How to read aa GRC Score
Compliance

How to Get GRC Certified in the UK: A Step-by-Step Guide

July 27, 2026

Boards and senior leaders across the UK are facing the same question: how does the organisation demonstrate that its governance, risk, and compliance framework actually works? Not just on paper. In practice, with evidence.

GRC certification in the UK is not a single certificate that arrives in the post. It is a programme of structured work that combines the right framework, credentialled professionals, documented controls, and independent assessment. When completed correctly, it gives boards a defensible, evidence-based position for regulators, auditors, clients, and investors.

With Provision 29 of the UK Corporate Governance Code requiring boards to declare the effectiveness of their material controls from financial years beginning 1 January 2026, and DORA enforcing ICT resilience standards across the EU from January 2025, the pressure to formalise GRC has never been more specific. This step-by-step guide explains exactly how to do it.

What Does GRC Certification Mean for an Organisation?

GRC certification describes the process by which an organisation achieves formal, independently verified assurance that its governance, risk management, and compliance framework meets a recognised standard. The output may be an ISO certificate issued by an accredited certification body, a SOC 2 attestation report from a CPA firm, or a maturity assessment conducted against the OCEG GRC Capability Model.

There is no single universal GRC certificate. The approach depends on the framework you choose, your sector, your regulatory obligations, and the expectations of your clients, investors, and regulators. What certification has in common across all frameworks is this: it requires evidence that controls exist, are designed correctly, and have been operating effectively. Documentation and good intentions are not sufficient.

What GRC Certification Involves

A recognised framework: OCEG GRC Capability Model, ISO 27001, COSO ERM, NIST CSF

Credentialled professionals: GRCP / GRCA-certified team members leading the programme

Documented controls: a complete control inventory with design evidence

Operating evidence: proof that controls functioned over a defined period

Independent assessment: third-party audit or evaluation against the framework

Ongoing maintenance: annual reviews, continuous improvement, and regulatory updates

Why UK Organisations Are Prioritising GRC Certification in 2026

Three regulatory developments have moved GRC certification from best practice to board-level obligation for a significant number of UK and EU organisations.

Provision 29 of the UK Corporate Governance Code 2024

From financial years beginning on or after 1 January 2026, boards of UK premium-listed companies must declare in their annual report whether their material controls were effective at the balance sheet date. Material controls cover financial, operational, reporting, and compliance categories. If controls did not operate effectively, the board must explain what happened and what corrective action was taken or planned.

Provision 29 does not mandate a specific certification framework, but it does require credible, documented evidence of control effectiveness. An organisation that has not implemented a structured GRC framework will struggle to make that declaration with confidence. Those that have invested in formal GRC certification are positioned to meet this obligation without producing it under the pressure of reporting deadlines.

DORA and NIS2

DORA became fully enforceable across the EU in January 2025. It requires financial entities and their critical ICT third-party providers to implement and document security and resilience controls. NIS2 applies to essential and important entities across finance, energy, health, and digital infrastructure, with fines reaching 10 million euros or two per cent of global annual turnover.

Both regulations require organisations to move from policy statements to operational evidence. GRC certification provides the structured approach to generate and maintain that evidence at scale.

FCA Senior Managers and Certification Regime

SMCR places explicit personal accountability on named senior managers for the oversight of governance and risk functions. When something goes wrong, regulators look first at who was accountable and what evidence they had that controls were working. A formal GRC certification programme creates the audit trail that supports senior manager accountability.

Step 1: Assess Your Current GRC Maturity

Before selecting a framework or engaging an auditor, your organisation needs to know where it currently stands. Committing to a certification programme without understanding your baseline is one of the most common and costly mistakes boards make. It leads to remediation work discovered mid-audit, findings that delay certification, and investment directed at the wrong priorities.

A GRC maturity assessment evaluates your organisation against a defined set of domains and scoring criteria. The output is a scored view of where controls are strong, where gaps exist, and what needs to be addressed before formal assessment or certification begins.

GRC Index: Your Baseline Assessment

The GRC Index benchmark evaluates your organisation across six domains:

Governance and Oversight  |  Risk Management  |  Regulatory Compliance

Information Security  |  Operational Resilience  |  Third-Party Risk

Each domain produces a score from 0 to 100 and a maturity level from 1 to 5,

with a RAG (Red, Amber, Green) status to prioritise where to act first.

Book your benchmark at grci.net before engaging any certification auditor.

