Analysis of the Implementation of Governance, Risk, and Compliance (GRC) in Supporting Information Technology Governance at Bank Pembangunan Daerah Kalimantan Barat
DOI:
https://doi.org/10.55681/economina.v5i9.4420Keywords:
GRC, IT Governance, Risk Management, Compliance, Bank KalbarAbstract
This study analyzes how Governance, Risk, and Compliance (GRC) is implemented in supporting information technology (IT) governance at Bank Pembangunan Daerah Kalimantan Barat (Bank Kalbar), and how IT utilization supports the implementation of IT GRC. A qualitative approach with a descriptive method was used. Primary data were obtained through in-depth interviews with the Head of the Information Technology Division and an IT GRC staff member, selected through purposive sampling, and were complemented by the Bank's 2025 Annual Report and Governance Report and relevant regulations of the Financial Services Authority (OJK). Data were analyzed through data reduction, data display, and conclusion drawing and verification. The findings show that GRC is implemented through IT policies and procedures, risk identification, assessment, prioritization, control, and monitoring, compliance with regulator requirements and internal SOPs, and IT audits with follow-up. IT in turn supports IT GRC through access control, change management, backup and recovery, security monitoring, IT general and application controls tested through TDE and TOE, and the Digital Resilience Center. Constraints include limited IT development budgets, numerous unit requests, third-party delays, and the time required for audit follow-up. The findings indicate that IT GRC is a continuous process that requires priority setting, vendor monitoring, and follow-up tracking.
Downloads
References
Abdurrahman, A., Gustomo, A., & Prasetio, E. A. (2024). Enhancing banking performance through dynamic digital transformation capabilities and governance, risk management, and compliance: Insights from the Indonesian context. The Electronic Journal of Information Systems in Developing Countries, 90(2), e12299. https://doi.org/10.1002/isd2.12299
ANTARA News Kalimantan Barat. (2025, January 21). Bank Kalbar catat transaksi QRIS 2024 sebesar Rp211,96 miliar. https://kalbar.antaranews.com/berita/619302/bank-kalbar-catat-transaksi-qris-2024-sebesar-rp21196-miliar
Bahri, S. (2018). Metodologi penelitian bisnis: Lengkap dengan teknik pengolahan data SPSS. ANDI.
Bank Kalbar. (n.d.). Laporan tahunan dan keberlanjutan [Annual and sustainability reports]. PT Bank Pembangunan Daerah Kalimantan Barat. https://bankkalbar.co.id/laporan_tahunan.php
Fitriani, F., Sandy, K. N., Amiruddin, A., & Syamsuddin, S. (2024). Governance, risk, and compliance: Pilar utama untuk audit berbasis nilai tambah. Jurnal Akuntansi dan Keuangan Kontemporer, 7(2), 374–385. https://doi.org/10.30596/jakk.v7i2.24756
International Organization for Standardization. (2022). ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection: Information security management systems: Requirements. https://www.iso.org/standard/27001
ISACA. (2018). COBIT 2019 framework: Governance and management objectives. ISACA.
Muziardy, E., & Yuniarti, R. (2025). Analysis of governance, risk, and compliance (GRC) implementation in rural bank management: A case study at PT BPR Panjawan Mitra Usaha. Journal of Economics and Business UBS, 14(4), 901–906. https://doi.org/10.52644/joeb.v14i4.2781
Nurdin, A. (2018). Pemetaan tata kelola TI dan analisa faktor penghambatnya: Studi kasus PT Bank DNM, Tbk. JIKA (Jurnal Informatika), 2(1). https://doi.org/10.31000/jika.v2i1.1410
Otoritas Jasa Keuangan. (2017). Peraturan Otoritas Jasa Keuangan Nomor 46/POJK.03/2017 tentang pelaksanaan fungsi kepatuhan bank umum. https://ojk.go.id/id/regulasi/Pages/Pelaksanaan-Fungsi-Kepatuhan-Bank-Umum.aspx
Otoritas Jasa Keuangan. (2022). Peraturan Otoritas Jasa Keuangan Nomor 11/POJK.03/2022 tentang penyelenggaraan teknologi informasi oleh bank umum. https://ojk.go.id/id/regulasi/Pages/Penyelenggaraan-Teknologi-Informasi-Oleh-Bank-Umum.aspx
Otoritas Jasa Keuangan. (2023). Peraturan Otoritas Jasa Keuangan Nomor 17 Tahun 2023 tentang penerapan tata kelola bagi bank umum. https://ojk.go.id/id/regulasi/Pages/Penerapan-Tata-Kelola-Bagi-Bank-Umum.aspx
Pascoe, C., Quinn, S., & Scarfone, K. (2024). The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.CSWP.29
Racz, N., Weippl, E., & Seufert, A. (2010). A frame of reference for research of integrated governance, risk and compliance (GRC). In B. De Decker & I. Schaumüller-Bichl (Eds.), Communications and multimedia security (Lecture Notes in Computer Science, Vol. 6109, pp. 106–117). Springer. https://doi.org/10.1007/978-3-642-13241-4_11
Suara Ketapang. (2024, December 14). ATM Bank Kalbar di Ketapang sering gangguan, nasabah keluhkan pelayanan. https://ketapang.suarakalbar.co.id/2024/12/atm-bank-kalbar-di-ketapang-sering.html
Sugiyono. (2023). Metode penelitian kuantitatif, kualitatif, dan R&D (2nd ed.). Alfabeta.
Tursina, N. (2025). Pengaruh teknologi informasi terhadap tata kelola, risiko dan kepatuhan (GRC) yang dimoderasi kinerja keuangan. COSTING: Journal of Economic, Business and Accounting, 8(2), 901–918. https://doi.org/10.31539/costing.v8i2.14325
Wibowo, A. P., Raharjo, T., Trisnawaty, N. W., Muhamad, G. A., & Faridy, A. (2025). Risk management in IT projects for digital banking: A case study of an Indonesian state-owned bank. Applied Information System and Management, 8(2), 231–244. https://doi.org/10.15408/aism.v8i2.46123
Wulandari, N. (2022). Sistem informasi, organisasi, dan strategi: Studi litratur permasalahan manajemen pada teknologi informasi. JIKSI: Jurnal Ilmu Komputer dan Sistem Informasi, 3(1), 1–6. https://doi.org/10.61346/jiksi.v3i1.127
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 JURNAL ECONOMINA

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.








