Compliance › Compliance
Digital Compliance
Modules
.legal AI
All AI features →Integrations
See all integrations →Platform & features
Understand the rules
See it in action
All customer stories →Plan your switch
Stay up to date
Governance, risk and compliance (GRC) is the ability to reach your objectives, manage uncertainty and meet your obligations. Get the definitions from OCEG, ISO and COSO, the difference between risk appetite and risk profile, and what GDPR, NIS2, DORA and the UK Code ask of the board.
GRC is one of those terms everyone in compliance uses and almost nobody defines the same way. To some it is a software category. To others it is a department, a framework or simply a new label for risk management. That ambiguity has a cost, because it hides the question that actually matters: who decides how much risk the organisation will accept, and who can prove it stays within that limit?
This article takes its definitions from the people who wrote them: OCEG, ISO, COSO and the Institute of Internal Auditors. It then shows how GDPR, NIS2, DORA and, in the UK, the Corporate Governance Code place responsibility for governance, risk and compliance directly on the board. Finally, it walks through a fictional example where one risk hits three rulebooks at once. If you are choosing a tool rather than a definition, we have a separate guide to GRC software.
Governance, risk and compliance (GRC) is an organisation's combined ability to steer towards its objectives, deal with uncertainty along the way and meet the obligations it is bound by. The most widely cited definition comes from OCEG: GRC is the capability, or integrated collection of capabilities, that enables an organisation to reliably achieve objectives, address uncertainty and act with integrity.
Each word answers a question. Governance answers who decides and who is accountable. Risk answers what could get in the way of the objectives, and how much of it you are prepared to live with. Compliance answers which obligations apply and whether you can show you meet them. GRC isn't a law, a standard or a system. It's the way the three disciplines work together. NIS2 has turned part of it into a legal duty. Once national law applies, management bodies in covered entities must approve and oversee cybersecurity risk management.
Searches for "what is GRC" tend to mix terms from different categories. A standard, a law and a role model get mentioned in the same breath, as if one could replace another. They can't. The table below sorts the most common terms so you can see what is voluntary, what is mandatory and what you can be certified against.
| Term | What it is | Certifiable? |
|---|---|---|
| GRC | An approach and an integrated capability, defined by OCEG | No. OCEG certifies individuals, not organisations |
| ISO 37000:2021 | Guidance on the governance of organisations, 11 principles | No, guidance standard |
| ISO 31000:2018 | Risk management guidelines, 8 principles | No, guidance standard |
| COSO ERM (2017) | Enterprise risk management framework, 5 components and 20 principles | No |
| ISO 37301:2021 | Requirements for a compliance management system | Yes |
| ISO/IEC 27001:2022 | Requirements for an information security management system (ISMS) | Yes |
| Three Lines Model (IIA, 2020) | A model for roles in governance and risk management | No |
| GDPR, NIS2, DORA, UK Code | Legislation or regulatory codes with specific duties for the board | No. You comply with them |
| GRC software | A tool to document the work and follow it up | No |
The key point is that GRC has no checklist of its own. The content comes from the standards and laws that apply to you. GRC is the glue that makes sure they are handled in one place, with one method and with clear ownership.

The acronym is closely tied to the Open Compliance and Ethics Group (OCEG), a non-profit founded in 2002. OCEG says the ideas behind GRC were developed within the organisation in the early 2000s and that an expert panel later formalised the definition. The first scholarly article on the concept was published in 2007 by OCEG's founder, Scott L. Mitchell, in the International Journal of Disclosure and Governance.
OCEG's central phrase is principled performance. An organisation achieves it when it reliably achieves objectives, addresses uncertainty and acts with integrity. The wording is worth noticing because it starts with objectives. GRC isn't mainly about avoiding fines. It's about getting where the organisation wants to go without compromising on laws, values or promises. OCEG's open GRC Capability Model, known as the Red Book, describes how to do that in practice. Read OCEG's own explanation of GRC.
ISO 37000:2021, the first international standard on the governance of organisations, describes good governance as a human-based system by which an organisation is directed, overseen and held accountable for achieving its defined purpose in an ethical and responsible manner. It was published on 15 September 2021 and organises the field into 11 principles, with purpose as the first and central one. Oversight, accountability and risk governance are among the others. See ISO's announcement of ISO 37000.
Governance is increasingly codified. In the UK, the UK Corporate Governance Code 2024 applies to financial years beginning on or after 1 January 2025. Its Provision 29, which asks the board to declare whether material internal controls were effective at the balance sheet date, applies to financial years beginning on or after 1 January 2026. Across the EU, company law in each member state sets similar duties. Danish company law, for example, requires the board of a limited company to ensure adequate procedures for risk management and internal control.
