GRC stands for Governance, Risk, and Compliance — the practices an organization uses to set direction and make decisions (governance), figure out what could go wrong and how badly (risk), and follow the laws, regulations, and standards that apply to it (compliance). Most companies bundle all three under one team or one person, because in practice they overlap constantly.
Governance: who decides, and how
Governance is the structure behind decision-making — who's accountable for what, how policies get approved, and how the organization checks that its stated goals actually happen. A governance failure looks like: nobody owns a decision, or a policy exists on paper but nobody follows it and no one notices.
Risk: what could go wrong, and how badly
Risk management is identifying what could go wrong (a vendor gets breached, an employee clicks a phishing link, a server isn't patched) and deciding what to do about each one: accept it, reduce it, transfer it (insurance, a vendor contract), or avoid it entirely. The tool most GRC teams use for this is a risk register — a running list of risks scored by how likely they are and how much damage they'd cause.
Compliance: the rules you actually have to follow
Compliance means meeting the specific laws, regulations, and standards that apply to your organization — and being able to prove it, usually to an auditor. Depending on the business, that might mean GDPR (EU data protection law), PCI DSS (a standard for anyone handling card payments), HIPAA (US healthcare data), or a voluntary framework like ISO 27001 or SOC 2 that customers increasingly expect as proof of good security practice — see how those two compare if you're weighing them against each other.
Why these three get lumped together
Because one control usually touches all three at once. Take multi-factor authentication (MFA): governance decides it's mandatory, risk management is the reason it was prioritized (stolen passwords are a top cause of breaches), and compliance is what actually verifies, with evidence, that it's turned on everywhere it's supposed to be. Splitting that into three separate jobs would mean constant hand-offs over the same piece of work — so most organizations don't.
Who does this work
Job titles vary, but the common ones are GRC Analyst, Compliance Analyst, Risk Analyst, and IT Auditor. See what a GRC Analyst actually does day to day for the specifics, how GRC differs from hands-on cybersecurity work if you're weighing the two as a career direction, or a realistic path in with no prior experience.
How GRC relates to ERM and TPRM
GRC doesn't sit in isolation. It's usually the operational layer underneath an organization's broader enterprise risk management (ERM) program — ERM sets the risk appetite at board level, GRC does the tracking and control work underneath it. And within GRC itself, some risk is specialized further: third-party risk management (TPRM) is the sub-practice focused specifically on the risk vendors and suppliers introduce.