Home / Insights / Glossary / Governance, risk and compliance (GRC)

Glossary

Governance, risk and compliance (GRC)

The combined discipline of directing an organisation, managing what could go wrong, and evidencing obligations.

What it means

GRC groups three functions that most organisations run separately: governance, meaning who decides what and on what authority; risk management, meaning identifying and treating what could go wrong; and compliance, meaning evidencing that obligations have been met.

The term is also a software category. A GRC platform typically holds a risk register, a control library, assessment workflows and reporting. The category is broad enough that two products both calling themselves GRC can solve almost unrelated problems, which is why the useful question is rarely “do we need GRC” but “which part of this is actually failing”.

Where MyRISK fits

What we do about it

MyRISK Core is a GRC product, and we say so plainly rather than inventing a category. What distinguishes it is reuse: controls and evidence are held once and drawn on by many requests, instead of each reporting, audit or supplier question being answered from scratch. Where the failing part is a decision that has to be explained later, that is Trace rather than Core; where it is follow-through on actions, that is Essentials.

MyRISK Core

Is this the thing you are actually trying to fix?

A definition rarely settles it. Tell us what happened — the request, the finding, the challenge or the incident — and we will say where to start, or that it isn't us.