The History and Evolution of Governance, Risk and Compliance (GRC)

September 10, 2026

Discover Symbiant risk register software for UK organisations. Configure registers, automate reviews, link controls and actions, and improve risk reporting.

How governance, risk management and compliance developed into a connected organisational discipline

Governance, risk management and compliance (GRC) shape how organisations make decisions, protect their resources and meet their responsibilities. Governance establishes direction and accountability. Risk management considers uncertainty in pursuing objectives. Compliance addresses the obligations that arise from laws, regulations and other commitments. GRC brings these activities together so that decisions in one area inform the others. 1

The history of GRC stretches well beyond the acronym. It reflects decades of development in corporate reporting, internal control, professional practice and technology. Its evolution is best understood as a gradual effort to connect information and responsibility across organisations, accelerated at different points by corporate failures, financial crises and changing expectations of business.

The foundations before the GRC acronym

Modern GRC inherited much from earlier efforts to make companies accountable. In the United States, the Securities Act of 1933 strengthened disclosure requirements for securities offerings, while the Securities Exchange Act of 1934 created the Securities and Exchange Commission and established an enduring framework for securities markets and company reporting. These were early milestones in the development of the regulatory environment within which many businesses operate today.2

Professional disciplines were also developing long before GRC became a recognised label. The Institute of Internal Auditors was founded in 1941, reflecting the growing importance of a profession concerned with examining organisations’ activities and controls. Boards, finance teams, auditors, lawyers and insurance specialists brought different forms of oversight to business, each with its own responsibilities and methods.3

The US Foreign Corrupt Practices Act of 1977 added another important connection. Alongside its anti-bribery provisions, it required covered companies to keep accurate books and records and maintain adequate internal accounting controls. Ethical conduct, reliable information and effective control were therefore linked within legislation decades before they were commonly discussed under a GRC heading.4

The 1990s and the development of governance and control frameworks

The 1990s gave organisations more explicit frameworks for governing and controlling their activities. In the UK, the Cadbury Report, published in December 1992, examined the financial aspects of corporate governance. Its recommendations addressed board effectiveness, the roles of executive and non-executive directors, audit committees and the relationship between the chair and chief executive. It helped establish the expectation that the way a company was directed deserved scrutiny alongside its financial results.5

In the same year, the Committee of Sponsoring Organizations of the Treadway Commission, known as COSO, issued its Internal Control — Integrated Framework. It gave organisations a structured basis for understanding and evaluating internal control. This helped move the discussion beyond individual checks towards the effectiveness of the wider arrangements through which an organisation pursued its objectives.6

The Turnbull Report followed in September 1999, providing guidance on internal control for UK-listed companies. Together, these developments made governance, risk and control more closely related boardroom concerns. They also exposed a practical difficulty: directors needed reliable information about activities carried out across multiple teams, often using different processes and reporting systems.

From separate records to shared information

The tools used to support these activities changed unevenly. Paper files and manual registers existed alongside spreadsheets, databases and specialist applications. There was no single moment when all organisations moved from one method to another. Their choices depended on size, sector, resources and the complexity of the work.

Each tool could serve its immediate purpose. A spreadsheet could hold a risk register; an audit application could record findings; a compliance team could maintain its own schedule of obligations. The difficulty arose when management needed to understand how these records related to one another. Separate systems could obscure the connections between an identified risk, a weak control and an overdue corrective action.

For example, an audit finding about poor access controls might concern a risk already recorded by the IT team and an obligation tracked by compliance. Without shared references and clear ownership, the same issue could be recorded several times and reported differently. Staff then had to reconcile the records before leaders could judge its significance. This coordination problem explains much of the appeal of integrated GRC.

The early 2000s and the emergence of integrated GRC

A major regulatory milestone came on 30 July 2002, when the Sarbanes-Oxley Act became law in the United States. Its reforms addressed corporate responsibility, financial disclosure and accounting oversight, including the creation of the Public Company Accounting Oversight Board. It reinforced the importance of dependable reporting and the arrangements supporting it.

Sarbanes–Oxley formed part of a wider movement towards stronger accountability, more dependable information and demonstrable control. At the same time, technology was beginning to change how organisations gathered and managed risk information.

2002 and Symbiant’s pioneering collaborative SaaS platform

Symbiant’s development history places it within this formative period. In response to the practical challenges organisations faced following the Turnbull Report, the UK software company developed the Symbiant Risk Suite: a web-based platform designed to help organisations identify, assess, monitor and report risks across the enterprise. In 2002, it was combined with Symbiant Tracker, its audit action-tracking tool. The resulting online solution brought together risk registers, risk workshops, incident reporting, assessments, key risk indicators, questionnaires and audit action tracking.

Symbiant identifies this release as the first collaborative software-as-a-service (SaaS) GRC solution. What distinguished the platform was its collaborative design. Using the internet and company intranets, it enabled responsibility and ownership for risk to be distributed to people across the organisation, rather than leaving the process in the hands of a single risk manager or system administrator. Management retained greater oversight, while input from multiple participants provided a broader, consensus-based view of risk.

The significance of this development also lay in how that collective information could be connected and used. Risk information and audit follow-up could be managed within a shared online environment, giving managers a broader view of emerging issues, different perspectives on their significance and the work undertaken to address them. An account published by Business Reporter highlighted the platform’s ability to produce holistic management reports and make previously disconnected information more visible.

