
Boards and senior leaders across the UK are facing the same question: how does the organisation demonstrate that its governance, risk, and compliance framework actually works? Not just on paper. In practice, with evidence.
GRC certification in the UK is not a single certificate that arrives in the post. It is a programme of structured work that combines the right framework, credentialled professionals, documented controls, and independent assessment. When completed correctly, it gives boards a defensible, evidence-based position for regulators, auditors, clients, and investors.
With Provision 29 of the UK Corporate Governance Code requiring boards to declare the effectiveness of their material controls from financial years beginning 1 January 2026, and DORA enforcing ICT resilience standards across the EU from January 2025, the pressure to formalise GRC has never been more specific. This step-by-step guide explains exactly how to do it.
GRC certification describes the process by which an organisation achieves formal, independently verified assurance that its governance, risk management, and compliance framework meets a recognised standard. The output may be an ISO certificate issued by an accredited certification body, a SOC 2 attestation report from a CPA firm, or a maturity assessment conducted against the OCEG GRC Capability Model.
There is no single universal GRC certificate. The approach depends on the framework you choose, your sector, your regulatory obligations, and the expectations of your clients, investors, and regulators. What certification has in common across all frameworks is this: it requires evidence that controls exist, are designed correctly, and have been operating effectively. Documentation and good intentions are not sufficient.
A recognised framework: OCEG GRC Capability Model, ISO 27001, COSO ERM, NIST CSF
Credentialled professionals: GRCP / GRCA-certified team members leading the programme
Documented controls: a complete control inventory with design evidence
Operating evidence: proof that controls functioned over a defined period
Independent assessment: third-party audit or evaluation against the framework
Ongoing maintenance: annual reviews, continuous improvement, and regulatory updates
Three regulatory developments have moved GRC certification from best practice to board-level obligation for a significant number of UK and EU organisations.
From financial years beginning on or after 1 January 2026, boards of UK premium-listed companies must declare in their annual report whether their material controls were effective at the balance sheet date. Material controls cover financial, operational, reporting, and compliance categories. If controls did not operate effectively, the board must explain what happened and what corrective action was taken or planned.
Provision 29 does not mandate a specific certification framework, but it does require credible, documented evidence of control effectiveness. An organisation that has not implemented a structured GRC framework will struggle to make that declaration with confidence. Those that have invested in formal GRC certification are positioned to meet this obligation without producing it under the pressure of reporting deadlines.
DORA became fully enforceable across the EU in January 2025. It requires financial entities and their critical ICT third-party providers to implement and document security and resilience controls. NIS2 applies to essential and important entities across finance, energy, health, and digital infrastructure, with fines reaching 10 million euros or two per cent of global annual turnover.
Both regulations require organisations to move from policy statements to operational evidence. GRC certification provides the structured approach to generate and maintain that evidence at scale.
SMCR places explicit personal accountability on named senior managers for the oversight of governance and risk functions. When something goes wrong, regulators look first at who was accountable and what evidence they had that controls were working. A formal GRC certification programme creates the audit trail that supports senior manager accountability.
Before selecting a framework or engaging an auditor, your organisation needs to know where it currently stands. Committing to a certification programme without understanding your baseline is one of the most common and costly mistakes boards make. It leads to remediation work discovered mid-audit, findings that delay certification, and investment directed at the wrong priorities.
A GRC maturity assessment evaluates your organisation against a defined set of domains and scoring criteria. The output is a scored view of where controls are strong, where gaps exist, and what needs to be addressed before formal assessment or certification begins.
The GRC Index benchmark evaluates your organisation across six domains:
Governance and Oversight | Risk Management | Regulatory Compliance
Information Security | Operational Resilience | Third-Party Risk
Each domain produces a score from 0 to 100 and a maturity level from 1 to 5,
with a RAG (Red, Amber, Green) status to prioritise where to act first.
Book your benchmark at grci.net before engaging any certification auditor.
OCEG also provides the GRC Assessment Framework (the Burgundy Book), which supports self-assessment and independent assessment against the GRC Capability Model. Both tools serve the same purpose: giving your board an honest, evidence-based picture before the formal certification process begins.
The framework you choose determines the standard against which your controls will be assessed and the certification or attestation you will receive. The four most widely adopted frameworks in the UK and EU context are:
The OCEG GRC Capability Model is the only open-source integrated GRC standard globally. It combines governance, strategy, performance, risk, compliance, ethics, internal control, security, privacy, and audit into a single unified framework. It is built around Principled Performance, which is the reliable achievement of objectives while addressing uncertainty and acting with integrity.
The GRC Capability Model is the most comprehensive option for organisations that want a single framework covering all GRC disciplines. Assessment against it produces a maturity score and recommendations for improvement rather than a binary pass or fail certificate.
