Analysis of the Implementation of Governance, Risk, and Compliance (GRC) in Supporting Information Technology Governance at Bank Pembangunan Daerah Kalimantan Barat

Authors

  • Anistya Fitri Larasati Politeknik Negeri Pontianak, Indonesia
  • Syarifah Novieyana Politeknik Negeri Pontianak, Indonesia
  • Lidya Sri Mulyani Politeknik Negeri Pontianak, Indonesia
  • Marsela Diaz Politeknik Negeri Pontianak, Indonesia

DOI:

https://doi.org/10.55681/economina.v5i9.4420

Keywords:

GRC, IT Governance, Risk Management, Compliance, Bank Kalbar

Abstract

This study analyzes how Governance, Risk, and Compliance (GRC) is implemented in supporting information technology (IT) governance at Bank Pembangunan Daerah Kalimantan Barat (Bank Kalbar), and how IT utilization supports the implementation of IT GRC. A qualitative approach with a descriptive method was used. Primary data were obtained through in-depth interviews with the Head of the Information Technology Division and an IT GRC staff member, selected through purposive sampling, and were complemented by the Bank's 2025 Annual Report and Governance Report and relevant regulations of the Financial Services Authority (OJK). Data were analyzed through data reduction, data display, and conclusion drawing and verification. The findings show that GRC is implemented through IT policies and procedures, risk identification, assessment, prioritization, control, and monitoring, compliance with regulator requirements and internal SOPs, and IT audits with follow-up. IT in turn supports IT GRC through access control, change management, backup and recovery, security monitoring, IT general and application controls tested through TDE and TOE, and the Digital Resilience Center. Constraints include limited IT development budgets, numerous unit requests, third-party delays, and the time required for audit follow-up. The findings indicate that IT GRC is a continuous process that requires priority setting, vendor monitoring, and follow-up tracking.

Downloads

Download data is not yet available.

References

Abdurrahman, A., Gustomo, A., & Prasetio, E. A. (2024). Enhancing banking performance through dynamic digital transformation capabilities and governance, risk management, and compliance: Insights from the Indonesian context. The Electronic Journal of Information Systems in Developing Countries, 90(2), e12299. https://doi.org/10.1002/isd2.12299

ANTARA News Kalimantan Barat. (2025, January 21). Bank Kalbar catat transaksi QRIS 2024 sebesar Rp211,96 miliar. https://kalbar.antaranews.com/berita/619302/bank-kalbar-catat-transaksi-qris-2024-sebesar-rp21196-miliar

Bahri, S. (2018). Metodologi penelitian bisnis: Lengkap dengan teknik pengolahan data SPSS. ANDI.

Bank Kalbar. (n.d.). Laporan tahunan dan keberlanjutan [Annual and sustainability reports]. PT Bank Pembangunan Daerah Kalimantan Barat. https://bankkalbar.co.id/laporan_tahunan.php

Fitriani, F., Sandy, K. N., Amiruddin, A., & Syamsuddin, S. (2024). Governance, risk, and compliance: Pilar utama untuk audit berbasis nilai tambah. Jurnal Akuntansi dan Keuangan Kontemporer, 7(2), 374–385. https://doi.org/10.30596/jakk.v7i2.24756

International Organization for Standardization. (2022). ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection: Information security management systems: Requirements. https://www.iso.org/standard/27001

ISACA. (2018). COBIT 2019 framework: Governance and management objectives. ISACA.

Muziardy, E., & Yuniarti, R. (2025). Analysis of governance, risk, and compliance (GRC) implementation in rural bank management: A case study at PT BPR Panjawan Mitra Usaha. Journal of Economics and Business UBS, 14(4), 901–906. https://doi.org/10.52644/joeb.v14i4.2781

Nurdin, A. (2018). Pemetaan tata kelola TI dan analisa faktor penghambatnya: Studi kasus PT Bank DNM, Tbk. JIKA (Jurnal Informatika), 2(1). https://doi.org/10.31000/jika.v2i1.1410

Otoritas Jasa Keuangan. (2017). Peraturan Otoritas Jasa Keuangan Nomor 46/POJK.03/2017 tentang pelaksanaan fungsi kepatuhan bank umum. https://ojk.go.id/id/regulasi/Pages/Pelaksanaan-Fungsi-Kepatuhan-Bank-Umum.aspx

Otoritas Jasa Keuangan. (2022). Peraturan Otoritas Jasa Keuangan Nomor 11/POJK.03/2022 tentang penyelenggaraan teknologi informasi oleh bank umum. https://ojk.go.id/id/regulasi/Pages/Penyelenggaraan-Teknologi-Informasi-Oleh-Bank-Umum.aspx

Otoritas Jasa Keuangan. (2023). Peraturan Otoritas Jasa Keuangan Nomor 17 Tahun 2023 tentang penerapan tata kelola bagi bank umum. https://ojk.go.id/id/regulasi/Pages/Penerapan-Tata-Kelola-Bagi-Bank-Umum.aspx

Pascoe, C., Quinn, S., & Scarfone, K. (2024). The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.CSWP.29

Racz, N., Weippl, E., & Seufert, A. (2010). A frame of reference for research of integrated governance, risk and compliance (GRC). In B. De Decker & I. Schaumüller-Bichl (Eds.), Communications and multimedia security (Lecture Notes in Computer Science, Vol. 6109, pp. 106–117). Springer. https://doi.org/10.1007/978-3-642-13241-4_11

Suara Ketapang. (2024, December 14). ATM Bank Kalbar di Ketapang sering gangguan, nasabah keluhkan pelayanan. https://ketapang.suarakalbar.co.id/2024/12/atm-bank-kalbar-di-ketapang-sering.html

Sugiyono. (2023). Metode penelitian kuantitatif, kualitatif, dan R&D (2nd ed.). Alfabeta.

Tursina, N. (2025). Pengaruh teknologi informasi terhadap tata kelola, risiko dan kepatuhan (GRC) yang dimoderasi kinerja keuangan. COSTING: Journal of Economic, Business and Accounting, 8(2), 901–918. https://doi.org/10.31539/costing.v8i2.14325

Wibowo, A. P., Raharjo, T., Trisnawaty, N. W., Muhamad, G. A., & Faridy, A. (2025). Risk management in IT projects for digital banking: A case study of an Indonesian state-owned bank. Applied Information System and Management, 8(2), 231–244. https://doi.org/10.15408/aism.v8i2.46123

Wulandari, N. (2022). Sistem informasi, organisasi, dan strategi: Studi litratur permasalahan manajemen pada teknologi informasi. JIKSI: Jurnal Ilmu Komputer dan Sistem Informasi, 3(1), 1–6. https://doi.org/10.61346/jiksi.v3i1.127

Downloads

Published

2026-09-30

How to Cite

Anistya Fitri Larasati, Novieyana, S., Mulyani, L. S., & Diaz, M. (2026). Analysis of the Implementation of Governance, Risk, and Compliance (GRC) in Supporting Information Technology Governance at Bank Pembangunan Daerah Kalimantan Barat. JURNAL ECONOMINA, 5(9), 7512–7529. https://doi.org/10.55681/economina.v5i9.4420