In practice, governance in a GRC context comes down to four things:
ISO defines risk as the effect of uncertainty on objectives. The definition appears in ISO 31000:2018 and in the vocabulary standard ISO 31073:2022, which replaced ISO Guide 73:2009. The effect can be positive or negative. Risk management is therefore not only about avoiding losses. It's about making decisions with your eyes open.
The two leading references are ISO 31000 and COSO. ISO 31000:2018 was published on 14 February 2018 and consists of principles, a framework and a process. It is now being revised, with a committee draft (ISO/CD 31000) out for comment until 1 March 2026, so expect a new edition. COSO's Enterprise Risk Management: Integrating with Strategy and Performance, released in June 2017, has five components: governance and culture, strategy and objective-setting, performance, review and revision, and information, communication and reporting. Governance is COSO's first component. Risk management without governance is just a list.
For the method itself, our article on information security risk management shows how one approach can serve GDPR, NIS2, DORA and ISO 27001 at once.
A common mistake in GRC content is to describe the risk profile as the amount of risk the organisation is willing to accept. That's risk appetite. The risk profile describes the risks you actually have. The distinction isn't pedantry. The whole point of governance is to compare the two: if the profile sits above the appetite, someone has to act.
| Term | Meaning | Who sets it? | Example |
|---|---|---|---|
| Risk appetite | The amount and type of risk an organisation is willing to pursue or retain (ISO 31073) | The board or governing body | "We accept no high risks to patient safety." |
| Risk tolerance | The acceptable variation around a specific objective. COSO ties tolerance to objectives | Executive management, within the board's appetite | "Critical systems may be down for no more than 4 hours." |
| Risk capacity | The maximum risk the organisation can bear before it can no longer meet its objectives | Calculated, not chosen | Cash to survive a 10-day production stop |
| Risk profile | The composite view of the risks the organisation actually faces at a given level (COSO) | The output of risk assessment | "14 risks, 3 of them above appetite." |
COSO describes the risk profile as the composite view of risks related to a specific strategy or business objective at a particular level of the entity. Appetite is drawn as a line, the profile as a curve. Where the curve crosses the line, risk becomes too high. That comparison is what the board needs to see.

Compliance means meeting obligations, and in GRC the term reaches further than legislation. ISO 37301:2021 on compliance management systems talks about compliance obligations. They cover the requirements an organisation must meet and those it chooses to meet, such as customer contracts, industry codes or its own policies. A data processing agreement or a commitment in a tender is as much a compliance obligation as GDPR.
ISO 37301 was published on 13 April 2021, replaced ISO 19600:2014 and, unlike its predecessor, is a requirements standard you can be certified against. It shares its structure with ISO 27001, so anyone running an ISMS will recognise the pattern of context, leadership, planning, operation, evaluation and improvement. Like the other ISO management system standards, it received a climate action amendment in 2024.
For most organisations with 50 or more staff, the compliance portfolio is a handful of rulebooks: GDPR compliance, NIS2 if you're in scope, ISO 27001 if customers ask for it, plus contractual and sector requirements. The job is knowing which apply, who owns each one and how you evidence that it is met.
The most widely used model for how governance, risk and compliance map onto roles is the Institute of Internal Auditors' Three Lines Model. Published in July 2020, it replaced the older Three Lines of Defence. It rests on six principles and stresses that the lines are not structural elements but a useful differentiation of roles. Read the IIA's Three Lines Model.
| Role | Task in the model | Typically in a mid-sized organisation |
|---|---|---|
| Governing body | Accountable to stakeholders for oversight of the organisation | Board of directors, often the executive team in owner-managed firms |
| First line | Leads operations and owns risk in day-to-day activity | Department heads, IT operations, production, HR |
| Second line | Complementary expertise, support, monitoring and challenge | Compliance, risk management, CISO, data protection officer (DPO) |
| Third line | Independent assurance and advice, reporting to the governing body | Internal audit, often outsourced in smaller organisations |
| External | Additional assurance to satisfy legal and regulatory expectations | External auditor, certification body, supervisory authority |
The DPO sits in the second line as an adviser. Keeping the record of processing and notifying breaches are duties of the controller, not the DPO. And many organisations under 250 staff have no internal audit function at all. Then the third line has to come from an external review, or the board has to accept that independent assurance is limited.