COSO ERM is the framework most widely used by boards and audit committees for enterprise risk management and internal controls. It is directly relevant to Provision 29 compliance, as its five components (governance and culture, strategy and objective-setting, performance, review and revision, information and communication) map closely to what the FRC expects boards to demonstrate.
Organisations in financial services, manufacturing, and other regulated industries that need to satisfy both their board and external auditors about the quality of their internal control framework typically adopt COSO ERM.
ISO 27001 is the internationally recognised certification standard for information security management systems. It is issued by UKAS-accredited certification bodies including BSI, DNV, and Bureau Veritas. Certification is achieved after a Stage 1 documentation review and Stage 2 audit, followed by annual surveillance audits and a three-year recertification cycle.
ISO 27001 is the right choice for organisations whose primary GRC driver is information security, or where clients and procurement teams specifically require an ISO 27001 certificate. All certifications must now be against the 2022 version of the standard (ISO/IEC 27001:2022).
NIST CSF originated in the US but has been widely adopted by UK and EU organisations, particularly those with US clients or those aligning with DORA's security and resilience requirements. It organises cybersecurity activities into five functions: Identify, Protect, Detect, Respond, and Recover. NIST CSF does not carry a formal certification, but it provides a recognised assessment framework that maps well to both SOC 2 and ISO 27001 requirements.
Your primary driver is information security and you need a formal certificate:
Your board needs to demonstrate material control effectiveness under Provision 29:
Select COSO ERM
You want a single integrated framework covering all GRC disciplines:
Select OCEG GRC Capability Model
You supply ICT services to EU financial entities under DORA:
Consider SOC 2 (Security + Availability) alongside your primary framework
You need to satisfy US enterprise buyers:
Add SOC 2 Type II to whichever primary framework you choose
GRC certification cannot be delivered by a compliance team working in isolation. It requires board-level ownership, cross-functional commitment, and resource allocation. Without board sign-off, certification programmes stall at the implementation stage because controls that span finance, operations, IT, HR, and legal require senior authority to establish and enforce.
The maturity assessment from Step 1 is your primary tool for building the business case. A board can understand a score. Red, Amber, and Green ratings across six domains make the risk landscape visible. Quantifying the cost of inaction in the context of Provision 29 obligations, DORA fines, or the loss of enterprise contracts due to missing certifications converts the board conversation from 'do we need to do this?' to 'what does doing this require from us?'
For UK financial services organisations, SMCR adds a personal dimension. The named senior manager accountable for GRC has a direct interest in ensuring the programme is properly resourced. That accountability makes the business case easier to present than in sectors where consequences are less personally attributable.
The people who design, implement, and audit your GRC framework need to understand the framework they are working with. Organisations that attempt certification with a team that has no formal GRC training consistently produce weaker control documentation, encounter more findings, and take longer to achieve certification than those whose team leads hold recognised credentials.
The GRC Professional (GRCP) certification is issued by OCEG and validates that the holder can apply the GRC Capability Model in an organisation. It is recommended for anyone leading or contributing to a GRC programme: GRC managers, risk officers, compliance leads, and governance professionals. The exam is open-book, 100 questions, two hours, and requires a 70 per cent passing score. OCEG recommends two or more years of professional experience in governance, risk, compliance, internal audit, or information security, though no formal prerequisite exists.
The GRC Auditor (GRCA) certification is for professionals who will audit a GRC programme against the OCEG Capability Model. It builds on the GRCP and is specifically relevant for internal auditors, risk assurance professionals, and those conducting assessments against the Burgundy Book. OCEG recommends completing GRCP before GRCA, and both certifications are required by OCEG for professionals issuing formal assurance reports against the GRC Capability Model.
GRC Programme Lead / GRC Manager: OCEG GRCP
Internal Auditor / Risk Assurance: OCEG GRCA
Compliance Specialist (financial services): ICA Certificate or Diploma
Risk Management Specialist: IRM Certificate or International Diploma
Information Security Lead: CISSP, CISM, or ISO 27001 Lead Implementer
All senior GRC team members: consider ISACA CRISC for IT risk coverage
Control implementation is where the majority of the work in a GRC certification programme takes place. It requires building a control inventory, documenting each control's design, establishing the processes through which evidence of operation is collected, and mapping controls to the regulatory obligations and framework requirements they address.
A control inventory lists every material control your organisation has in place across each GRC domain. For organisations preparing for Provision 29, material controls are those critical to the reliability of financial, operational, reporting, and compliance processes. Your inventory should state what each control does, who is responsible for it, and how its operation is verified.
The three lines of defence model provides the governance structure through which controls are owned, monitored, and independently assessed. The first line is operational management, which owns and operates controls. The second line is the risk and compliance function, which monitors and challenges the first line. The third line is internal audit, which provides independent assurance to the board. GRC certification assessors and regulators expect to see this structure clearly defined and operating.
