Governance Risk and Compliance: What It Means for Your Organisation

Governance, risk and compliance (GRC) describes the three disciplines that every organisation needs to operate with accountability, manage uncertainty, and meet its legal and regulatory obligations. In the UK and across the EU, the pressure to get all three right has never been greater. Boards are being asked to declare controls effectiveness under Provision 29. Financial entities in the EU are subject to DORA. NIS2 has extended cyber and operational obligations across critical sectors.

GRC Index (GRCi) brings governance, risk management, and compliance together into a single independent assessment. It gives your board a scored, evidence-based view of where your programme stands and what needs to change.

GRCI About Us Large

What Is Governance, Risk and Compliance (GRC)?

Governance, risk and compliance is not a piece of software or a regulation. It is a way of running an organisation. It describes how an organisation directs itself, manages what might go wrong, and ensures it meets its obligations to regulators, shareholders, employees, and the public.

The term was developed by OCEG (Open Compliance and Ethics Group) to describe what they called Principled Performance: the ability to reliably achieve objectives, address uncertainty, and act with integrity. In practice, most organisations treat GRC as a framework that brings three separate functions into a coherent, connected programme.

When those three functions operate independently, organisations face duplicated effort, inconsistent risk assessments, and compliance gaps that fall between team boundaries. When they work together, the board has a clear, real-time picture of the organisation's risk and control position.

GRC at a Glance

Governance: how the board directs, oversees, and holds the organisation accountable
Risk Management: how the organisation identifies, assesses, and controls threats to its objectives
Compliance: how the organisation meets its obligations under law, regulation, and internal policy
GRC: the integrated approach that brings all three together into a single framework and reporting line

The Three Pillars Explained

Governance

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Risk Management

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Compliance

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Why All Three Must Work Together

Governance, risk management, and compliance are often managed by separate teams with separate budgets, separate reporting lines, and separate tools. On paper, this looks efficient: each function focuses on its own area of expertise. In practice, it creates problems that are well understood but surprisingly common.

When governance operates in isolation, the board sets a risk appetite that risk teams do not reference and compliance teams have never seen. When risk management operates in isolation, risk registers capture threats that no control owner is responsible for addressing. When compliance operates in isolation, teams spend time demonstrating they have met obligations that overlap significantly with the work done elsewhere in the organisation.

The Cost of Siloed GRC

Duplicated effort: separate teams assess the same risks under different frameworks without sharing findings
Compliance gaps: obligations that fall between team boundaries are missed until a regulator or auditor finds them
Board blindspots: the board receives fragmented reporting from separate functions rather than a coherent risk and control picture
Wasted investment: organisations spend on multiple tools, processes, and reviews that cover overlapping ground
Slow response: without a shared view of risk and control status, escalation is slow and remediation is reactive

The integrated alternative is not about merging governance, risk, and compliance into a single department. It is about connecting them so that risk appetite flows from governance decisions, compliance obligations are mapped to risks, controls address both risk and compliance requirements together, and the board receives a single, coherent view rather than three separate reports.

Organisations that have achieved this integration spend less time demonstrating compliance and more time managing risk. They meet regulatory requirements more efficiently because they are not treating each framework as a separate project. And their boards are better positioned to make informed decisions because they have a connected picture rather than a fragmented one.

Why UK and EU Organisations Need GRC Now

The regulatory landscape in the UK and EU in 2025 and 2026 has made integrated GRC a practical necessity rather than a governance aspiration. Organisations are not managing one or two regulatory requirements. They are managing a portfolio of overlapping, sometimes conflicting, and continuously evolving obligations that span multiple domains.

United Kingdom

UK organisations subject to FCA regulation must demonstrate compliance with the Senior Managers and Certification Regime, which places direct personal accountability on named individuals for specific areas of the firm's governance and risk management. The UK Corporate Governance Code's Provision 29 requires boards of premium-listed companies to declare the effectiveness of material controls from financial years beginning January 2026. UK GDPR places ongoing obligations on data controllers and processors across all sectors.

