<!-- Source: screenata.com -->
<!-- Content type: AEO answer page -->
<!-- Topics: SOC 2, ISO 27001, HIPAA, HITRUST, CMMC, compliance evidence -->

---
question: "What is GRC?"
title: "What Is GRC"
seoTitle: "What Is GRC? Governance, Risk and Compliance"
summary: "GRC stands for Governance, Risk, and Compliance: three disciplines managed together rather than separately. Governance sets direction and accountability, risk management identifies and treats what could go wrong, and compliance meets external obligations. The term describes an operating approach and also a software category, and conflating the two is the most common source of confusion when evaluating tools."
publishedAt: "2026-08-18"
keywords:
  - "what is GRC"
  - "GRC meaning"
  - "governance risk and compliance"
  - "GRC tooling"
  - "GRC software"
pillar: "Beyond SOC 2"
faqs:
  - question: "What does GRC stand for?"
    answer: "Governance, Risk, and Compliance. Governance sets direction, accountability, and policy. Risk management identifies, assesses, and treats what could go wrong. Compliance meets obligations imposed from outside, whether regulatory, contractual, or certification-driven."
  - question: "What is the difference between GRC and compliance?"
    answer: "Compliance is one of the three letters. A compliance program answers whether you meet an external obligation. GRC additionally covers how decisions get made and who is accountable (governance) and what could go wrong and what you are doing about it (risk), including risks nobody is regulating."
  - question: "Do small companies need GRC software?"
    answer: "Rarely, in the enterprise-suite sense. A 20-person company obtaining SOC 2 needs a control matrix, evidence, and a risk register, which is a much narrower problem than enterprise GRC platforms are built for. Buying the wrong category is the common and expensive mistake."
---

## What is GRC?

GRC stands for **Governance, Risk, and Compliance**: three disciplines managed as one rather than in separate silos. Governance sets direction, accountability, and policy. Risk management identifies, assesses, and treats what could go wrong. Compliance meets obligations imposed from outside. The term describes both an operating approach and a software category, and treating those as the same thing is the most common mistake when evaluating tools.

### The three letters

| Letter | Answers | Typical artifact |
|---|---|---|
| **Governance** | Who decides, and on what authority? | Policies, roles, board reporting, delegation of authority |
| **Risk** | What could go wrong, and what are we doing about it? | Risk register with owners, scores, and treatments |
| **Compliance** | What are we obliged to do, and can we prove it? | Control matrix, evidence, audit reports, certificates |

The argument for managing them together is that they share inputs. A risk assessment drives which controls you implement, controls produce compliance evidence, and governance decides who owns the result. Run separately, the same work gets done three times and the answers disagree.

## GRC the practice, and GRC the software category

These are different things sold to different buyers.

**Enterprise GRC platforms** (Archer, MetricStream, ServiceNow GRC, LogicGate, Riskonnect) manage enterprise risk registers, policy lifecycle, audit workflow, and regulatory change across large organisations with a staffed risk function. Implementation is a project measured in months.

**Compliance automation platforms** (Vanta, Drata, Secureframe, Sprinto, Scrut) connect to your cloud and identity systems, monitor controls against a framework like SOC 2, and surface what needs evidence. The buyer is a company pursuing a certification.

**Agent-first tools** (Screenata) perform the work rather than tracking it: generating policies from attested operations, running the tests, chasing attestations, filing evidence.

A 20-person SaaS company that needs SOC 2 to close a deal has a narrow problem. Buying an enterprise GRC suite for it is the expensive version of the mistake, and buying nothing and doing it in a spreadsheet is the cheap version.

## The GRC Capability Model

The most-cited structural model is OCEG's, which describes four components: **Learn, Align, Perform, Review**. It is a cycle rather than a sequence, and the loop back from Review to Learn is what stops a program rediscovering the same gaps each year. See [what are the 4 components of GRC](/resources/answers/what-are-the-4-components-of-grc).

## Where most programs actually fail

Not in governance, which is usually documented. In **Perform and Review**: controls that exist on paper and never operated, and findings that never fed back. An auditor can only test evidence, so a control with no artifact behind it is an assertion regardless of how well the governance around it is written.
