Governance, risk management and compliance (GRC) — is it a platform, a process, or a technology? What is within the scope of GRC and how should your organization approach it? In this article, we go back to the basics and review what GRC is, who is involved and why it is mission critical to your business.
The scope of GRC
GRC isn’t just the computer software you use to manage it — it’s a set of
capabilities that enable your organization to achieve its objectives, address uncertainties and operate with integrity. Processes and practices that run across all departments and functions of your business to help achieve
Principled Performance are all an integrated part of GRC.
Today, the scope of GRC extends beyond your traditional financial or legal compliance to include components like performance management, sustainability, quality assurance, and even
practices such as information security management, ethics management and business continuity planning. To gain a better understanding, imagine how the components in this diagram are integrated into each department or function of your business.