Skip to content
Reference

GRC (Governance, Risk and Compliance): Definition and Frameworks

The short version

Governance, risk and compliance (GRC) is the coordinated management of an organization's governance, its risks and its obligations to comply with laws, regulations and its own policies. OCEG, the body that developed the term, defines GRC as the capability, or integrated collection of capabilities, that enables an organization to reliably achieve objectives, address uncertainty and act with integrity. GRC draws on established frameworks, notably the IIA's Three Lines Model and COSO's internal control and enterprise risk management frameworks. GRC software is the category of systems used to hold the records of that work: policies, risks, controls, issues, the regulatory inventory, evidence and reports.

Governance, risk and compliance (GRC) is the integrated management of three related functions: governance, the structures and processes by which an organization is directed and held accountable; risk management, the identification, assessment and treatment of uncertainty affecting its objectives; and compliance, conformance with laws, regulations, contracts and the organization's own policies. The term also names a category of software used to support that work.

The premise of GRC is that the three functions share information. A risk assessment identifies which controls matter; controls are how compliance obligations are met; governance bodies set risk appetite and receive reporting on all three. Managed separately, the same control may be documented three times and tested three times, and a failure seen by one function may not reach the others.

The OCEG definition and principled performance

OCEG (originally the Open Compliance and Ethics Group) developed the GRC concept in the early 2000s and maintains the GRC Capability Model, known as the Red Book. OCEG defines GRC as "the capability, or integrated collection of capabilities, that enables an organization to reliably achieve objectives, address uncertainty, and act with integrity." It calls the outcome of that capability principled performance, which it describes as achieved when an organization reliably achieves objectives, addresses uncertainty and acts with integrity.

The definition treats GRC as an organizational capability, not a department or a product. The three elements map onto the three words: achieving objectives corresponds to governance, addressing uncertainty to risk management, and acting with integrity to compliance and ethics. OCEG's capability model organizes the work into four components, Learn, Align, Perform and Review, each broken into elements and practices.

The IIA Three Lines Model

The Institute of Internal Auditors' Three Lines Model (July 2020), an update of the earlier Three Lines of Defense model, describes how roles are divided in governance and risk management. It rests on six principles and identifies four sets of roles:

RoleResponsibility under the model
Governing bodyAccountable to stakeholders for oversight; ensures appropriate structures and processes are in place and that objectives align with stakeholder interests.
First line roles (management)Deliver products and services and own the management of the risks in that work, including operating controls.
Second line roles (management)Provide expertise, support, monitoring and challenge on risk matters, for example risk management and compliance functions.
Third line (internal audit)Provides independent and objective assurance and advice on the adequacy and effectiveness of governance and risk management, reporting to the governing body.

The model also recognizes external assurance providers, such as external auditors and regulators, outside the organization. In GRC programs the model supplies the answer to who owns each record: the first line owns risks and controls, the second line sets frameworks and monitors, and the third line tests independently.

The COSO frameworks

The Committee of Sponsoring Organizations of the Treadway Commission (COSO) publishes two widely used frameworks for structuring the risk and control content of a GRC program.

Other frameworks fill the same structure in specific domains, such as ISO 31000 for risk management, ISO 37301 for compliance management systems, and the NIST Cybersecurity Framework for cybersecurity risk.

The components of a GRC program

Descriptions vary, but a GRC program usually includes the following elements.

In U.S. financial services, many of these elements appear in regulatory form as the components of a compliance management system, which examiners assess.

What GRC software holds

GRC software is a category of systems that record and connect the work above. The products differ widely in scope, but most hold some combination of the following records and the links between them:

RecordContents
Policies and proceduresApproved documents with owners, versions, review dates and attestations.
Risk registerIdentified risks with inherent and residual ratings, owners and treatment decisions.
Control libraryControls with descriptions, owners, frequency and mappings to risks and requirements.
Regulatory inventoryApplicable laws, rules and standards, linked to business lines, policies and controls.
Issues and actionsFindings, exceptions and remediation plans with owners and due dates.
EvidenceTest results and artifacts showing that controls operated.
ReportingDashboards and reports for management, committees and the board.

Some products add third-party risk management, audit management, incident management or regulatory change feeds. Organizations with small programs often keep the same records in spreadsheets and document repositories; the records matter more than the tool.

Limits of GRC

A GRC program records and coordinates judgments; it does not make them. A risk register is only as accurate as the assessments entered into it, and a control marked effective in a system is only as reliable as the testing behind the mark. Frameworks describe what good governance and control look like, but they do not decide which risks an organization should accept. Recognized limits include:

Primary sources

Common questions

What does GRC stand for?
GRC stands for governance, risk and compliance: the coordinated management of an organization's governance structures, its risks, and its conformance with laws, regulations, contracts and internal policies.
What is OCEG's definition of GRC?
OCEG defines GRC as the capability, or integrated collection of capabilities, that enables an organization to reliably achieve objectives, address uncertainty, and act with integrity. It calls the result principled performance.
What is the Three Lines Model?
The Three Lines Model, published by the Institute of Internal Auditors in July 2020, describes roles in governance and risk management: the governing body, management in first and second line roles, and internal audit as the independent third line.
How many principles are in the COSO frameworks?
COSO's Internal Control: Integrated Framework (2013) has five components and 17 principles. COSO's Enterprise Risk Management: Integrating with Strategy and Performance (2017) has five components and 20 principles.
What does GRC software do?
GRC software records and links the elements of a GRC program: policies, the risk register, the control library, the regulatory inventory, issues and remediation, evidence of control operation, and reporting to management and the board.
About this library

This reference library is maintained by Rupture Labs. We perform BSA/AML independent testing and automated control testing against every record, with each requirement cited to its rule. Talk to a practitioner.