Ten years ago you could still argue about whether GRC was good practice or consultancy jargon. Legislation has settled the argument. Several regimes now place responsibility for risk management squarely on the management body, and some let supervisors pursue individual executives.
| Regime | Provision | What the board must do | Applies to |
|---|---|---|---|
| GDPR | Art. 5(2) and Art. 24(1) | The controller must be able to demonstrate compliance and implement appropriate measures | All controllers in scope of Art. 3 |
| NIS2 | Art. 20(1) and (2) | Approve the Art. 21 measures, oversee implementation, follow training. Members can be held liable | Essential and important entities, via national law |
| NIS2 | Art. 32(5)(b) | Authorities can impose or seek a temporary ban on a CEO or legal representative exercising managerial functions | Essential entities |
| DORA | Art. 5(2)(a) | The management body bears ultimate responsibility for managing ICT risk | Financial entities, from 17 January 2025 |
| UK Corporate Governance Code 2024 | Provision 29 | Monitor the risk management and internal control framework and declare whether material controls were effective | UK listed companies (comply or explain), financial years from 1 January 2026 |
| ISO/IEC 27001:2022 | Clauses 5.1 and 9.3 | Top management must demonstrate leadership and carry out management review | Voluntary, required for certification |
NIS2 is the sharpest of these. Article 20(1) of the NIS2 Directive requires member states to ensure that management bodies approve the cybersecurity risk-management measures, oversee their implementation and can be held liable for infringements. Article 20(2) requires members of management bodies to follow training, which our article on NIS2 training requirements covers in detail. Article 34 sets fines of a maximum of at least EUR 10 million or 2 % of worldwide annual turnover for essential entities, and EUR 7 million or 1.4 % for important entities.
How this lands depends on national law. Denmark's NIS2 Act (Act no. 434 of 6 May 2025) has applied since 1 July 2025, and its section 7 copies the board duties almost word for word. Transposition has been uneven elsewhere. In July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify full transposition (IP/26/1499). The UK is outside NIS2. Its NIS Regulations 2018 remain in force, and the Cyber Security and Resilience Bill was at Report stage in the House of Lords in September 2026, according to the UK Parliament bill page. Our NIS2 introduction explains who is in scope.
For financial entities, DORA is even more explicit. Under Article 5(2), the management body must define, approve, oversee and be responsible for the implementation of all arrangements in the ICT risk management framework. GDPR says less about the board as such, but the accountability principle in Article 5(2) and the controller's responsibility in Article 24 of the GDPR require, in practice, a governance structure that can show who decided what.
Kystlab Medical A/S and its CFO Mette Holm are fictional. We invented them for this article.
Kystlab Medical A/S is a Danish manufacturer of medical devices with 240 employees. Manufacturing of medical devices is listed in Annex II of NIS2, and with more than 50 staff Kystlab is an important entity under the Danish NIS2 Act. It processes personal data about patients in complaint cases and about its own employees. A large hospital customer requires ISO 27001 certification in the contract.
Until this year, three people managed the same risk without knowing it. The IT manager had "ransomware on the production server" in the ISO 27001 risk register. The DPO had "loss of availability of complaint files" in the GDPR risk assessment. The production manager had "assembly line stopped for more than 24 hours" in the business continuity plan. Three registers, three scales, three owners and three reports to the board.
Mette Holm was asked to bring it together. First, the board adopted a one-page risk appetite:
The three risks were then merged into one risk with one owner, the production manager, and scored on one shared scale. The result was a single risk profile of 14 risks, 3 of them above appetite. Ransomware was the largest: likelihood 3 out of 5, impact 5 out of 5. The control chosen to reduce it was a tested offline backup with restore within 24 hours. That single control served three obligations:
| Obligation | Provision | What the control evidences |
|---|---|---|
| NIS2 | Art. 21(2)(c), business continuity and backup management | Backup and disaster recovery |
| GDPR | Art. 32(1)(c) | The ability to restore availability of and access to personal data in a timely manner |
| ISO/IEC 27001:2022 | Annex A 8.13 (information backup) | Backups maintained and tested in line with an agreed policy |
The board received one report instead of three. It showed that the risk was above appetite, that the control had been approved, that the first test was scheduled for November and who owned it. That is exactly what NIS2 Article 20 asks of the management body: approve the measures and oversee their implementation. Kystlab used the same scoring approach as in our guide to the risk assessment matrix, but only once.
The point isn't that one control covers everything. It doesn't. A backup won't give you a lawful basis under GDPR or meet NIS2's incident reporting deadlines. The point is that the risk only needs to be assessed, owned and reported once.
