What is GRC and operational risk?

GRC stands for Governance, Risk and Compliance – the discipline of running an organisation in a controlled, evidenced way. Operational risk is the sub-domain concerned with risks from internal processes, people, systems and external events.

What is a risk register?

A risk register is the structured list of identified risks an organisation is tracking – with severity, likelihood, owner, treatment and review date.

What are controls and criteria?

In a risk framework, controls are the things you do to mitigate a risk. Criteria are the conditions a control must satisfy to be considered effective.