Glossary

GRC

GRC stands for Governance, Risk, and Compliance — an integrated approach to aligning an organization's strategy, risk management, and adherence to regulations and standards.

Governance, Risk, and Compliance (GRC) describes the coordinated set of capabilities an organization uses to operate reliably, manage uncertainty, and act with integrity. Governance defines direction and accountability, risk management identifies and treats threats to objectives, and compliance ensures adherence to laws, regulations, and internal policies.

Treating these disciplines together avoids the silos that arise when security, legal, and audit teams maintain separate, duplicated processes. A unified GRC program shares a common control library, risk register, and evidence base across frameworks.

Modern GRC platforms automate much of this work — continuously collecting evidence, mapping controls across frameworks, and surfacing risks — so teams can spend less time on manual coordination and more on decisions.

Related terms