OCEG also provides the GRC Assessment Framework (the Burgundy Book), which supports self-assessment and independent assessment against the GRC Capability Model. Both tools serve the same purpose: giving your board an honest, evidence-based picture before the formal certification process begins.

Step 2: Choose the Right GRC Framework

The framework you choose determines the standard against which your controls will be assessed and the certification or attestation you will receive. The four most widely adopted frameworks in the UK and EU context are:

OCEG GRC Capability Model (Red Book)

The OCEG GRC Capability Model is the only open-source integrated GRC standard globally. It combines governance, strategy, performance, risk, compliance, ethics, internal control, security, privacy, and audit into a single unified framework. It is built around Principled Performance, which is the reliable achievement of objectives while addressing uncertainty and acting with integrity.

The GRC Capability Model is the most comprehensive option for organisations that want a single framework covering all GRC disciplines. Assessment against it produces a maturity score and recommendations for improvement rather than a binary pass or fail certificate.

COSO Enterprise Risk Management Framework

COSO ERM is the framework most widely used by boards and audit committees for enterprise risk management and internal controls. It is directly relevant to Provision 29 compliance, as its five components (governance and culture, strategy and objective-setting, performance, review and revision, information and communication) map closely to what the FRC expects boards to demonstrate.

Organisations in financial services, manufacturing, and other regulated industries that need to satisfy both their board and external auditors about the quality of their internal control framework typically adopt COSO ERM.

ISO 27001 (Information Security Management)

ISO 27001 is the internationally recognised certification standard for information security management systems. It is issued by UKAS-accredited certification bodies including BSI, DNV, and Bureau Veritas. Certification is achieved after a Stage 1 documentation review and Stage 2 audit, followed by annual surveillance audits and a three-year recertification cycle.

ISO 27001 is the right choice for organisations whose primary GRC driver is information security, or where clients and procurement teams specifically require an ISO 27001 certificate. All certifications must now be against the 2022 version of the standard (ISO/IEC 27001:2022).

NIST Cybersecurity Framework

NIST CSF originated in the US but has been widely adopted by UK and EU organisations, particularly those with US clients or those aligning with DORA's security and resilience requirements. It organises cybersecurity activities into five functions: Identify, Protect, Detect, Respond, and Recover. NIST CSF does not carry a formal certification, but it provides a recognised assessment framework that maps well to both SOC 2 and ISO 27001 requirements.

Choosing Your Framework: A Quick Selector

Your primary driver is information security and you need a formal certificate:

Select ISO 27001

Your board needs to demonstrate material control effectiveness under Provision 29:

Select COSO ERM

You want a single integrated framework covering all GRC disciplines:

Select OCEG GRC Capability Model

You supply ICT services to EU financial entities under DORA:

Consider SOC 2 (Security + Availability) alongside your primary framework

You need to satisfy US enterprise buyers:

Add SOC 2 Type II to whichever primary framework you choose

Step 3: Build the Business Case and Secure Board Sign-Off

GRC certification cannot be delivered by a compliance team working in isolation. It requires board-level ownership, cross-functional commitment, and resource allocation. Without board sign-off, certification programmes stall at the implementation stage because controls that span finance, operations, IT, HR, and legal require senior authority to establish and enforce.

The maturity assessment from Step 1 is your primary tool for building the business case. A board can understand a score. Red, Amber, and Green ratings across six domains make the risk landscape visible. Quantifying the cost of inaction in the context of Provision 29 obligations, DORA fines, or the loss of enterprise contracts due to missing certifications converts the board conversation from 'do we need to do this?' to 'what does doing this require from us?'

For UK financial services organisations, SMCR adds a personal dimension. The named senior manager accountable for GRC has a direct interest in ensuring the programme is properly resourced. That accountability makes the business case easier to present than in sectors where consequences are less personally attributable.

Step 4: Credential Your GRC Team

The people who design, implement, and audit your GRC framework need to understand the framework they are working with. Organisations that attempt certification with a team that has no formal GRC training consistently produce weaker control documentation, encounter more findings, and take longer to achieve certification than those whose team leads hold recognised credentials.

OCEG GRCP: GRC Professional Certification

The GRC Professional (GRCP) certification is issued by OCEG and validates that the holder can apply the GRC Capability Model in an organisation. It is recommended for anyone leading or contributing to a GRC programme: GRC managers, risk officers, compliance leads, and governance professionals. The exam is open-book, 100 questions, two hours, and requires a 70 per cent passing score. OCEG recommends two or more years of professional experience in governance, risk, compliance, internal audit, or information security, though no formal prerequisite exists.