European Union

EU financial entities have been subject to the full requirements of the Digital Operational Resilience Act (DORA) since January 2025. DORA requires financial entities to implement ICT risk management frameworks, conduct digital operational resilience testing, report major ICT incidents, and oversee critical third-party ICT providers. NIS2 has extended cybersecurity and incident reporting obligations across a significantly wider range of sectors than its predecessor, with fines of up to ten million euros or two percent of global annual turnover for non-compliance.

Cross-Border Operations

For organisations with operations in both the UK and the EU, or those that supply services to UK or EU regulated entities, the challenge is not just meeting each set of requirements in isolation. It is managing the interaction between frameworks that share common themes but have different implementation requirements. DORA, NIS2, EU GDPR, and the UK Corporate Governance Code all address governance, risk management, and operational resilience. An integrated GRC framework allows organisations to map obligations across frameworks, identify where controls serve multiple requirements simultaneously, and avoid duplicating work that achieves the same regulatory purpose.

Key Regulatory Obligations for UK and EU Organisations

UK: UK GDPR, FCA Senior Managers and Certification Regime (SMCR), UK Corporate Governance Code (Provision 29)
EU Financial Services: DORA (full enforcement January 2025), ECB SSM supervisory expectations, MiFID II
EU All Sectors: NIS2 Directive (fines up to 10 million euros or 2% of global turnover), EU GDPR
Germany: BaFin BAIT/VAIT/ZAIT circulars, MaRisk (minimum risk management requirements)
Netherlands: DNB Good Practices for Cloud Outsourcing, DNB Guidance on Operational Resilience
Sweden: Finansinspektionen FFFS regulations, NIS2 transposition under Swedish law

How GRC Index Brings Governance, Risk and Compliance Together

GRC Index (GRCi) is an independent GRC benchmarking service. It assesses your organisation's governance, risk, and compliance programme across six domains, produces a GRC score between 0 and 100, assigns a maturity level, and gives the board a domain-by-domain view of where the programme stands and where the gaps are.

The GRC Index framework is not a consultancy engagement or a software subscription. It is an independent assessment with a scored, documented output that can be presented to the board, used to brief the audit committee, shared with external auditors, and used to track improvement year on year.

The Six Domains

GRC Index measures programme maturity across six domains that together cover the full scope of governance, risk, and compliance for most UK and EU organisations:

  • Governance and Oversight: board structure, accountability, policy frameworks, escalation processes, and the quality of GRC reporting to the board
  • Risk Management: risk identification, assessment, treatment, appetite framework, and integration into operational decision-making
  • Regulatory Compliance: identification of applicable obligations, compliance monitoring, regulatory change management, and evidence of compliance across UK and EU frameworks
  • Information Security: cyber risk management, access control, incident response, data protection, and alignment with NIS2 and DORA ICT requirements
  • Operational Resilience: business continuity, disaster recovery, critical service mapping, resilience testing, and DORA operational resilience requirements
  • Third-Party Risk: supplier due diligence, ongoing monitoring, critical third-party oversight, and supply chain risk management under DORA and NIS2

The GRC Score

Each domain is assessed against a five-level maturity scale and scored independently. The overall GRC score (0 to 100) is a weighted composite of all six domain scores. A score of 0 to 24 indicates Level 1 (Ad Hoc). A score of 25 to 49 indicates Level 2 (Reactive). A score of 50 to 69 indicates Level 3 (Defined), which is where most organisations assessed currently sit. A score of 70 to 84 indicates Level 4 (Managed). A score of 85 to 100 indicates Level 5 (Optimised).

The score is not a pass or fail judgement. It is a benchmark. It tells the organisation precisely where it is on the maturity scale, how each domain contributes to or constrains the overall score, and where focused investment will produce the greatest improvement.

