What is GRC? Governance, risk and compliance
A simple definition, the three pillars, frameworks, roles, maturity levels and criteria for choosing a cybersecurity GRC tool.
GRC (governance, risk and compliance) is the approach that links three activities often carried out separately: setting rules and responsibilities, identifying and treating risks, and demonstrating that requirements are met. In cybersecurity, it lets the CISO and management steer security with shared, up-to-date information rather than scattered files. Here is what GRC covers, where it comes from, which frameworks it relies on and how to choose a GRC tool.
What is GRC? A simple definition
GRC in one sentence
GRC describes how an organisation directs itself (governance), anticipates what could stop it from reaching its objectives (risk) and follows the rules that apply to it (compliance), treating these three topics as a whole. The starting idea is simple: a management decision, a risk assessment and a compliance audit often concern the same asset, the same control or the same supplier. Running each in its own corner produces duplicates, blind spots and contradictory dashboards.
Where does the term GRC come from?
The term was popularised in the early 2000s by OCEG (Open Compliance and Ethics Group), a US professional association that says it formalised the concept in 2002. OCEG defines GRC as the integrated collection of capabilities that enable an organisation to "reliably achieve objectives, address uncertainty, and act with integrity". This definition has one merit: it reminds us that GRC serves the organisation's performance first, not just control.
The three pillars of GRC: governance, risk, compliance
Governance: who decides, under which rules
Governance sets the course. It defines security objectives, roles and responsibilities, decision bodies (security committee, risk committee) and the rules of the game, starting with the information security policy. It also sets the risk appetite: the level of risk management is willing to take to reach its objectives. The guide on controlling digital risk published by ANSSI (France's national cybersecurity agency) and AMRAE (the French association of risk managers) puts it plainly: digital risk must be handled at the highest level of the organisation.
Risk management: prioritising what matters
Risk management identifies what could harm the organisation's activities, estimates severity and likelihood, then decides on treatment: reduce, transfer, avoid or accept. In cybersecurity, it relies on a recognised method such as EBIOS Risk Manager, published by ANSSI, or ISO/IEC 27005. This is what turns a list of requirements into priorities: not all controls are equal, and risk analysis tells you which ones matter most to you.
Compliance: demonstrating that rules are applied
Compliance checks that the organisation meets the requirements that apply to it: laws and regulations (NIS 2, DORA, GDPR), standards it commits to (ISO 27001), contracts and internal rules. It is not just about ticking boxes: it must produce evidence, measure gaps and follow corrective actions through to closure.
Taken in isolation, each pillar works poorly. Governance without risk analysis decides blindly; risk analysis without compliance tracking remains a document; compliance without governance becomes a race from one audit to the next. GRC is a loop:
- Governance → Risk Management sets the objectives, the risk appetite and the responsibilities, so the risk assessment knows what it must protect and how far to go.
- Risk → Compliance Risks judged unacceptable become measures to apply, added to the requirements of standards and the law.
- Compliance → Governance Assessments measure the gaps and produce indicators: management arbitrates, adjusts course, and the loop starts again.
Enterprise GRC and cybersecurity GRC: what is the difference?
GRC was born in finance and audit, where it covers all of a company's risks: financial, legal, operational, reputational. This is enterprise GRC, often run by the risk or internal control function, with frameworks such as ISO 31000 for risk management or ISO 37301 for compliance management systems.
Cybersecurity GRC (or IT GRC) applies the same logic to information security. It is usually led by the CISO, and its objects are more concrete: information systems, data, suppliers, security controls.
| Enterprise GRC | Cybersecurity GRC | |
|---|---|---|
| Scope | All of the company's risks | Information and systems security |
| Lead | Risk, internal control, compliance | CISO, with IT, the DPO and business units |
| Frameworks | ISO 31000, ISO 37301, COSO | ISO 27001/27002, ISO 27005, EBIOS RM, NIST CSF, NIS 2, DORA, GDPR |
| Outputs | Risk map, internal control plan | Risk assessments, security policy, compliance assessments, action plans, security accreditations |
The two meet: cyber risk is part of the company's risk map, and the CISO must be able to translate scenarios into the risk manager's language (financial impact, business impact). That is precisely what the ANSSI and AMRAE guide sets out to do.
