Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

2.1.5. Governance, Risk, and Compliance (GRC)

💡 First Principle: GRC names three activities that must work together for an organization's compliance posture to mean anything — governance sets the policies and who's accountable for them, risk management identifies and prioritizes what could go wrong, and compliance verifies that reality actually matches the policy — and removing any one of the three breaks the whole cycle.

Without governance, there's no agreed-upon policy to measure against. Without risk management, effort gets spent evenly across all controls instead of prioritized toward the highest-impact gaps. Without compliance verification, an organization has policies and priorities but no evidence they're actually being followed. Microsoft Purview's Compliance Manager (Phase 5) is essentially a GRC tool: it holds assessments (governance), highlights gaps by impact (risk), and tracks completed improvement actions with a score (compliance verification) — all three activities in one workflow.

⚠️ Exam Trap: GRC is not one activity with three names — it's three distinct, interdependent activities. A scenario testing "which GRC component is missing" expects you to identify specifically whether it's a policy gap, a prioritization gap, or a verification gap.

Reflection Question: An organization has clear security policies and a documented risk register, but has never audited whether employees actually follow the policies. Which GRC component are they missing?

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder18 professional certifications