Documentation of control design is necessary but not sufficient. Certifying bodies and auditors require evidence that controls have operated during the observation period. This means logs, approvals, review records, exception reports, and testing outputs produced as controls run, not assembled retrospectively when an audit is announced. Organisations that have systematic evidence collection built into their operations consistently achieve cleaner certification outcomes.
Once controls have been implemented and are operating, your organisation is ready for independent assessment. The nature of the assessment depends on the framework and the type of assurance you need.
For EU organisations, DNB in the Netherlands, BaFin in Germany, and Finansinspektionen in Sweden all conduct supervisory reviews that assess the quality of GRC frameworks at regulated entities. A completed certification programme provides the evidence base these reviews draw on.
Certification is not the end of the programme. It is the point at which ongoing GRC maintenance becomes the primary activity. Regulatory requirements change. Frameworks are updated. New risks emerge. Surveillance audits and re-certification cycles require continuing evidence of operating effectiveness.
Organisations that treat GRC certification as a one-time project consistently find their maturity score declining between certification cycles. Those that establish a continuous improvement programme, with quarterly control reviews, annual framework updates, and regular board reporting, maintain and improve their maturity level over time.
Level 1, Ad Hoc: Controls exist informally. No consistent documentation or oversight.
Level 2, Reactive: Controls respond to incidents. Documentation is patchy.
Level 3, Defined: Controls are documented, assigned, and regularly reviewed.
Level 4, Managed: Controls are measured. Risk appetite is quantified and monitored.
Level 5, Optimised: Continuous improvement. Controls adapt proactively to emerging risks.
Most UK organisations beginning a GRC certification programme start at Level 1 or 2.
Most certifications require a minimum of Level 3 to pass an initial assessment cleanly.
Timeline depends on your current maturity, the framework you have chosen, and how well-resourced your programme is. As a guide for UK organisations planning their programme:
Organisations starting from a low baseline, with no formal control documentation and no credentialled GRC team, should plan for twelve to eighteen months before they are ready for external assessment. Those that have existing controls but have never formalised them can typically achieve first certification within nine to twelve months with focused investment.
The first question every GRC certification programme must answer is: where do we actually stand? Without a scored, evidence-based baseline, organisations either over-invest in areas that are already strong or under-invest in areas that will generate findings at audit.
The GRC Index benchmark evaluates your organisation across six domains with scores from zero to one hundred and maturity levels from one to five. It identifies which controls are in place, which are missing, and where investment will generate the greatest improvement in your readiness for formal assessment or certification.
Boards that begin their certification programme with a GRC Index benchmark report have a clear, prioritised roadmap before they engage any auditor or certification body. That means fewer surprises, shorter timelines, and better outcomes.
Before engaging a certification body, know exactly where your controls stand.
The GRC Index benchmark gives your board a scored, RAG-rated view across:
Governance and Oversight | Risk Management | Regulatory Compliance
Information Security | Operational Resilience | Third-Party Risk
Score: 0 to 100 | Maturity: 1 to 5 | Priority actions per domain
Book your GRC benchmark at grci.net
There is no single universal GRC certificate. UK organisations typically pursue formal assessments or certifications against recognised frameworks such as ISO 27001 for information security, COSO ERM for enterprise risk and internal controls, or the OCEG GRC Capability Model for an integrated approach. The output is an attestation report, formal certificate, or scored maturity assessment rather than one universal badge.
The GRC Professional (GRCP) certification is issued by OCEG and validates that an individual understands and can apply the GRC Capability Model in an organisation. It requires passing a 100-question open-book exam with a 70 per cent passing score. OCEG recommends it for professionals leading or contributing to a GRC programme, including risk officers, compliance managers, and governance professionals.
Timeline depends on the framework and your current maturity. An initial GRC maturity assessment takes four to eight weeks. ISO 27001 certification typically takes six to eighteen months. An OCEG GRC Capability Model assessment can be completed in three to six months for organisations with existing controls. Organisations starting from a low maturity baseline should plan for twelve to eighteen months before they are ready for external assessment.
Provision 29 of the UK Corporate Governance Code 2024 requires boards of premium-listed companies to declare whether their material controls were effective for financial years beginning on or after 1 January 2026. It does not mandate a specific certification, but organisations need a structured, evidence-based GRC framework in place to support that declaration with credibility. A COSO ERM implementation or OCEG GRC Capability Model assessment provides the strongest evidence base.
ISO 27001 is the most widely adopted formal certification in the UK for information security management. COSO ERM is widely used for enterprise risk and internal control frameworks, particularly in financial services and organisations preparing for Provision 29. The OCEG GRC Capability Model is the leading integrated GRC framework globally and is increasingly adopted by UK organisations seeking a unified approach across governance, risk, compliance, and audit.
© 2025 GRC Index. All rights reserved.