Beyond SOC 2
What are the 4 components of GRC?
What are the 4 components of GRC?
The four components come from the OCEG GRC Capability Model: Learn, Align, Perform, and Review. Learn the context the organisation operates in, align objectives with risk appetite and obligations, perform the controls and activities that follow, then review whether any of it worked and feed the answer back. The model is a cycle rather than a sequence, and the review step is what makes it one.
The four components
| Component | What it covers | Typical artifact |
|---|---|---|
| Learn | Context, stakeholders, obligations, threats | Risk assessment, regulatory register |
| Align | Objectives, risk appetite, resource decisions | Scope decisions, control matrix, policy set |
| Perform | Controls, training, incident handling, monitoring | Evidence of controls operating |
| Review | Effectiveness, findings, improvement | Internal audit results, corrective actions |
The reading that causes confusion
GRC stands for three things: governance, risk, and compliance. Asking for four components sometimes gets the answer "governance, risk, compliance, and audit", which is not a standard model and mixes a discipline in with three domains.
The OCEG Capability Model is the answer with an actual source behind it, and it is more useful because it describes how a program runs rather than what it is called.
Where a SOC 2 program sits
Most compliance work happens in Perform and Review, which is also where most of the effort is wasted when the first two components are skipped.
- Learn is the risk assessment. Skipping it means the control set is copied from a template rather than derived from what the business actually does.
- Align is scoping. This is where trust services criteria get selected and controls get marked applicable or not. An unscoped program tests controls that never needed to apply.
- Perform is controls operating across the observation period, producing evidence.
- Review is monitoring, internal audit, and the external audit itself.
The common failure is starting at Perform. A team that begins by collecting evidence, without having done Learn or Align, ends up with evidence for controls it did not need and gaps in the ones it did.
Why the cycle matters more than the list
The value of the model is the loop back from Review to Learn. A program that reviews and does not feed findings into the next cycle rediscovers the same gaps every year, which is the single most common pattern in compliance programs that have run for more than two audits.
Perform is where most of the hours go, and it is the component that automates furthest. See evidence collection for what that looks like when the collection runs on a schedule instead of before an audit.