GlossaryCompliance operations

GRC

Short answer

GRC (Governance, Risk and Compliance) is the integrated way an organisation sets security direction and responsibilities, manages its risks and meets the laws, standards and contracts that apply to it. In security, it covers frameworks such as ISO 27001, ENS, NIS2, DORA and SOC 2.

The three parts

Governance defines who is accountable for security, which policies apply and how management oversees them. Risk management identifies and treats the threats that matter to the business, starting from a risk assessment. Compliance shows that the organisation meets its obligations, from regulations like NIS2 to certifications like ISO 27001 and customer requirements.

Why integrate them

Run separately, each framework becomes its own project with its own spreadsheets, evidence and audits. Treating GRC as one programme lets a company map a single control to several frameworks, collect evidence once and avoid duplicated work, as explained in running ISO 27001 and ENS as a single programme.

GRC platforms

GRC and compliance automation platforms help manage policies, controls, evidence and audits. They organise the work but do not secure systems by themselves: someone still has to operate the controls and check that they work. See what a compliance platform does not cover.

Common pitfalls

The most frequent problem is compliance on paper: policies and evidence that look complete but do not match how the company really operates. Auditors increasingly test whether controls are operated, not just documented.

Related terms

Keep reading on this topic

Running security as a repeatable process: policy management, risk registers, evidence upkeep, supplier assessment and audit readiness between cycles.

Go to the topic hub