Cyber GRC frameworks: ISO 27001, NIS 2, DORA, GDPR…
A cybersecurity GRC approach relies on frameworks of different kinds: some are laws, others voluntary standards, others methods. Knowing them avoids treating them as separate projects, when they often require the same controls.
| Framework | Type | What it brings to GRC |
|---|---|---|
| ISO/IEC 27001:2022 | Voluntary, certifiable standard | The requirements of an ISMS: the security management framework |
| ISO/IEC 27002:2022 | Code of practice | Details of the 93 reference security controls |
| ISO/IEC 27005 and EBIOS RM | Risk assessment methods | How to assess and treat risks |
| NIS 2 Directive | EU Directive 2022/2555 | Risk management measures and reporting obligations for essential and important entities |
| DORA Regulation | EU Regulation 2022/2554, applicable since 17 January 2025 | Digital operational resilience in the financial sector, including ICT third-party risk |
| GDPR | EU Regulation 2016/679 | Personal data protection and the duty to demonstrate compliance |
| NIST CSF 2.0 | Voluntary US framework | A "Govern" function dedicated to governance, added in 2024 |
| Security policy | Internal rule | The organisation's own requirements |
NIS 2 shows why GRC is becoming essential. The directive requires management bodies to approve cybersecurity risk management measures and to follow training, and provides for their liability in case of failure (Article 20). In France, its transposition was still before Parliament in autumn 2026, while ANSSI is already supporting the entities concerned. For more detail, read our article From NIS to NIS 2, and see how to track these requirements with compliance campaigns and a framework and policy editor.
Who does GRC? The key roles
GRC is not one person's job. It shares responsibilities between several players:
- Executive management sets the risk appetite, arbitrates budgets and, under NIS 2 and DORA, bears direct responsibility.
- The CISO organises security governance, runs risk assessments, writes the security policy and tracks compliance. In many SMEs and mid-sized companies, the CISO is the de facto GRC manager.
- The risk manager integrates cyber risk into the company's risk map and translates it into financial and business impacts.
- The DPO (data protection officer) oversees GDPR compliance and advises on data protection impact assessments (DPIA).
- The compliance officer tracks regulatory obligations, especially in regulated sectors (banking, insurance, healthcare).
- Internal audit independently checks that the system works.
- Business units know the value of their activities and data: without them, risk analysis remains theoretical.
To organise these roles, many organisations use the Three Lines Model of the Institute of Internal Auditors (IIA), updated in 2020: operational teams manage risk day to day (first line), risk, compliance and security functions provide expertise and challenge (second line), and internal audit provides independent assurance (third line). The CISO usually sits in the second line.
Why set up a GRC approach? The benefits
- Assess once, serve several frameworks. The same control (access management, backups, logging) meets ISO 27001, NIS 2, DORA and your security policy. Once linked, these frameworks no longer require four assessments.
- Prioritise investment. Risk analysis shows where each euro reduces risk most, instead of funding the most visible control.
- Give management a clear view. Risk level, compliance rate, action plan progress: indicators calculated from the same data.
- Prepare audits calmly. Evidence is attached to requirements as you go, not gathered the night before the audit.
- Control the supply chain. Suppliers are assessed against the same requirements as internal teams: this is third-party risk management.
- Earn the trust of customers and partners. An organisation that can demonstrate control of its risks answers security questionnaires and tenders faster.
Setting up a GRC approach, step by step
There is no single recipe, but approaches that work often follow the same order:
- Get a mandate from management: a sponsor, a scope, resources.
- List the applicable requirements: laws, standards, contracts, internal rules.
- Define roles and decision bodies (security committee, reviews).
- Choose a risk assessment method and apply it first to the most critical scope.
- Assess compliance gaps and attach existing evidence.
- Build a single action plan, fed by risks and gaps, with owners and deadlines.
- Measure and report at regular intervals, then start again.
Before choosing a tool, it helps to know where you start from. Maturity models, such as OCEG's or the staged grids used by consultancies, generally distinguish a reactive organisation from one that steers its risks with indicators. Find out where you stand in five questions:
- 01 · Governance Who makes decisions about information security?
- 02 · Risk How are your cyber risks assessed?
- 03 · Compliance Do you know where you stand against your frameworks?
- 04 · Third parties How do you assess your suppliers?
- 05 · Steering Where does your governance, risk and compliance data live?
0 of 5 answered
- Initial : Security is handled as it comes, driven by incidents and requests. Priority: lay the foundations of governance.
- Structured : The building blocks exist but live apart. Priority: link risk assessments to requirements and actions.
- Integrated : Governance, risk and compliance respond to each other. Priority: measure over time and extend the approach to third parties.
- Managed : GRC informs management decisions. Priority: keep the loop alive and track changes in threats and regulations.
How to choose a GRC tool or GRC software
Many organisations start their GRC in spreadsheets. That works while the scope is small; beyond that, the links between risks, requirements and actions break with every update, and preparing an audit becomes a consolidation project. GRC software then takes over. Here are the criteria that really matter; our GRC tools comparison guide covers them in depth with an interactive scoring grid:
Functional coverage
- Risk assessment using a recognised method: in France, an EBIOS RM module labelled by ANSSI guarantees fidelity to the method.
- A catalogue of frameworks (ISO 27001/27002, NIS 2, DORA, GDPR…) and the ability to add your own security policy.
