GRC glossary
Essential definitions risk and compliance leaders need to know.

-

Regulatory compliance including SCF compliance frameworks
Read more: Regulatory compliance including SCF compliance frameworksWhat is regulatory compliance? Regulatory compliance is the process of meeting the laws, rules, standards, and requirements set by regulators, governments, and supervisory bodies. It helps organizations understand which external obligations apply, assign ownership, operate controls, collect evidence, and report when required. In governance, risk, and compliance (GRC), regulatory compliance matters because regulatory expectations rarely…
-

Compliance
Read more: ComplianceWhat is compliance? Compliance is the process of meeting the laws, regulations, standards, policies, contractual requirements, and ethical expectations that apply to an organization. In simple terms, compliance helps organizations understand what they are required to do, assign ownership, operate controls, evidence activity, and respond when something goes wrong. In governance, risk, and compliance (GRC),…
-

UK Corporate Governance Code
Read more: UK Corporate Governance CodeWhat is the UK Corporate Governance Code? The UK Corporate Governance Code is the Financial Reporting Council’s corporate governance framework for listed companies in the UK. It sets out principles and provisions covering board leadership, company purpose, division of responsibilities, board composition, succession, evaluation, audit, risk, internal control, and remuneration. The Financial Reporting Council explains…
-

AI governance
Read more: AI governanceWhat is AI governance? AI governance is the system an organization uses to direct, oversee, control, and evidence the way artificial intelligence is developed, bought, deployed, monitored, and used. It covers who can approve AI use, what risks need to be assessed, what data can be used, how outputs are reviewed, how decisions are documented,…
-

Board governance
Read more: Board governanceWhat is board governance? Board governance is the way a board of directors directs, oversees, and holds an organization accountable. It covers how the board sets strategic direction, challenges management, monitors performance, oversees risk and internal controls, and makes decisions in the interests of the organization and its stakeholders. In governance, risk, and compliance (GRC), board governance…
-

Board oversight
Read more: Board oversightWhat is board oversight? Board oversight is the process through which a board of directors monitors, challenges, and holds an organization’s leadership accountable. It helps directors understand whether strategy is being delivered, risks are being managed, controls are operating effectively, and issues are being escalated and resolved. In governance, risk, and compliance (GRC), board oversight matters because directors cannot…
-

Governance roles and responsibilities
Read more: Governance roles and responsibilitiesWhat are governance roles and responsibilities? Governance roles and responsibilities define who makes decisions, who provides oversight, who owns risk, who manages controls, who monitors compliance, and who must act when issues arise. They explain how authority, accountability, escalation, and reporting work across an organization. In practice, this means knowing who approves what, who owns…
-

Board reporting
Read more: Board reportingWhat is board reporting? Board reporting is the process of giving a board of directors the information it needs to oversee an organization, challenge management, and make informed decisions. It brings together relevant updates on strategy, performance, risk, controls, compliance, audit, issues, and actions. In governance, risk, and compliance (GRC), board reporting matters because directors…
-

Governance and compliance
Read more: Governance and complianceWhat is governance and compliance? Governance and compliance describes the relationship between how an organization is directed and controlled, and how it meets the obligations that apply to its activities. Governance sets direction, decision-making structures, accountability, oversight, and reporting. Compliance helps ensure the organization meets legal, regulatory, contractual, policy, and ethical requirements. In governance, risk,…
-

Governance and risk
Read more: Governance and riskWhat is governance and risk? Governance and risk describes how an organization directs, oversees, and makes decisions about uncertainty. Governance sets the structure for decision-making, accountability, reporting, oversight, and challenge. Risk management helps the organization understand what could affect its objectives, how serious those risks are, who owns them, and what action is needed. In…
Got a question for our team?
Discover our latest trends & insights
Continue learning about the world of GRC
-

Coca-Cola’s Fairlife ransomware attack: why risk doesn’t respect the org chart
Key takeaways How Fairlife’s cyberattack became a group governance issue On July 16, 2026, Coca-Cola disclosed that Fairlife, its dairy business, had detected unauthorized access to a section of its network, including production-linked systems. Production at Fairlife’s 4 US factories stopped. Canadian production continued. Product on shelves stayed safe. A ransomware-as-a-service group calling itself Anubis claimed responsibility, saying it had taken 1 terabyte of data and threatening to leak it. According to…
-

The EU delayed its AI Act deadline: what the Digital Omnibus means for AI governance everywhere
Key takeaways Introduction: the AI compliance deadline GRC teams have been racing toward just moved For eighteen months, “2 August 2026” has been a fixed point on the calendar for compliance, risk and AI governance teams across Europe, and well beyond. This was the date the EU AI Act’s toughest obligations, covering high-risk AI systems, were due to bite: conformity assessments, technical…
-

When the US government switched off AI: what the Anthropic shutdown means for your GRC program
Key takeaways Introduction: for many businesses the lights went out when the US government enforced AI restrictions Picture this: it’s the morning of 13 June 2026 and the compliance team at a mid-sized, European financial services business opens their AI-assisted regulatory monitoring tool – the one they recently rolled out, that surfaces horizon risk items and flags policy changes across five jurisdictions. It is offline, with no warning email, no estimated time of restoration and, critically, no fallback. …
Ready to discover game-changing GRC tech?
Contact the team and request your demo today.
This form may not be visible due to adblockers, or JavaScript not being enabled.