OCEG GRCA: GRC Auditor Certification

The GRC Auditor (GRCA) certification is for professionals who will audit a GRC programme against the OCEG Capability Model. It builds on the GRCP and is specifically relevant for internal auditors, risk assurance professionals, and those conducting assessments against the Burgundy Book. OCEG recommends completing GRCP before GRCA, and both certifications are required by OCEG for professionals issuing formal assurance reports against the GRC Capability Model.

Team Credentials by Role

GRC Programme Lead / GRC Manager: OCEG GRCP

Internal Auditor / Risk Assurance: OCEG GRCA

Compliance Specialist (financial services): ICA Certificate or Diploma

Risk Management Specialist: IRM Certificate or International Diploma

Information Security Lead: CISSP, CISM, or ISO 27001 Lead Implementer

All senior GRC team members: consider ISACA CRISC for IT risk coverage

Step 5: Implement and Document Your Controls

Control implementation is where the majority of the work in a GRC certification programme takes place. It requires building a control inventory, documenting each control's design, establishing the processes through which evidence of operation is collected, and mapping controls to the regulatory obligations and framework requirements they address.

Build Your Control Inventory

A control inventory lists every material control your organisation has in place across each GRC domain. For organisations preparing for Provision 29, material controls are those critical to the reliability of financial, operational, reporting, and compliance processes. Your inventory should state what each control does, who is responsible for it, and how its operation is verified.

Apply the Three Lines of Defence Model

The three lines of defence model provides the governance structure through which controls are owned, monitored, and independently assessed. The first line is operational management, which owns and operates controls. The second line is the risk and compliance function, which monitors and challenges the first line. The third line is internal audit, which provides independent assurance to the board. GRC certification assessors and regulators expect to see this structure clearly defined and operating.

Establish Evidence Collection Processes

Documentation of control design is necessary but not sufficient. Certifying bodies and auditors require evidence that controls have operated during the observation period. This means logs, approvals, review records, exception reports, and testing outputs produced as controls run, not assembled retrospectively when an audit is announced. Organisations that have systematic evidence collection built into their operations consistently achieve cleaner certification outcomes.

Step 6: Conduct an Independent Assessment or External Audit

Once controls have been implemented and are operating, your organisation is ready for independent assessment. The nature of the assessment depends on the framework and the type of assurance you need.

  • ISO 27001 certification: is conducted by a UKAS-accredited certification body in two stages. Stage 1 reviews your documentation and ISMS design. Stage 2 tests implementation and operating effectiveness. Certification is valid for three years with annual surveillance audits.
  • OCEG GRC Capability Model assessment: can be a self-assessment using the Burgundy Book, or an independent assessment conducted by a GRCA-certified assessor. The output is a maturity level and recommendations rather than a binary certificate.
  • SOC 2 attestation: is conducted by an accredited CPA firm. A Type I report covers control design at a point in time. A Type II report covers operating effectiveness over six to twelve months.
  • COSO ERM assessment: is typically conducted by internal audit or an external advisory firm with COSO expertise. It produces a management assessment of internal control effectiveness, which is what Provision 29 requires boards to declare.

For EU organisations, DNB in the Netherlands, BaFin in Germany, and Finansinspektionen in Sweden all conduct supervisory reviews that assess the quality of GRC frameworks at regulated entities. A completed certification programme provides the evidence base these reviews draw on.

Step 7: Achieve Certification and Maintain It

Certification is not the end of the programme. It is the point at which ongoing GRC maintenance becomes the primary activity. Regulatory requirements change. Frameworks are updated. New risks emerge. Surveillance audits and re-certification cycles require continuing evidence of operating effectiveness.

Organisations that treat GRC certification as a one-time project consistently find their maturity score declining between certification cycles. Those that establish a continuous improvement programme, with quarterly control reviews, annual framework updates, and regular board reporting, maintain and improve their maturity level over time.

GRC Maturity Levels and What They Mean

Level 1, Ad Hoc:   Controls exist informally. No consistent documentation or oversight.

Level 2, Reactive: Controls respond to incidents. Documentation is patchy.

Level 3, Defined:  Controls are documented, assigned, and regularly reviewed.

