About Forrester
Forrester Research, Inc. is an independent research company that provides pragmatic and forward-thinking advice to global leaders in business and technology.

Duncan primarily contributes to Forrester's offerings for Sourcing & Vendor Management Professionals. He is a leading expert on software pricing and licensing and helps clients understand and address the effect of technology changes on software contracts. By researching enterprises' experience in dealing with large software vendors, including their negotiation successes and the problems they encountered later in the relationship, Duncan helps clients create and execute sound negotiation strategies and get advantageous software license and maintenance agreements.
He is also a leading expert on ePurchasing technologies, such as eProcurement, eSourcing, and electronic invoice presentment and payment (EIPP), and he advises clients on their application strategy in this area, how to make good choices between alternative solution providers, and how to get the best results from implementation.
Prior to joining Forrester, Duncan worked for QAD, an international provider of enterprise solutions for manufacturing companies in various product management and product marketing roles. Most recently, he had global responsibility for radical changes to QAD's pricing and licensing strategy.
Duncan qualified as a chartered accountant with KPMG and then joined Courtaulds, a diverse multinational manufacturing company. He held various line finance and IT roles before becoming project manager in a corporate team, managing systems-enabled business improvement projects around the world.
Duncan has a first-class degree in mathematics from Hertford College at the University of Oxford and is a member of the Institute of Chartered Accountants in England and Wales.

Processes: The Governance, Risk, And Compliance Playbook
As a risk professional, you are currently in a position to exert more influence on your organization and increase the value you and your team can offer. Many of you will feel pressure to develop...

This report outlines Forrester's solution for security and risk (S&R) professionals looking to establish a formal risk and compliance management program. We designed this report to help S&R...
This week we published the first in a series of reports I'll be writing to help clients calculate the return on investment of GRC technologies. This report, How To Measure The ROI Of A GRC...
Documenting The Sources Of Uncertainty That Might Affect Your Organization, Project, Asset, Or Objective
Enterprise risk management (ERM) programs are helping to break down organizational silos so that executives can gain insight on the risks that may affect all aspects of their business. Unfortunately,...
We're looking for software that assists with the management and auditing of gifts that our employees receive from customers and suppliers.
Executive Overview: The Governance, Risk, And Compliance Playbook
Unexpected events are at best distracting and at worst catastrophic for an organization as it strives to meet its objectives. Risk and compliance professionals must help their colleagues anticipate...
Determining Whether, When, And How To Treat Risks
The goal of a risk management program is to drive effective decisions and actions based on an understanding of how uncertainty may affect objectives. However, even mature programs that have...
Guest post from Researcher Nick Hayes. Take a second to think back to the year 2009. The US was in the thick of the financial crisis; companies were slashing budgets, and the unemployment rate...
Developing And Managing Efforts To Control Unacceptable Levels Of Risk
From understanding comes action. Your risk management efforts up to this point will have yielded a list of concerns; a measure of how much these concerns could affect objectives; and a decision of...

Organization: The Governance, Risk, And Compliance Playbook
Governance, risk, and compliance (GRC) encompass an incredibly broad set of functions for organizations in any geography, in any industry. In fact, almost all employees play some role in helping...

RSA Archer, Agiliance, Rsam, Symantec, and Modulo Are All Leaders For Very Different Reasons
IT governance, risk, and compliance (GRC) vendors continue to show strong technical and strategic advances, while the market itself still struggles to define its direction. A small set of vendors...
Vision: The Governance, Risk, And Compliance Playbook
This report outlines the future look of Forrester's solution for security and risk (S&R) executives working to build their organization's governance, risk, and compliance (GRC) program. We designed...
Last week saw news that yet another top GRC software vendor has been acquired, following in the footsteps of Paisley, Archer, OpenPages, among others. BWise has always been an impressive vendor in...
GRC Programs Are Set To Increase Their Breadth More Than Their Maturity
Those who have been involved with GRC initiatives or technologies may often conceive of a tipping point, where GRC comes of age and its value propositions and use cases become clear for all global...
What is the size of the governance, risk, and compliance (GRC) market, and what is the market growth rate in India? Who are the major GRC vendors in India, and what are the areas of opportunity?
After months of diligent product and vendor evaluations, today we published The Forrester Wave: Enterprise GRC Platforms, Q4 2011. In the next few days, we will also publish The Forrester Wave: IT...
I’m proud to announce that this week Forrester launched our Governance, Risk, and Compliance Playbook, a collection of in-depth reports covering the critical information you need to implement a...
Business Case: The Governance, Risk, And Compliance Playbook
As the governance, risk, and compliance (GRC) platform market matures, product vendors struggle to point to credible return on investment figures, and potential buyers similarly struggle when asked...
What would you see as the governance, risk, and compliance characteristics of each of the following groups: 1) laggards; 2) middle of the pack; and 3) early adopters? Are there any special...