Governance Risk Management And Compliance (GRC)
Governance risk management and compliance GRC puts three distinct disciplines under one heading, and the bundling causes confusion about who does what.
Governance is about authority. Who decides, who oversees, who is accountable when something fails.
Risk management is forward looking. What could go wrong, how likely, how bad, and what reduces it.
Compliance is obligation based. What rules apply, and can we show we met them.
They overlap but they answer different questions, and they often report to different people. An organisation can be fully compliant and badly governed. It can manage risk well and have no compliance register worth the name.
Buying one system that covers all three is sensible. Assuming one person can hold all three disciplines is usually not, and it is a common way to lose good people.
ASIC publishes governance guidance. This is general information rather than legal advice, and obligations vary by state and territory.
See Sentrient’s GRC system and risk management system.
What Is GRC? Governance, Risk and Compliance Explained
Quick Answer: What is GRC? GRC stands for governance, risk and compliance. Governance decides who is accountable and how decisions are made. Risk management identifies and controls what could go wrong. Compliance meets legal and regulatory obligations and keeps the evidence. Run together as one discipline off one set of records, they stop each pillar […]
