GRC, or Governance, Risk, and Compliance, is a framework that ties together how an organization governs itself, manages its risks, and meets its requirements. It makes sure your policies align with your business goals, that risks are identified and handled, and that you stay in line with the rules that apply to you.

Unlike a specific security tool, GRC is a practice. It brings the business and technology sides together to make decisions with awareness of the risks involved. For many industries, it is the structure that keeps audits, insurance, and customer expectations in order.