Governance, Risk, and Compliance (GRC)
Governance, Risk, and Compliance (GRC) is an organizational approach that brings together three related activities: setting direction and oversight (governance), identifying and managing threats to objectives (risk), and meeting applicable rules and obligations (compliance). It is generally used to align an organization's activities—particularly its IT activities—with its business goals while managing risk and adhering to relevant requirements. GRC describes a way of working and coordinating these functions, rather than a specific law that organizations must follow.
GRC is an integrated operational strategy and set of capabilities intended to coordinate governance, risk management, and regulatory compliance so that an organization can reliably achieve its objectives while aligning IT and other activities to business goals. As characterized in the evidence, it is variously described as an operational strategy, a structured or integrated framework, and a holistic approach adopted by companies, governments, and other entities to manage the interdependencies among oversight, risk, and adherence to obligations. GRC should be understood as a voluntary management approach and coordinating discipline rather than a binding legal regime; it may incorporate obligations arising from applicable laws, standards, or contracts, but GRC itself is not a regulation or a certification scheme. The specific scope, capabilities, and maturity of a GRC program are fact-specific and vary by organization, sector, and jurisdiction, and readers should verify definitions and expectations against current authoritative sources, as interpretations and supporting frameworks evolve over time.
Why it matters
Organizations rarely manage governance, risk, and compliance as isolated activities without cost. When oversight, risk management, and compliance functions operate in silos, the same control may be documented multiple times, risk assessments may not inform compliance priorities, and leadership may lack a coherent view of whether the organization is meeting its obligations. GRC matters because it offers a coordinating discipline intended to reduce this fragmentation—aligning IT and other activities with business objectives while managing risk and adhering to applicable requirements, as described across the evidence.
For compliance officers, auditors, and information security professionals, the practical value of GRC lies in integration. A GRC approach seeks to connect the direction set by governance, the threats identified through risk management, and the obligations tracked through compliance so that decisions in one area reflect information from the others. The evidence characterizes this variously as an operational strategy, a structured or integrated framework, and a holistic approach adopted by companies, governments, and other entities. It is worth stressing what GRC is not: it is not a law, a regulation, or a certification scheme. It is a way of working that may incorporate obligations arising from applicable laws, voluntary standards, or contracts, but does not itself impose binding legal requirements.
Because GRC is a management approach rather than a defined legal regime, its scope and rigor vary considerably by organization, sector, and jurisdiction. The maturity of a given GRC program depends on organizational choices, and the term should not be read to imply any fixed set of controls or guaranteed outcomes. Readers evaluating GRC claims—whether from vendors, internal stakeholders, or third parties—should look closely at what capabilities are actually in scope rather than assuming a standard meaning.
Who it's relevant to
Inside GRC
Common questions
Answers to the questions practitioners most commonly ask about GRC.
