GRC glossary
Essential definitions risk and compliance leaders need to know.

-

General Data Protection Regulation (GDPR) and Data Privacy management
Read more: General Data Protection Regulation (GDPR) and Data Privacy managementWhat is GDPR and Data Privacy management? The General Data Protection Regulation (GDPR) is the EU data protection law that governs how organizations collect, use, store, share, protect, and delete personal data. Data privacy management is the ongoing process organizations use to meet GDPR and other privacy obligations in practice. In governance, risk, and compliance…
-

Compliance audit
Read more: Compliance auditWhat is a compliance audit? A compliance audit is a structured review that checks whether an organization is meeting specific laws, regulations, standards, policies, contractual requirements, or internal controls. It helps confirm whether compliance requirements are understood, owned, evidenced, and operating in practice. In governance, risk, and compliance (GRC), a compliance audit matters because it…
-

Compliance reporting
Read more: Compliance reportingWhat is compliance reporting? Compliance reporting is the process of collecting, analyzing, and presenting information that shows whether an organization is meeting its compliance obligations. It helps leadership, boards, auditors, regulators, and internal stakeholders understand compliance status, control effectiveness, issues, breaches, remediation, and areas needing attention. In governance, risk, and compliance (GRC), compliance reporting matters…
-

Compliance management software
Read more: Compliance management softwareWhat is compliance management software? Compliance management software is a digital system that helps organizations manage compliance obligations, controls, policies, evidence, issues, remediation, and reporting in 1 connected place. It gives compliance teams a clearer way to understand what requirements apply, who owns them, what actions are due, and what evidence proves compliance activity has…
-

Regulatory compliance including SCF compliance frameworks
Read more: Regulatory compliance including SCF compliance frameworksWhat is regulatory compliance? Regulatory compliance is the process of meeting the laws, rules, standards, and requirements set by regulators, governments, and supervisory bodies. It helps organizations understand which external obligations apply, assign ownership, operate controls, collect evidence, and report when required. In governance, risk, and compliance (GRC), regulatory compliance matters because regulatory expectations rarely…
-

Compliance
Read more: ComplianceWhat is compliance? Compliance is the process of meeting the laws, regulations, standards, policies, contractual requirements, and ethical expectations that apply to an organization. In simple terms, compliance helps organizations understand what they are required to do, assign ownership, operate controls, evidence activity, and respond when something goes wrong. In governance, risk, and compliance (GRC),…
-

UK Corporate Governance Code
Read more: UK Corporate Governance CodeWhat is the UK Corporate Governance Code? The UK Corporate Governance Code is the Financial Reporting Council’s corporate governance framework for listed companies in the UK. It sets out principles and provisions covering board leadership, company purpose, division of responsibilities, board composition, succession, evaluation, audit, risk, internal control, and remuneration. The Financial Reporting Council explains…
-

AI governance
Read more: AI governanceWhat is AI governance? AI governance is the system an organization uses to direct, oversee, control, and evidence the way artificial intelligence is developed, bought, deployed, monitored, and used. It covers who can approve AI use, what risks need to be assessed, what data can be used, how outputs are reviewed, how decisions are documented,…
-

Board governance
Read more: Board governanceWhat is board governance? Board governance is the way a board of directors directs, oversees, and holds an organization accountable. It covers how the board sets strategic direction, challenges management, monitors performance, oversees risk and internal controls, and makes decisions in the interests of the organization and its stakeholders. In governance, risk, and compliance (GRC), board governance…
-

Board oversight
Read more: Board oversightWhat is board oversight? Board oversight is the process through which a board of directors monitors, challenges, and holds an organization’s leadership accountable. It helps directors understand whether strategy is being delivered, risks are being managed, controls are operating effectively, and issues are being escalated and resolved. In governance, risk, and compliance (GRC), board oversight matters because directors cannot…
Got a question for our team?
Discover our latest trends & insights
Continue learning about the world of GRC
-

Lombard Odier’s money-laundering conviction shows why flagging a compliance risk isn’t enough
Key takeaways Introduction: failure to go beyond filing a risk report leads to an AML conviction In 2012, a Geneva private bank, Lombard Odier, noticed unusual activity connected to one relationship manager’s client accounts and reported their suspicions to Switzerland’s Money Laundering Reporting Office. 14 years of legal process, and one collapsed prosecution against the alleged ringleader, later, Switzerland’s Federal Criminal Court…
-

Coca-Cola’s Fairlife ransomware attack: why risk doesn’t respect the org chart
Key takeaways How Fairlife’s cyberattack became a group governance issue On July 16, 2026, Coca-Cola disclosed that Fairlife, its dairy business, had detected unauthorized access to a section of its network, including production-linked systems. Production at Fairlife’s 4 US factories stopped. Canadian production continued. Product on shelves stayed safe. A ransomware-as-a-service group calling itself Anubis claimed responsibility, saying it had taken 1 terabyte of data and threatening to leak it. According to…
-

The EU delayed its AI Act deadline: what the Digital Omnibus means for AI governance everywhere
Key takeaways Introduction: the AI compliance deadline GRC teams have been racing toward just moved For eighteen months, “2 August 2026” has been a fixed point on the calendar for compliance, risk and AI governance teams across Europe, and well beyond. This was the date the EU AI Act’s toughest obligations, covering high-risk AI systems, were due to bite: conformity assessments, technical…
Ready to discover game-changing GRC tech?
Contact the team and request your demo today.
This form may not be visible due to adblockers, or JavaScript not being enabled.