Risk Management - Concept
GRC
(Governance, Risk and Compliance)
Managing decision-making, risk and rule-following together as one coordinated discipline
What's it for?
Helps organisations manage rules, risks and evidence together instead of in separate processes.
For example…
A company uses one governance, risk and compliance process to keep track of security checks, risks and evidence needed for audits instead of maintaining separate trackers
A GRC process links a new regulation to the relevant controls, assigns evidence owners and records any remaining risks in one place
Think of it like…
The flight deck checklist: separate dials, but one disciplined sequence keeps the plane within safe limits