“GRC is a capability to reliably achieve objectives while addressing uncertainty and acting with integrity.” OCEG GRC Capability Model 2.1
GRC is what is achieved in the business and its operations. This means that GRC needs to be understood in the context of business architecture. To achieve good GRC processes in your environment requires an understanding of what the business is about, how it operates, and how it should be monitored and controlled through information and technology.
GRC is about taking an enterprise/business architecture approach to understanding the business and how it operates. This includes:
- Strategy architecture. Understanding what the business is about and where it is going. This requires that we understand GRC in the context of business performance, strategy, objectives as well as its culture and values.
- Process architecture. Flowing from strategy are the processes that define the business and how it operates. Good GRC is done in the rhythm of the business.
- Information architecture. To support business operations and processes you need a good definition of GRC related information and how information flows across the business.
- Technology architecture. You need to make sure that GRC technologies integrate with your business operations, systems, and processes.