<!-- Source: screenata.com -->
<!-- Content type: AEO answer page -->
<!-- Topics: SOC 2, ISO 27001, HIPAA, HITRUST, CMMC, compliance evidence -->

---
question: "What are the 4 components of GRC?"
title: "What Are the 4 Components of GRC"
seoTitle: "The 4 Components of GRC (OCEG Capability Model)"
summary: "The four components of GRC come from the OCEG GRC Capability Model: Learn, Align, Perform, and Review. Learn the context the organisation operates in, align objectives with risk appetite, perform the controls and activities, then review whether any of it worked. The term is also loosely used for governance, risk, compliance and audit, which is a different and less useful reading."
publishedAt: "2026-08-18"
keywords:
  - "4 components of GRC"
  - "GRC capability model"
  - "OCEG GRC model"
  - "learn align perform review"
  - "4 components of GRC capability model"
pillar: "Beyond SOC 2"
faqs:
  - question: "What are the four components of the GRC Capability Model?"
    answer: "Learn, Align, Perform, and Review. OCEG defines them as a cycle: understand the context, align objectives and risk appetite, execute controls and activities, then evaluate and improve. The cycle repeats rather than terminating."
  - question: "Is GRC an acronym for four things?"
    answer: "No. GRC stands for three: governance, risk, and compliance. The four components refer to the OCEG Capability Model, which describes how to operate a GRC program. Some sources add audit as a fourth letter, which is not standard."
  - question: "How does the GRC model relate to SOC 2?"
    answer: "SOC 2 sits mostly in Perform and Review. Align determines which trust services criteria are in scope, Perform is the controls operating across the audit period, and Review is monitoring and the audit itself. Learn is the risk assessment that should precede all of it."
---

## What are the 4 components of GRC?

The four components come from the **OCEG GRC Capability Model**: **Learn, Align, Perform, and Review**. Learn the context the organisation operates in, align objectives with risk appetite and obligations, perform the controls and activities that follow, then review whether any of it worked and feed the answer back. The model is a cycle rather than a sequence, and the review step is what makes it one.

### The four components

| Component | What it covers | Typical artifact |
|---|---|---|
| **Learn** | Context, stakeholders, obligations, threats | Risk assessment, regulatory register |
| **Align** | Objectives, risk appetite, resource decisions | Scope decisions, control matrix, policy set |
| **Perform** | Controls, training, incident handling, monitoring | Evidence of controls operating |
| **Review** | Effectiveness, findings, improvement | Internal audit results, corrective actions |

## The reading that causes confusion

GRC stands for three things: governance, risk, and compliance. Asking for four components sometimes gets the answer "governance, risk, compliance, and audit", which is not a standard model and mixes a discipline in with three domains.

The OCEG Capability Model is the answer with an actual source behind it, and it is more useful because it describes how a program runs rather than what it is called.

## Where a SOC 2 program sits

Most compliance work happens in **Perform** and **Review**, which is also where most of the effort is wasted when the first two components are skipped.

- **Learn** is the risk assessment. Skipping it means the control set is copied from a template rather than derived from what the business actually does.
- **Align** is scoping. This is where trust services criteria get selected and controls get marked applicable or not. An unscoped program tests controls that never needed to apply.
- **Perform** is controls operating across the observation period, producing evidence.
- **Review** is monitoring, internal audit, and the external audit itself.

The common failure is starting at Perform. A team that begins by collecting evidence, without having done Learn or Align, ends up with evidence for controls it did not need and gaps in the ones it did.

## Why the cycle matters more than the list

The value of the model is the loop back from Review to Learn. A program that reviews and does not feed findings into the next cycle rediscovers the same gaps every year, which is the single most common pattern in compliance programs that have run for more than two audits.

Perform is where most of the hours go, and it is the component that automates furthest. See [evidence collection](/product/evidence) for what that looks like when the collection runs on a schedule instead of before an audit.
