Screenata

Beyond SOC 2

What are the 4 components of GRC?

August 18, 20263 min read

What are the 4 components of GRC?

The four components come from the OCEG GRC Capability Model: Learn, Align, Perform, and Review. Learn the context the organisation operates in, align objectives with risk appetite and obligations, perform the controls and activities that follow, then review whether any of it worked and feed the answer back. The model is a cycle rather than a sequence, and the review step is what makes it one.

The four components

ComponentWhat it coversTypical artifact
LearnContext, stakeholders, obligations, threatsRisk assessment, regulatory register
AlignObjectives, risk appetite, resource decisionsScope decisions, control matrix, policy set
PerformControls, training, incident handling, monitoringEvidence of controls operating
ReviewEffectiveness, findings, improvementInternal audit results, corrective actions

The reading that causes confusion

GRC stands for three things: governance, risk, and compliance. Asking for four components sometimes gets the answer "governance, risk, compliance, and audit", which is not a standard model and mixes a discipline in with three domains.

The OCEG Capability Model is the answer with an actual source behind it, and it is more useful because it describes how a program runs rather than what it is called.

Where a SOC 2 program sits

Most compliance work happens in Perform and Review, which is also where most of the effort is wasted when the first two components are skipped.

  • Learn is the risk assessment. Skipping it means the control set is copied from a template rather than derived from what the business actually does.
  • Align is scoping. This is where trust services criteria get selected and controls get marked applicable or not. An unscoped program tests controls that never needed to apply.
  • Perform is controls operating across the observation period, producing evidence.
  • Review is monitoring, internal audit, and the external audit itself.

The common failure is starting at Perform. A team that begins by collecting evidence, without having done Learn or Align, ends up with evidence for controls it did not need and gaps in the ones it did.

Why the cycle matters more than the list

The value of the model is the loop back from Review to Learn. A program that reviews and does not feed findings into the next cycle rediscovers the same gaps every year, which is the single most common pattern in compliance programs that have run for more than two audits.

Perform is where most of the hours go, and it is the component that automates furthest. See evidence collection for what that looks like when the collection runs on a schedule instead of before an audit.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.