GRC glossary
Essential definitions risk and compliance leaders need to know.

-

Risk
Read more: RiskWhat is risk? Risk is the effect of uncertainty on an organization’s objectives. In simple terms, risk is what could happen that may affect whether an organization achieves what it set out to do. In governance, risk, and compliance (GRC), risk matters because decisions are rarely made with perfect certainty. Organizations need a clear way…
-

Third party risk management
Read more: Third party risk managementThird party risk management is the process of identifying, assessing, monitoring, and managing the risks that come from working with external organizations. These third parties can include suppliers, vendors, contractors, service providers, consultants, technology providers, outsourced partners, and other external relationships. In governance, risk, and compliance (GRC), third party risk management matters because organizations are…
-

Healthcare compliance and HIPPA
Read more: Healthcare compliance and HIPPAWhat is healthcare compliance and HIPAA? Healthcare compliance is the process of meeting the laws, regulations, standards, policies, ethical rules, and patient safety requirements that apply to healthcare organizations. HIPAA, often misspelled as HIPPA, is 1 of the most important healthcare compliance laws in the United States because it sets rules for protecting health information…
-

Audit management
Read more: Audit managementWhat is audit management? Audit management is the process of planning, coordinating, executing, documenting, reporting, and tracking audits from start to finish. It gives organizations a structured way to decide what should be audited, why it matters, what evidence is needed, who owns findings, and how remediation is tracked through to closure. In governance, risk,…
-

General Data Protection Regulation (GDPR) and Data Privacy management
Read more: General Data Protection Regulation (GDPR) and Data Privacy managementWhat is GDPR and Data Privacy management? The General Data Protection Regulation (GDPR) is the EU data protection law that governs how organizations collect, use, store, share, protect, and delete personal data. Data privacy management is the ongoing process organizations use to meet GDPR and other privacy obligations in practice. In governance, risk, and compliance…
-

Compliance audit
Read more: Compliance auditWhat is a compliance audit? A compliance audit is a structured review that checks whether an organization is meeting specific laws, regulations, standards, policies, contractual requirements, or internal controls. It helps confirm whether compliance requirements are understood, owned, evidenced, and operating in practice. In governance, risk, and compliance (GRC), a compliance audit matters because it…
-

Compliance reporting
Read more: Compliance reportingWhat is compliance reporting? Compliance reporting is the process of collecting, analyzing, and presenting information that shows whether an organization is meeting its compliance obligations. It helps leadership, boards, auditors, regulators, and internal stakeholders understand compliance status, control effectiveness, issues, breaches, remediation, and areas needing attention. In governance, risk, and compliance (GRC), compliance reporting matters…
-

Compliance management software
Read more: Compliance management softwareWhat is compliance management software? Compliance management software is a digital system that helps organizations manage compliance obligations, controls, policies, evidence, issues, remediation, and reporting in 1 connected place. It gives compliance teams a clearer way to understand what requirements apply, who owns them, what actions are due, and what evidence proves compliance activity has…
-

Regulatory compliance including SCF compliance frameworks
Read more: Regulatory compliance including SCF compliance frameworksWhat is regulatory compliance? Regulatory compliance is the process of meeting the laws, rules, standards, and requirements set by regulators, governments, and supervisory bodies. It helps organizations understand which external obligations apply, assign ownership, operate controls, collect evidence, and report when required. In governance, risk, and compliance (GRC), regulatory compliance matters because regulatory expectations rarely…
-

Compliance
Read more: ComplianceWhat is compliance? Compliance is the process of meeting the laws, regulations, standards, policies, contractual requirements, and ethical expectations that apply to an organization. In simple terms, compliance helps organizations understand what they are required to do, assign ownership, operate controls, evidence activity, and respond when something goes wrong. In governance, risk, and compliance (GRC),…
Got a question for our team?
Discover our latest trends & insights
Continue learning about the world of GRC
-

Norway’s BankID outage shows what DORA-grade third-party risk management actually requires
For 2 days, millions of Norwegians couldn’t sign a contract, complete a house sale or access a health record because a single supplier’s infrastructure failed for the second time in 5 years. What happens when an entire country’s digital ID depends on a single supplier? On the morning of 3 September 2026, a real estate agent in…
-

The CareCloud data breach: a third-party risk warning for healthcare compliance teams
Key takeaways Introduction: the changing face of a healthcare data hack In early August 2026, patients of various US healthcare providers began opening data breach notifications from a company many had never heard of: CareCloud, the cloud-based electronic health record and billing platform their doctor’s office quietly ran in the background. The letter said their…
-

Lombard Odier’s money-laundering conviction shows why flagging a compliance risk isn’t enough
Key takeaways Introduction: failure to go beyond filing a risk report leads to an AML conviction In 2012, a Geneva private bank, Lombard Odier, noticed unusual activity connected to one relationship manager’s client accounts and reported their suspicions to Switzerland’s Money Laundering Reporting Office. 14 years of legal process, and one collapsed prosecution against the alleged ringleader, later, Switzerland’s Federal Criminal Court…
Ready to discover game-changing GRC tech?
Contact the team and request your demo today.
This form may not be visible due to adblockers, or JavaScript not being enabled.