Definition Of Governance Risk And Compliance
The acronym grc was invented by the oceg originally called the open compliance and ethics group membership as a shorthand reference to the critical capabilities that must work together to achieve principled.
Definition of governance risk and compliance. Governance risk management and compliance grc is the term covering an organization s approach across these three practices. The first scholarly research on grc was published in 2007 where grc was formally defined as the integrated collection of capabilities that enable an organization to reliably achieve objectives address uncertainty and act. By definition the scope of grc doesn t end with just governance risk and compliance management but also includes assurance and performance management. Grc aids an organization in achieving its goals through coordinating strategies around corporate governance enterprise risk management erm and compliance with any.
Compliance a company s conformance with regulatory requirements for business operations data retention and other business. Governance risk and compliance grc is a combined area of focus developed to cover an organization s strategy to handle any interdependencies between the three components. Governance risk management and compliance grc is a corporate management system that focuses on integrating these three key elements across all departments. In practice however the scope of a grc framework is further getting extended to information security management quality management ethics and values management and business continuity.
Grc as an acronym denotes governance risk and compliance but the full story of grc is so much more than those three words.