Level 4, Managed:   Controls are measured. Risk appetite is quantified and monitored.

Level 5, Optimised: Continuous improvement. Controls adapt proactively to emerging risks.

Most UK organisations beginning a GRC certification programme start at Level 1 or 2.

Most certifications require a minimum of Level 3 to pass an initial assessment cleanly.

How Long Does GRC Certification Take?

Timeline depends on your current maturity, the framework you have chosen, and how well-resourced your programme is. As a guide for UK organisations planning their programme:

  • GRC maturity assessment (Step 1): four to eight weeks from engagement to report
  • OCEG GRC Capability Model assessment: three to six months for organisations at maturity Level 2 or above
  • ISO 27001 certification: six to eighteen months from scoping to certificate, depending on existing ISMS maturity
  • SOC 2 Type II: nine to fifteen months including the observation period, for a first-time engagement
  • COSO ERM framework implementation: six to twelve months to document controls and produce board-level reporting sufficient for Provision 29

Organisations starting from a low baseline, with no formal control documentation and no credentialled GRC team, should plan for twelve to eighteen months before they are ready for external assessment. Those that have existing controls but have never formalised them can typically achieve first certification within nine to twelve months with focused investment.

How GRC Index Supports Your Certification Journey

The first question every GRC certification programme must answer is: where do we actually stand? Without a scored, evidence-based baseline, organisations either over-invest in areas that are already strong or under-invest in areas that will generate findings at audit.

The GRC Index benchmark evaluates your organisation across six domains with scores from zero to one hundred and maturity levels from one to five. It identifies which controls are in place, which are missing, and where investment will generate the greatest improvement in your readiness for formal assessment or certification.

Boards that begin their certification programme with a GRC Index benchmark report have a clear, prioritised roadmap before they engage any auditor or certification body. That means fewer surprises, shorter timelines, and better outcomes.

Start With a GRC Benchmark at grci.net

Before engaging a certification body, know exactly where your controls stand.

The GRC Index benchmark gives your board a scored, RAG-rated view across:

Governance and Oversight  |  Risk Management  |  Regulatory Compliance

Information Security  |  Operational Resilience  |  Third-Party Risk

Score: 0 to 100  |  Maturity: 1 to 5  |  Priority actions per domain

Book your GRC benchmark at grci.net

Frequently Asked Questions

Is there a single GRC certification for organisations in the UK?

There is no single universal GRC certificate. UK organisations typically pursue formal assessments or certifications against recognised frameworks such as ISO 27001 for information security, COSO ERM for enterprise risk and internal controls, or the OCEG GRC Capability Model for an integrated approach. The output is an attestation report, formal certificate, or scored maturity assessment rather than one universal badge.

What is OCEG GRCP certification?

The GRC Professional (GRCP) certification is issued by OCEG and validates that an individual understands and can apply the GRC Capability Model in an organisation. It requires passing a 100-question open-book exam with a 70 per cent passing score. OCEG recommends it for professionals leading or contributing to a GRC programme, including risk officers, compliance managers, and governance professionals.

How long does it take to get GRC certified in the UK?

Timeline depends on the framework and your current maturity. An initial GRC maturity assessment takes four to eight weeks. ISO 27001 certification typically takes six to eighteen months. An OCEG GRC Capability Model assessment can be completed in three to six months for organisations with existing controls. Organisations starting from a low maturity baseline should plan for twelve to eighteen months before they are ready for external assessment.

Does Provision 29 require GRC certification?

Provision 29 of the UK Corporate Governance Code 2024 requires boards of premium-listed companies to declare whether their material controls were effective for financial years beginning on or after 1 January 2026. It does not mandate a specific certification, but organisations need a structured, evidence-based GRC framework in place to support that declaration with credibility. A COSO ERM implementation or OCEG GRC Capability Model assessment provides the strongest evidence base.

Which GRC framework is most widely adopted in the UK?

ISO 27001 is the most widely adopted formal certification in the UK for information security management. COSO ERM is widely used for enterprise risk and internal control frameworks, particularly in financial services and organisations preparing for Provision 29. The OCEG GRC Capability Model is the leading integrated GRC framework globally and is increasingly adopted by UK organisations seeking a unified approach across governance, risk, compliance, and audit.

GRC Assessment & Benchmarking

Evaluate your governance, risk, and compliance performance. Receive your GRC Score. Join organisations & professionals building verifiable, standards-based trust.