What is GRC? (Governance, Risk and Compliance)
As defined by OCEG, GRC is the integrated collection of capabilities that enable an organisation to reliably achieve objectives, address uncertainty and act with integrity to achieve Principled Performance.
The OCEG (previously Open Compliance and Ethics Group) coined the acronym GRC (back in 2002) to describe the capabilities that integrate governance, management, performance assurance, risk and compliance activities.
Many organisations do not have a GRC program or concept, but do actively manage risk and compliance, and possibly through management structures exercise governance, so why would we say they do not have GRC?
GRC is the integration of all the capabilities that enable the achievement of mission, vision, goals. OCEG refers to Principled Performance as a “concept that encompasses an organisation’s ability to reliably achieve objectives, address uncertainty and act with integrity.”
Simply put: GRC is the framework of integrated working across governance, risk and compliance to achieve an organisation’s objectives. GRC software (or platforms) are tools that enable an organisation to embed and streamline the ways of working across the GRC capabilities i.e. the Risk Management, Information Security, Compliance, Strategy teams etc.
Historically, many of these departments operated in silos leading to duplication of effort, therefore high costs and lack of visibility of risks across the enterprise. Achievement of goals is at risk, if departments are working at cross-purposes, not sharing information and selecting strategies based on their view of the world, and not the organisational view.
There are now many modern, truly integrated, beautifully designed GRC solutions, that enable organisations to seamlessly implement a GRC program, and capitalise on the benefits of risk visibility. Achievement of strategic and operational goals becomes more certain due to the integrated way of working, visibility and regular monitoring of indicators, that enable an organisation to take alternative actions quickly.
GRC, a framework and a technology solution to enable your organisation to achieve its goals and manage risk effectively.
Reach out if you want to know our insights on the many GRC solutions out there, and which ones meet your UAE hosting requirements.
Any Questions?
Connect with lawyers and seek expert legal advice
Share
Find by Article Category
Browse articles by categories
Find Article by Practice Area
Browse articles by practice area
Related Articles
How do you keep control of your UAE com…
Quick Answer You keep control of an onshore UAE company at Series A by combi…
How do you keep control of your UAE company throu…
Quick Answer You keep control of an onshore UA…
How to Choose a Commercial Lawyer in Du…
If you are comparing commercial lawyers in Dubai, finding names is rarely the p…
How to Choose a Commercial Lawyer in Dubai: Pract…
If you are comparing commercial lawyers in Dubai,…
Legal Safety Rules — Issue 11 When a…
There is a sentence people say every day, and almost no one imagines it could l…
Legal Safety Rules — Issue 11 When a Gift Beco…
There is a sentence people say every day, and alm…
Legal Safety Rules — Issue 10 — When …
In a previous article, I shared a real story about insurance… and it re…
Legal Safety Rules — Issue 10 — When “Third-Par…
In a previous article, I shared a real story abou…
Legal Safety Rules — Issue 6 ---- Forc…
You may be hearing this more often these days… “Because of the cu…
Legal Safety Rules — Issue 6 ---- Force Majeure …
You may be hearing this more often these days&hel;…
Can two non-DIFC parties get a freezing…
What every business in Dubai needs to know about the DIFC Courts' expanding…
Can two non-DIFC parties get a freezing order in …
What every business in Dubai needs to know about …