GRC

GRC is governance, Risk, and Compliance, an integrated approach to managing organizational governance, risk identification and treatment, and regulatory compliance.

TPRM & GRC

Why it matters

GRC programs produce the policies and controls that security answers are drawn from and define how vendor risk is governed.

Where it appears in the workflow

Provides the policy and control framework underlying questionnaire answers and TPRM assessments.

Common mistakes

  1. Treating grc as a universal term with no workflow context.