GRC glossary
Essential definitions risk and compliance leaders need to know.

-

Governance
Read more: GovernanceWhat is governance? Governance is the system an organization uses to direct decisions, oversee performance, assign authority, and hold people accountable. It sets the rules for who can decide, who needs to approve, what evidence must be kept, and how leadership can see whether the organization is acting in line with its purpose. In governance, risk, and compliance, governance…
-

Good governance
Read more: Good governanceWhat is good governance? Good governance is governance that works in practice. It means an organization is directed, overseen, and held accountable in a way that is clear, fair, responsible, and effective. UN ESCAP describes good governance as having 8 major characteristics: “participatory, consensus oriented, accountable, transparent, responsive, effective and efficient, equitable and inclusive and…
-

Corporate governance
Read more: Corporate governanceWhat is corporate governance? The Cadbury Report gave one of the most widely used definitions of corporate governance: “Corporate governance is the system by which companies are directed and controlled.“ The Cadbury Report However, beyond day-to-day operations corporate governance is also the system by which a company is held accountable. It covers how the board…
-

Governance, risk and compliance (GRC)
Read more: Governance, risk and compliance (GRC)What is Governance, Risk and Compliance (GRC)? Governance, risk, and compliance, often shortened to GRC, is the framework organizations use to oversee decision-making, manage risk, and meet legal, regulatory, and internal requirements. OCEG refined the term, defining it as: At its best, GRC helps organizations move beyond siloed activity. Instead of governance, risk, compliance, audit, and…
Got a question for our team?
Discover our latest trends & insights
Continue learning about the world of GRC
-

The Novo Nordisk breach shows cyber extortion now targets far more than personal data – what risk and compliance leaders can learn from this
Key takeaways What happened at Novo Nordisk? Reuters reported that cyber extortion group FulcrumSec claimed it spent more than 2 months inside Novo Nordisk’s network and stole more than 700,000 files, equal to roughly 1.3 terabytes of data. The group also claimed Novo Nordisk refused to pay a $25m extortion demand. Reuters said it could not immediately verify the authenticity of the data…
-

World Cup stadium strike was narrowly averted: how resilient are your critical suppliers?
Key takeaways Introduction: What happened at the 2026 World Cup? Days before the World Cup began, a supplier issue at one of the tournament’s highest-profile venues was narrowly avoided. Reuters reported that a union representing around 2,000 food and beverage workers at SoFi Stadium reached a tentative agreement with Legends Hospitality only days before the tournament. AP described the agreement as averting a…
-

Recent Bank of England warning and why AI-driven cyber threats are now a top concern for banking regulators globally
Key takeaways Introduction: Is AI changing the cyber threat environment faster than organizations can respond? AI is not only a technology that organizations need to govern internally. It is also reshaping the external cyber threat environment. Used well, AI can help teams detect vulnerabilities, strengthen defenses and respond to incidents more quickly. However, the same capabilities can create new attack…
Ready to discover game-changing GRC tech?
Contact the team and request your demo today.
This form may not be visible due to adblockers, or JavaScript not being enabled.