GRC rarely starts as a big-bang programme. It usually begins when someone notices the same work being done three times. These six steps give a realistic order for an organisation with 50 to 500 staff:

GRC is easy to oversell. Three caveats are worth knowing before you start.
Risk matrices have known weaknesses too, including giving the same score to very different risks. We cover them in our article on information security risk management. And certification isn't compliance. An ISO 27001 certification shows your management system works, but it doesn't discharge your NIS2 or GDPR obligations.
The practical challenge is rarely understanding GRC. It's keeping obligations, risks, controls and decisions together, so that one risk doesn't live in three spreadsheets.
In the .legal platform's Frameworks module you map one control to several rulebooks, such as GDPR, NIS2 and ISO 27001, and see where evidence is missing. Risk management uses one method across areas, and the information security module brings assets, risks and controls together for your ISMS. Policies are kept current and acknowledged in Policy Management, suppliers are handled in Vendor Management, and recurring tasks such as management review, policy review and control testing go into compliance task management.
The platform doesn't make decisions for you, and it doesn't make you compliant on its own. The board still has to set the risk appetite, and controls still have to work in practice. What the platform gives you is structure and traceability, so you can show who decided what. To see how it looks, book a demo.
GRC stands for governance, risk and compliance. It describes an organisation's combined ability to steer towards its objectives, manage uncertainty and meet the obligations it is bound by. The acronym was popularised by the Open Compliance and Ethics Group (OCEG), which frames the goal as principled performance: reliably achieving objectives while acting with integrity.
Governance is about how the organisation is directed: who makes decisions, who oversees them and who is accountable. Compliance is about whether the organisation meets its obligations, including laws and voluntary commitments such as contracts and internal policies. Governance sets the frame, and compliance is one of the areas that frame has to steer. Without governance, nobody owns a compliance breach.
Risk appetite is the amount and type of risk the board has decided the organisation is willing to take. Risk profile is the actual picture of the risks the organisation faces right now. Appetite is a choice, whereas the profile is the output of risk assessment. Good governance means comparing the two and acting when the profile rises above the appetite.
The term GRC doesn't appear in legislation, but its substance does. NIS2 Article 20 requires management bodies of covered entities to approve and oversee cybersecurity risk measures. DORA Article 5 gives the management body of financial entities ultimate responsibility for ICT risk. GDPR Articles 5(2) and 24 require controllers to demonstrate compliance, and UK listed companies must report on internal controls under Provision 29.
Overall accountability sits with the board or governing body. Executive management and department heads own risks in day-to-day operations. Compliance, risk management, the CISO and the DPO advise and monitor, while internal or external audit provides independent assurance. In smaller organisations several roles often sit with one person, and the board should be aware that independence is then limited.
The most widely used are ISO 31000 and COSO ERM for risk management, ISO 37301 for compliance management systems, ISO 37000 for governance and the IIA's Three Lines Model for roles. For information security, organisations use ISO/IEC 27001 and the NIST Cybersecurity Framework, and for IT governance COBIT from ISACA. Most combine two or three and map them to the laws they are subject to.
Not as such, because GRC isn't a standard. An organisation can, however, be certified against requirements standards such as ISO 37301 for compliance or ISO/IEC 27001 for information security. Individuals can hold GRC certifications, including those offered by OCEG. ISO 31000 and COSO ERM are guidance, so no organisation can be certified against them.
ERM, enterprise risk management, is the organisation-wide management of risk described in frameworks such as COSO and ISO 31000. GRC is broader and also covers governance and compliance. You could say ERM is the R in GRC, raised to enterprise level. COSO itself makes governance and culture its first component, so the boundary between the two is blurred.
A GRC analyst or manager keeps obligations, risks and controls joined up across departments. Typical tasks include maintaining the risk register, mapping controls to GDPR, NIS2 and ISO 27001 requirements, preparing board reporting and coordinating audits. The role belongs to the second line in the Three Lines Model. It advises management but normally doesn't own the risks itself.
Yes, in a lighter form. An organisation of 60 people rarely needs a GRC department, but it does need an approved risk appetite, one method for assessing risk and a clear allocation of responsibility. If it is in scope of NIS2, board approval and oversight of cybersecurity measures are mandatory whatever the size. Start small and build out as your obligations grow.
Discover more about how governance, risk, and compliance frameworks can strengthen your organization's data protection posture.
Info
.legal A/S
hello@dotlegal.com
+45 7027 0127
VAT-no: DK40888888
Support
support@dotlegal.com
+45 7027 0127
Need help?
Let me help you get started
.legal is not a law firm and is therefore not under the supervision of the Bar Council.