Governance, Risk, and Compliance (GRC)
Definition
An integrated discipline that combines governance structures, risk management processes, and compliance monitoring into a unified programme. GRC platforms and frameworks allow organisations to manage policy obligations, risk registers, and audit findings in a single view.
- Scope
- Governance, risk management, and compliance monitoring in one programme
- Typical tools
- GRC platforms (e.g. ServiceNow GRC, RSA Archer)
- Core artefacts
- Policy library, risk register, audit findings log
- Adjacent field
- Digital forensics and incident response feed GRC risk registers
Common questions
How does GRC differ from a standalone risk register?+
A risk register lists and scores risks in isolation. GRC ties that register to the governance policies that set risk appetite and to the compliance controls that are supposed to mitigate each risk, so a gap in one area is visible against the other two.
Where does forensic evidence fit into a GRC programme?+
Incident response and digital forensics findings feed the risk register as evidence of realised threats, and audit findings from compliance checks often trigger the forensic investigations that populate it in the first place.
Related terms
- CISO (Chief Information Security Officer)
- The senior executive responsible for developing and maintaining the information security programme. The CISO reports to the board or a board committee...
- Policy Hierarchy
- The layered document set that translates governance intent into operational requirements. Tiers typically run: information security policy, topic-specific policies, standards, procedures, and...
- Risk Appetite
- The amount and type of risk an organisation is willing to accept in pursuit of its objectives, as defined by its governing...
- Security Governance
- The set of structures, roles, policies, and accountability mechanisms by which an organisation directs, controls, and monitors its information security activities. Governance...
- Three Lines of Defence
- A governance model that separates security responsibility into three distinct layers: operational management that owns controls (first line), risk and compliance functions...