GRC · Governance · Control functions

GRC: what the acronym really covers

The acronym CRM is everywhere — in software offers, job titles, board presentations. Yet it rarely refers to the same thing from one person to another. Clarifying what it covers is not a semantic exercise: it is what distinguishes a system that truly structures the organisation from a disjointed stack of tools.

Category: Governance Reading time: 8 minutes

GRC stands for governance, risk and compliancegovernance, risk and compliance). Beyond this obvious fact, usage is fluid. Three confusions regularly crop up.

An ability

Not a department, not a piece of software

Three dimensions

Governance, risk management, compliance

Everyone

Nobody has exclusive ownership of business advisory services.

01

An acronym used for three different things

The first consists of treating the GRC as a risk management. That is oversimplifying: risk management is only one of the three dimensions, and GRC does not replace it — it integrates it into the pursuit of the organisation's objectives.

The second one makes one compliance matter. This reading can be explained historically, as a portion of the foundational work originated in the field of compliance, but it strips the concept of its strategic dimension.

The third, which is the most widespread in organisations, reduces GRC to a IT subject — often because the initial contact with the term was through software. Yet no single tool in itself constitutes a CRM arrangement.

02

A definition that fits into three verbs

The most operational definition, stemming from the work of the OCEG (Open Compliance and Ethics Group), organisation at the origin of the formalisation of the concept, describes GRC as a capacity enabling an organisation to reliably achieve its objectives, address uncertainty and act with integrity.

Each term corresponds to a dimension:

  • Governance - reliably achieve the right objectives: define them, manage them, and report on them.
  • Risks — manage uncertainty: identify what could affect these objectives, and take justified risks rather than shunning them.
  • Compliance - act with integrity: respect applicable obligations and the values the organisation has adopted.
What this definition changes: GRC is not a control exercised over the activity, but a capability in the service of performance. It does not ask «have we complied with the rules?», but «are we in a position to achieve our objectives, knowingly and with integrity?»
03

A capability, not a department

From this definition stems an important practical consequence: CRM does not embody itself in a department. Creating a «GRC department» that would absorb existing functions is a contradiction in terms, and a source of inefficiency.

GRC actually spans the entire organisation. The board of directors participates when setting the direction and risk appetite. Management, when making trade-offs. Control functions — compliance, risk management, internal control — when providing oversight. Internal audit, when providing independent assurance. Legal, IT, human resources, finance, and above all the business lines themselves, all contribute at their own level.

This also invites caution regarding job titles. A compliance officer, a risk manager or an internal auditor perform distinct jobs, with different independence requirements. Grouping them under the generic label of «GRC professionals» blurs boundaries that regulations carefully maintain — particularly within the regulated financial sector.

04

The real contribution of the concept: orchestration

If GRT is neither a department nor a tool, what is left? The most important thing: the idea that these activities, historically organised in silos, must operate in a coordinated manner.

The situation is familiar in many organisations. Compliance maintains its own tracking tables. Risk management maintains its mapping. Internal control documents its controls elsewhere. Internal audit formulates recommendations in a third repository. Each function requests the same operational teams, with similar requests and different formats. No one has the big picture.

Orchestration consists of ensuring that these functions share a common understanding of objectives, risks and obligations — and that the right people receive the right information at the right time. It does not involve merging teams, but linking their work.

A simple indicator: Ask three control functions to name the organisation's five major risks. If the lists diverge significantly, the problem is not with their skills — it is the lack of orchestration.

Once this orchestration has been defined, tooling can facilitate its execution. A common environment makes it possible, amongst other things, to link risks, controls, documents, recommendations and action plans, whilst maintaining the traceability required to manage the framework.

05

What GRC means for a regulated Luxembourg entity

For industry stakeholders, the question is not about adopting an additional concept: the components of GRC are already in place, often because regulations require them. A compliance function, a risk management function, an internal control system, an independent internal audit function: these are all elements expected by the internal governance framework applicable to entities regulated by the Commission de Surveillance du Secteur Financier (CSSF).

The issue is therefore shifting. It is not a matter of creating, but of connect — and to demonstrate this consistency. Three expectations converge in this direction:

  • Consistency — a supervisor questioning the system expects consistent responses from one function to the next, not three versions of the same subject.
  • Traceability decisions, approvals and corrective actions must be traceable; assertion is not enough, proof is expected.
  • Proportionality — the arrangement is assessed with regard to the size, risk profile and complexity of the entity, rather than according to a single model.
06

Common pitfalls

  • Confusing the tool with the device. Software structures data and streamlines a process; it does not set objectives, arbitrate or replace professional judgment.
  • Create a mega-department. Grouping functions under a single authority undermines the independence that the regulatory framework protects.
  • Reducing GRC to compliance. This results in a defensive setup, disconnected from strategy and perceived as a blocker by the business lines.
  • Increase the number of requests from the business areas. Without coordination, each function separately queries the same teams — the setup ends up being more of a burden than a benefit.
  • Neglecting the «objectives» dimension. A GRC that is not connected to what the organisation is trying to achieve loses its raison d'être.
07

The ARCAD approach

ARCAD approaches GRC as a capability to be structured, not as a product to be installed. The approach starts with the organisation's objectives and risk profile, then connects existing mechanisms — compliance, risk, internal control, internal audit — rather than piling them on top of one another. The tooling comes afterwards, once the method is established: it is in this order that it produces results.

Structure your GRC framework on clear foundations.

ARCAD supports Luxembourg regulated entities in aligning their control functions.

Schedule an exchange →

References & further reading

  • OCEG works (Open Compliance and Ethics Group) on the definition and capabilities of the CRM.
  • Global Internal Audit Standards and the Three Lines Model, Institute of Internal Auditors (IIA).
  • Internal governance framework applicable to CSSF-regulated entities.

Note: Good practice to be adapted to the profile, size and regulatory framework specific to each organisation.