterprise, as part of an Information Management Plan.Encompasses advisory, legal, eDiscovery, and consulting services to develop access, use, and transfer procedures including compliance with data transfer, confidentiality and privilege restrictions and security and breach containment and notification requirements. OCEG GI103
G814Develop GRC Information Storage & Disposition Policy & ProceduresEstablish the policies and procedures necessary to store GRC information in the organization and extended enterprise in accordance with requirements and recovery objectives, as part of an Information Management Plan.Encompasses advisory, legal, eDiscovery, and consulting services to develop policies and procedures including retention, preservation, restoration, disposition of information, reconciling knowledge management, back-up, archiving and media rotation processes. OCEG GI104
G820CommunicationOCEG GI200
G821Develop Reporting PlanEstablish a plan to ensure compliance with mandatory reporting requirements and provide desired reports to management, the Board, and stakeholders.Encompasses advisory, legal, and consulting services in establishing required reporting practices, including regulatory reporting, and desired reporting to stakeholders, including shareholders. OCEG GI201
G822Develop Communication PlanDefine how the organization will manage GRC related communications that are not formal reports.Encompasses advisory, legal, and consulting services in establishing internal communication plans, including change management messaging. OCEG GI202
G830TechnologyOCEG GI300
G831Assess Technology Needs and GapsIdentify gaps and underperforming systems in existing technology environment.Encompasses advisory consulting services identifying technological requirements, gaps and opportunities whether point solutions or enterprise architecture including designation of systems of record that "own" particular information and the data flow and protocols used for exchanges emanating from those systems. OCEG GI301
G832Develop GRC Technology Portion of GRC Strategic PlanDevelop plan for implementing technology to enable GRC processes and information flows.Encompasses advisory consulting services in developing a plan that prioritizes implementation initiatives, and implementing appropriate solutions, architectures, information flows, and protocols to enable GRC processes and information requirements. OCEG GI302
utbms.com - LOC GRC Code Set

Search every code set

Not sure which set a line belongs to? The UTBMS code lookup searches all 625 codes and the LEDES 1998B and 98BI fields at once. Type a code or describe the work in plain English.

Who maintains this page

Caddi automates the business of law

Caddi builds and runs automations for law firms: new matter intake, filing to the DMS, time capture, pre-bill review, and AR follow-up, inside the systems your firm already runs, from iManage and NetDocuments to Clio, Aderant, and Elite 3E. Coding to the set your client mandates is the easy half. Remembering the work is the hard one.