Board-Ready Output

The GRC Index assessment produces a report structured for board consumption. It includes the overall score and maturity level, a Red/Amber/Green domain view, a summary of the principal gaps, and a prioritised action plan. Boards preparing Provision 29 declarations, responding to regulatory scrutiny, or managing audit committee oversight of the GRC programme have a clear, independent basis for their conclusions.

What the GRC Index Assessment Produces

Overall GRC score: 0 to 100
Maturity level: 1 (Ad Hoc) to 5 (Optimised)
Domain-level scores and RAG ratings across all six GRC domains
Summary of principal gaps and their regulatory and risk implications
Prioritised action plan with impact and effort ratings
Board-ready report formatted for audit committee and board presentation
Year-on-year benchmark tracking for organisations that assess annually

Who This Is For

GRC Index assessments are designed for directors, senior risk and compliance professionals, and board-level advisers in organisations that need a clear, independent view of their GRC programme. The assessment is relevant to:

  • Board directors and non-executives: who need an independent basis for governance declarations, including Provision 29
  • Chief Risk Officers and Heads of Risk: who need a structured benchmark to present to the board and use to prioritise programme investment
  • Chief Compliance Officers and Compliance Directors: who need a consolidated view of the organisation's compliance position across multiple frameworks
  • Audit Committee Chairs: who need independent evidence of GRC programme maturity to support their oversight role
  • CFOs and Finance Directors: at organisations where financial reporting controls and operational resilience are directly relevant to their reporting obligations
  • General Counsel and Company Secretaries: supporting boards with governance obligations under the UK Corporate Governance Code and equivalent EU requirements

The assessment is available to organisations of all sizes across all sectors in the UK and EU. The domains covered and the regulatory mapping within each domain are calibrated to reflect the obligations most relevant to the organisation's sector and jurisdiction.

Frequently Asked Questions

What is governance risk and compliance (GRC)?

+

Governance, risk and compliance (GRC) is an integrated approach through which organisations direct and oversee their operations, identify and manage threats to their objectives, and meet their legal and regulatory obligations. When these three disciplines work together, organisations gain a unified view of performance, accountability, and control rather than managing each function in isolation.

Why do organisations need governance, risk and compliance?

+

Organisations need GRC because operating in the UK and EU means managing overlapping regulatory obligations simultaneously, including UK GDPR, the FCA Senior Managers and Certification Regime, Provision 29, DORA, and NIS2. Without an integrated approach, compliance becomes duplicated, risks fall through gaps between teams, and the board lacks a coherent view of the organisation's risk and control position.

What is the difference between governance, risk management, and compliance?

+

Governance sets the direction: it covers how the board oversees strategy, accountability, and organisational behaviour. Risk management identifies what could prevent the organisation from achieving its objectives and puts controls in place. Compliance ensures the organisation meets its obligations under law, regulation, and policy. Each discipline is necessary but incomplete without the others.

What is a GRC framework?

+

A GRC framework is a structured approach that integrates governance, risk management, and compliance into a single operating model. GRC Index uses a six-domain framework covering Governance and Oversight, Risk Management, Regulatory Compliance, Information Security, Operational Resilience, and Third-Party Risk. Each domain is assessed independently and contributes to an overall GRC score between 0 and 100.

How does GRC Index benchmark an organisation's programme?

+

GRC Index assesses your programme across six domains and produces a GRC score between 0 and 100, a maturity level between 1 and 5, and a Red/Amber/Green domain rating. The output gives the board a clear, evidence-based view of where the programme stands, how it compares to sector benchmarks, and where investment is needed.

Which organisations need a GRC assessment?

+

Any organisation that needs to demonstrate GRC programme maturity to its board, regulators, auditors, or counterparties benefits from a GRC assessment. This includes listed companies preparing Provision 29 declarations, financial services firms subject to FCA, PRA, or ECB oversight, EU organisations subject to DORA and NIS2, and any organisation whose board needs an independent, scored view of its governance, risk, and compliance position.