In late 2017, John Wheeler, Gartner's Global Research Leader for Risk Management Technology, claimed that Governance, Risk, and Compliance (GRC) had become obsolete. In a blog, he announced that Gartner would shift its focus from GRC to Integrated Risk Management (IRM).
What Is the Difference Between IRM and GRC?
GRC is a structured approach that aligns governance, risk management, and compliance activities to help organizations meet objectives while addressing uncertainty and acting with integrity. IRM is a set of practices and processes supported by a risk-aware culture and enabling technologies that improves decision making and performance through an integrated view of how well an organization manages its unique set of risks. Gartner defines IRM using this framework, and the research firm predicted that the number of large enterprises using an IRM solution set would rise from 30% in 2017 to 50% by 2021.
Wheeler believes IRM can shift from GRC’s compliance focus to an analysis of how risk affects all business operations. However, IRM and GRC share significant overlap, and organizations with mature GRC programs that include a complementary enterprise risk management (ERM) focus may already be achieving IRM objectives. ERM is the quantifiable process of identifying, assessing, and managing risks across an entire organization to support strategic decision-making.
IRM vs. GRC: Key Differences
| Dimension | GRC | IRM |
|---|---|---|
| Primary Focus | Compliance and governance | Risk-aware decision making |
| Approach | Conceptual framework for policies and controls | Integrated, data-driven risk analysis |
| Champ d'application | Regulatory requirements and internal policies | Enterprise-wide risk across all operations |
| Business Outcome | Meeting compliance obligations | Improved performance through risk insights |
Faut-il passer du GRC à l'IRM ?
The increasing emphasis on Big Data and the Internet of Things (IoT), as well as globalization and the growing utilization of third-party vendors, are all motivations for concern over organizational risks. A GRC program—when combined with ERM—is capable of managing these evolving risks effectively.
Bien que les objectifs de la GRC et de l'ERM soient les mêmes, les approches sont traditionnellement très différentes. La GRC est davantage une approche conceptuelle des questions de gouvernance et de conformité. En revanche, l'ERM est le processus quantifiable de mesure des risques.
Many organizations struggle when combining several different platforms to meet compliance and risk needs. A solution that rests at the intersection of both addresses this challenge. While Gartner says prioritizing compliance can hurt risk management, the right ERM-GRC solution can help your organization focus on both.
Combiner GRC et ERM en une seule solution
More organizations are turning to adaptable, configurable, and intuitive ERM-GRC solutions to meet the needs of integrated risk management. The best of these allow them to master compliance and risk with fully integrated and turnkey functionality.
Their policies and controls can be linked to federal and state laws, guidelines, and compliance requirements within an ERM-GRC system that has compliance policy management features. These supply a central hub to manage policies, procedures, and enterprise documentation for regulatory, legal, and compliance requirements as well as audits and examinations.
Le logiciel ERM-GRC offre une solution pour l'environnement de risque et de conformité d'une organisation, quel que soit l'acronyme utilisé. Une organisation peut prendre un contrôle plus ferme grâce à une combinaison équilibrée dans un cadre structuré.
Se défendre contre les risques liés aux fournisseurs et à l'entreprise
Learn about our best-in-class VRM/ERM solutions. Contact Us
Principaux enseignements
- IRM and GRC are complementary approaches; IRM emphasizes risk-aware decision making while GRC focuses on compliance and governance.
- Organizations do not need to abandon GRC—combining GRC with ERM achieves many IRM objectives.
- An integrated ERM-GRC solution provides a central hub for managing policies, compliance, and enterprise-wide risk.
- The right solution balances compliance requirements with strategic risk management within a structured framework.