- Mappings between frameworks, so the same control is not assessed twice.
- Compliance assessments with evidence, and access for auditors.
- Action plans with owners, deadlines and reminders.
- Third-party risk: questionnaires and supplier follow-up.
Fit and adoption
- Does the tool adapt to your methods, scales and risk libraries, or do you have to change everything?
- Can business contributors take part without heavy training?
- Can you import the history of your existing files?
- Can you start with one module and extend later?
Sovereignty and security requirements
- Where is the data hosted (your risk assessments are sensitive)? Is a SecNumCloud-qualified cloud option or an on-premise installation available?
- Are single sign-on (SAML, OAuth) and fine-grained role management supported?
As an example, Phinasoft is a French GRC platform dedicated to cybersecurity, with five modules sharing the same data: risk analysis (including an EBIOS RM module labelled by ANSSI, and ISO 27005), frameworks and security policies, compliance campaigns, vendor risk management and GDPR compliance. It can be hosted as European SaaS, in a French sovereign cloud with a SecNumCloud option, or on premise. The simplest way to judge a tool is still to see it on your own cases: that is what a demo is for.
Common mistakes in a GRC approach
- Buying a tool before having an approach. GRC software equips roles and a method; it does not replace them.
- Reducing GRC to compliance. An organisation can tick every box of a framework and still leave its main risk untouched. Compliance says "what is required", risk says "what matters".
- Trying to cover everything from day one. A first critical scope done well beats superficial total coverage.
- Forgetting the business. A risk assessment written by the security team alone misses the real value of activities.
- Letting the loop stop. A risk assessment never reassessed, an action plan never reread: GRC becomes a paperwork exercise.
- Neglecting third parties. A large part of the attack surface runs through suppliers and digital service providers.
Summary
Three linked activities
GRC links governance, risk management and compliance so that decisions, priorities and evidence all rely on the same information.
An approach before a tool
Clear roles, a risk assessment method, a list of applicable frameworks: the GRC tool then makes the approach sustainable and measurable.
A loop that must keep turning
GRC is only useful if it stays alive: risks reassessed, compliance measured, gaps reported to management, and decisions that take them into account.
Frequently asked questions
What does GRC stand for?
GRC stands for governance, risk and compliance. It is an approach that links setting rules and responsibilities, assessing and treating risks, and checking that legal, normative and internal requirements are met. In cybersecurity, it gives the CISO and management a shared, up-to-date view of security.
What is the difference between GRC and an ISMS?
An ISMS (information security management system) is the system defined by ISO/IEC 27001 to manage information security. GRC is broader: it also covers other frameworks (NIS 2, DORA, GDPR), third-party risk and overall governance. An ISMS is often the backbone of a cyber GRC approach.
What is a GRC tool?
A GRC tool or platform centralises requirement frameworks, risk assessments, compliance assessments, evidence and action plans. Its value lies in linking these elements, so that the risk level and the compliance rate are calculated from up-to-date data rather than by consolidating spreadsheets.
Is GRC mandatory?
The term GRC does not appear in any law. Its components, however, are increasingly required: NIS 2 and DORA impose governance involving management, risk management and security measures; the GDPR requires organisations to demonstrate compliance. A GRC approach is the simplest way to meet these demands in a coordinated way.
What does a GRC manager or consultant do?
A GRC manager organises security governance, runs or coordinates risk assessments, tracks compliance with frameworks, prepares audits and produces indicators for management. Depending on the size of the organisation, the role is held by the CISO, a dedicated team or an external consultant.
Which frameworks are used in cybersecurity GRC?
The most common in Europe are ISO/IEC 27001 and 27002 for the ISMS, ISO/IEC 27005 and EBIOS Risk Manager for risk assessment, the NIS 2 Directive, the DORA Regulation for the financial sector, the GDPR, the NIST Cybersecurity Framework, and each organisation's own security policy.
Sources (12)
- OCEG — What is GRC?
- ISO — ISO/IEC 27001:2022, Information security management systems
- ISO — ISO 31000:2018, Risk management — Guidelines
- ISO — ISO 37301:2021, Compliance management systems
- NIST — The NIST Cybersecurity Framework (CSF) 2.0
- The IIA — The IIA's Three Lines Model (2020)
- ANSSI et AMRAE — Maîtrise du risque numérique : l'atout confiance
- ANSSI — La directive NIS 2
- ANSSI — La méthode EBIOS Risk Manager
- EUR-Lex — Directive (EU) 2022/2555 (NIS 2)
- EUR-Lex — Regulation (EU) 2022/2554 (DORA)
- EUR-Lex — Regulation (EU) 2016/679 (GDPR)
A platform and service that adapt to you
Our platform is designed for fine-tuned configuration and broad adaptability to your needs.