Book

What Is GRC (Governance, Risk, and Compliance)?

by OCEG (Open Compliance and Ethics Group) · 2002 · 1 reading card

1 card

  1. What Is GRC (Governance, Risk, and Compliance)? · 2002

    GRC is not a department but the property of not having three different truths about the same control.

    The acronym was coined by OCEG in 2002, and its definition is less bureaucratic than it sounds: the integrated collection of capabilities that let an organisation reliably achieve objectives, address uncertainty and act with integrity. The load-bearing word is integrated. Governance sets direction and accountability, risk management says what can break that direction, compliance says what is mandatory along the way. Kept apart, they trip over each other: the same controls get inventoried three times, the same evidence is requested by three teams, and the board receives three dashboards that disagree. That is why GRC cannot be bought as a department or as a tool. It shows up in artefacts: one risk register, one set of controls with named owners, one list of legal obligations linked to those controls, and one report to the board. Everything else is a label stuck over the same three silos.

    GRC (Governance, Risk, and Compliance) is the integrated collection of capabilities that enable an organization to reliably achieve objectives, address uncertainty, and act with integrity — to achieve Principled Performance.

    Open the card