# Governance, Risk, and Compliance (GRC)

A framework aligning an organization's security practices with its policies, risk tolerance, and regulatory obligations.

**Governance, risk, and compliance (GRC)** is a framework for coordinating an organization's overall approach to policy-setting (governance), identifying and managing risk, and meeting relevant legal and regulatory obligations (compliance), so all three work together instead of in silos.

Without a unified GRC approach, security, legal, and business teams can end up duplicating effort or working against each other. GRC platforms and processes help organizations demonstrate to regulators, auditors, and customers that security isn't an afterthought but a managed, ongoing discipline.
