Governance, risk and compliance (GRC) is the coordinated management of an organization's governance, its risks and its obligations to comply with laws, regulations and its own policies. OCEG, the body that developed the term, defines GRC as the capability, or integrated collection of capabilities, that enables an organization to reliably achieve objectives, address uncertainty and act with integrity. GRC draws on established frameworks, notably the IIA's Three Lines Model and COSO's internal control and enterprise risk management frameworks. GRC software is the category of systems used to hold the records of that work: policies, risks, controls, issues, the regulatory inventory, evidence and reports.
Governance, risk and compliance (GRC) is the integrated management of three related functions: governance, the structures and processes by which an organization is directed and held accountable; risk management, the identification, assessment and treatment of uncertainty affecting its objectives; and compliance, conformance with laws, regulations, contracts and the organization's own policies. The term also names a category of software used to support that work.
The premise of GRC is that the three functions share information. A risk assessment identifies which controls matter; controls are how compliance obligations are met; governance bodies set risk appetite and receive reporting on all three. Managed separately, the same control may be documented three times and tested three times, and a failure seen by one function may not reach the others.
The OCEG definition and principled performance
OCEG (originally the Open Compliance and Ethics Group) developed the GRC concept in the early 2000s and maintains the GRC Capability Model, known as the Red Book. OCEG defines GRC as "the capability, or integrated collection of capabilities, that enables an organization to reliably achieve objectives, address uncertainty, and act with integrity." It calls the outcome of that capability principled performance, which it describes as achieved when an organization reliably achieves objectives, addresses uncertainty and acts with integrity.
The definition treats GRC as an organizational capability, not a department or a product. The three elements map onto the three words: achieving objectives corresponds to governance, addressing uncertainty to risk management, and acting with integrity to compliance and ethics. OCEG's capability model organizes the work into four components, Learn, Align, Perform and Review, each broken into elements and practices.
The IIA Three Lines Model
The Institute of Internal Auditors' Three Lines Model (July 2020), an update of the earlier Three Lines of Defense model, describes how roles are divided in governance and risk management. It rests on six principles and identifies four sets of roles:
| Role | Responsibility under the model |
|---|---|
| Governing body | Accountable to stakeholders for oversight; ensures appropriate structures and processes are in place and that objectives align with stakeholder interests. |
| First line roles (management) | Deliver products and services and own the management of the risks in that work, including operating controls. |
| Second line roles (management) | Provide expertise, support, monitoring and challenge on risk matters, for example risk management and compliance functions. |
| Third line (internal audit) | Provides independent and objective assurance and advice on the adequacy and effectiveness of governance and risk management, reporting to the governing body. |
The model also recognizes external assurance providers, such as external auditors and regulators, outside the organization. In GRC programs the model supplies the answer to who owns each record: the first line owns risks and controls, the second line sets frameworks and monitors, and the third line tests independently.
The COSO frameworks
The Committee of Sponsoring Organizations of the Treadway Commission (COSO) publishes two widely used frameworks for structuring the risk and control content of a GRC program.
- Internal Control: Integrated Framework (2013). Defines internal control in relation to operations, reporting and compliance objectives, and organizes it into five components (control environment, risk assessment, control activities, information and communication, and monitoring activities) supported by 17 principles. The SEC's rules on management's report on internal control over financial reporting require a suitable, recognized control framework and identify the COSO framework as one that meets that requirement (SEC Release No. 33-8238, 2003); the framework's compliance objective also makes it relevant to regulatory compliance programs.
- Enterprise Risk Management: Integrating with Strategy and Performance (2017). Organizes enterprise risk management into five components (governance and culture; strategy and objective-setting; performance; review and revision; and information, communication and reporting) and 20 principles, and ties risk to strategy and performance rather than treating it as a separate list.
Other frameworks fill the same structure in specific domains, such as ISO 31000 for risk management, ISO 37301 for compliance management systems, and the NIST Cybersecurity Framework for cybersecurity risk.
The components of a GRC program
Descriptions vary, but a GRC program usually includes the following elements.
- Governance: board and committee oversight, risk appetite, roles and accountabilities, and the policy framework.
- Risk management: risk identification and assessment, a risk register, risk treatment, and key risk indicators.
- Compliance management: a regulatory inventory of applicable requirements, regulatory change management, compliance monitoring and testing, and training.
- Internal control: a control library mapped to risks and requirements, with control testing.
- Issue management: recording findings from testing, audits and examinations, with owners, remediation plans and closure.
- Assurance and reporting: internal audit, reporting to management and the board, and support for external audits and examinations.
In U.S. financial services, many of these elements appear in regulatory form as the components of a compliance management system, which examiners assess.
What GRC software holds
GRC software is a category of systems that record and connect the work above. The products differ widely in scope, but most hold some combination of the following records and the links between them:
| Record | Contents |
|---|---|
| Policies and procedures | Approved documents with owners, versions, review dates and attestations. |
| Risk register | Identified risks with inherent and residual ratings, owners and treatment decisions. |
| Control library | Controls with descriptions, owners, frequency and mappings to risks and requirements. |
| Regulatory inventory | Applicable laws, rules and standards, linked to business lines, policies and controls. |
| Issues and actions | Findings, exceptions and remediation plans with owners and due dates. |
| Evidence | Test results and artifacts showing that controls operated. |
| Reporting | Dashboards and reports for management, committees and the board. |
Some products add third-party risk management, audit management, incident management or regulatory change feeds. Organizations with small programs often keep the same records in spreadsheets and document repositories; the records matter more than the tool.
Limits of GRC
A GRC program records and coordinates judgments; it does not make them. A risk register is only as accurate as the assessments entered into it, and a control marked effective in a system is only as reliable as the testing behind the mark. Frameworks describe what good governance and control look like, but they do not decide which risks an organization should accept. Recognized limits include:
- Documentation without operation. Policies and controls can be complete on paper while practice differs.
- Stale content. Registers and inventories lose accuracy if they are not maintained as the business and the rules change.
- Mapping error. Links between controls, risks and requirements are themselves judgments and can be wrong.
- Inherent limits of internal control. COSO notes that internal control provides reasonable, not absolute, assurance, because of human judgment, breakdowns, management override and collusion.
Primary sources
- OCEG, What is GRC: OCEG's definition of GRC and of principled performance.
- OCEG, GRC Capability Model 3.5 (Red Book): The Learn, Align, Perform and Review components of a GRC capability.
- The IIA's Three Lines Model: An Update of the Three Lines of Defense (July 2020): The six principles and the roles of the governing body, management and internal audit.
- COSO, Internal Control: Integrated Framework (2013): Five components and 17 principles of internal control.
- SEC, Management's Report on Internal Control Over Financial Reporting, Release No. 33-8238 (2003): Requires a suitable, recognized control framework and identifies COSO as one.
- COSO, Enterprise Risk Management: Integrating with Strategy and Performance (2017): Five components and 20 principles of enterprise risk management.