The reference desk / In practice

GRC

The organizational functions that set policy, track risk, and collect assurance evidence. Not a product that grants safety.

Governance, risk, and compliance

What it means

Governance establishes who can make security decisions and what the organization expects. Risk management examines uncertain events, their consequences, and possible responses. Compliance checks applicable obligations, including contractual commitments and chosen standards. These activities overlap, but their questions differ: a completed checklist does not establish that a business risk is acceptable. Useful GRC connects policy to actual controls, accountable owners, evidence, and decisions. A small organization can begin with clear records and regular reviews; buying a tracking platform does not create those responsibilities.

AN ILLUSTRATIVE SCENARIO

A clinic weighs a delayed update

A clinic cannot immediately update a scheduling server because the supplier has not validated the release. The service owner documents the exposure, patient-care impact of an outage, proposed restrictions, and expected update date. An authorized risk owner decides whether the remaining risk is acceptable. The compliance team checks relevant obligations and retains the decision and supporting evidence. Security tests the restrictions and reports any change that invalidates the original decision instead of treating the approval as permanent.

Put it to work

  1. Identify one important service, the person accountable for its risk, and the obligations that apply. Distinguish mandatory requirements from internal preferences and record how applicability was determined.
  2. Map each relevant requirement to an implemented control, an owner, and evidence that can be checked. Describe gaps and their business consequences in plain language.
  3. Set a review rhythm for risks, exceptions, and control performance. Require decisions to state the accepted exposure, responsible authority, next action, and conditions that trigger reconsideration.

How to check your work

Pick a recorded requirement and trace it to a working control, recent evidence, a responsible owner, and an exception process. Ask the owner what would make the current risk decision change; the answer should be specific enough to act on.

Connect the ideas

  • Risk

    The potential for harm, assessed using what could happen, how likely it is, its impact, and what remains uncertain.

  • Control

    A process, configuration, or technology meant to reduce a named risk or detect a named failure.

  • Residual risk

    The risk that remains after selected controls, including the uncertainty you still accept.

Explore a field lesson

Find your next idea.

Tip: press / to open search. Escape closes this window.