GRC
GRC stands for Governance, Risk, and Compliance — an integrated approach to aligning an organization's strategy, risk management, and adherence to regulations and standards.
Governance, Risk, and Compliance (GRC) describes the coordinated set of capabilities an organization uses to operate reliably, manage uncertainty, and act with integrity. Governance defines direction and accountability, risk management identifies and treats threats to objectives, and compliance ensures adherence to laws, regulations, and internal policies.
Treating these disciplines together avoids the silos that arise when security, legal, and audit teams maintain separate, duplicated processes. A unified GRC program shares a common control library, risk register, and evidence base across frameworks.
Modern GRC platforms automate much of this work — continuously collecting evidence, mapping controls across frameworks, and surfacing risks — so teams can spend less time on manual coordination and more on decisions.
Related terms
- Risk RegisterA risk register is a centralized record of an organization's identified risks, capturing their likelihood, impact, ownership, and treatment status.
- Control MappingControl mapping is the practice of linking a single control to the multiple framework requirements it satisfies, so that one piece of evidence can support several frameworks at once.
- Continuous ComplianceContinuous compliance is the practice of monitoring controls and collecting evidence on an ongoing basis, so an organization remains audit-ready at all times rather than only before an audit.
- AI ComplianceAI compliance is the practice of ensuring artificial-intelligence systems meet applicable legal, regulatory, and ethical requirements throughout their lifecycle.