The approach was subsequently recognised by ICAEW. Following its evaluation of the platform, the Symbiant Risk Suite and Audit Tracker became the first software products to receive ICAEW endorsement. ICAEW’s then Chief Executive, Michael Izza explained that the software addressed many of the practical risk management and control issues organisations encountered when implementing the principles of the Turnbull Report. This remains a unique distinction: no other software products have received the same ICAEW endorsement.

For organisations, the platform addressed two closely related obstacles: risk management being concentrated in the hands of one person and relevant information being dispersed across different teams and systems. It brought operational staff, risk specialists and auditors into connected processes, with access to related information and clearly assigned responsibilities. Its SaaS model also allowed the application to be delivered as a hosted service and accessed online. Symbiant’s early work therefore illustrates how collaborative risk management developed into practical technology supporting participation, collective insight, connected reporting, accountability and follow-through.

2002–2004 and the emergence of the GRC name

While platforms such as Symbiant were beginning to connect risk and audit processes in practice, OCEG was developing a common concept and vocabulary for the disciplines involved. The GRC concept and acronym were originated by OCEG, the organisation founded by Scott Mitchell in 2002. The acronym provided shorthand for governance, risk and compliance capabilities that needed to work together rather than operate as isolated functions.

OCEG framed the purpose of GRC around Principled Performance: the ability to “reliably achieve objectives, address uncertainty, and act with integrity”. This gave GRC a broad organisational purpose, connecting the pursuit of business objectives with the management of uncertainty and the standards of conduct expected along the way.⁹

In 2004, OCEG released its first GRC Capability Model, commonly known as the Red Book, formally documenting its integrated approach. This distinction matters: the organisational practices and supporting technology were developing alongside the terminology through which the field would later be understood.¹¹

2004 to 2009 and the formalisation of common approaches

During the rest of the decade, organisations gained more developed models for bringing these disciplines together. COSO published its Enterprise Risk Management — Integrated Framework in 2004, extending its body of guidance into a broader approach to risk.

The development also reached academic publication. The paper GRC360: A framework to help organisations drive principled performance appeared online in the International Journal of Disclosure and Governance in October 2007. It discussed performance in terms of both financial and non-financial objectives and the boundaries within which an enterprise pursued them.12

In November 2009, the first edition of ISO 31000 provided internationally applicable principles and guidelines for risk management. Its scope extended across sectors and organisational activities, with an emphasis on adapting the approach to the organisation’s circumstances.13

These frameworks served related purposes. COSO offered structured approaches to internal control and enterprise risk management; ISO 31000 provided general risk management guidance; OCEG addressed the coordination of GRC capabilities. An organisation could draw on several of them. The practical task was to establish consistent responsibilities, processes and information that worked in its own context.

The financial crisis and the expansion of GRC in the 2010s

The financial crisis of 2007–09 gave renewed urgency to questions about risk, governance and oversight. In the United States, the Dodd-Frank Act became law in July 2010. Internationally, the Basel Committee developed Basel III in response to the crisis, with the initial capital framework published in December 2010. The reforms sought to strengthen banking regulation, supervision and risk management.14

The relevance to GRC extended beyond producing additional reports. These developments strengthened the case for understanding concentrations of risk, the quality of controls and the way exposures could interact. For affected organisations, meeting new expectations required cooperation among finance, risk, compliance, operations and senior management.

Established frameworks also continued to evolve. COSO refreshed its internal control framework in 2013 and, in 2017, issued Enterprise Risk Management, Integrating with Strategy and Performance. The latter explicitly connected risk considerations with strategy setting and organisational performance. ISO 31000’s 2018 revision likewise described how risk management could be embedded in governance, planning, reporting and organisational culture.

Taken together, these changes show why GRC’s development cannot be explained solely as a response to more regulation. The frameworks increasingly articulated how risk and control information could support choices about direction, investment and acceptable uncertainty. For management, the value depended on whether that information improved decisions.

Cloud delivery, data protection and a wider remit

Software development supported this broader view. Hosted applications, shared records and connected modules gave organisations ways to coordinate work across departments and locations. The important change was the ability to connect related activities: a control assessment could inform a risk review, an incident could trigger an investigation, and an action could remain visible until someone had addressed it.

Symbiant continued to redevelop its platform as technology advanced and customer requirements evolved. Its modular approach brought risk, controls, incidents, assessments, business continuity and audit together through shared information. This allowed organisations to select the capabilities they needed while preserving the connections between the underlying records.

Data protection became another major concern. The EU General Data Protection Regulation was adopted in 2016 and became applicable on 25 May 2018. Its arrival sharpened the practical need to understand how personal data moved through an organisation and its external relationships.16

Consider a service that depends on an external provider handling customer information. Understanding that arrangement may involve legal obligations, information security, supplier assessment, incident management and business continuity. A connected GRC approach allows those perspectives to inform the same management decision. The example illustrates why the scope of the work can extend far beyond the finance function.

The 2020s and the growing focus on resilience and emerging technology

Operational resilience brought service continuity and the consequences of disruption into sharper focus. The UK Financial Conduct Authority published its final operational resilience rules in March 2021; they came into force on 31 March 2022. Firms within scope had until 31 March 2025 to ensure that important business services could operate within their impact tolerances, supported by mapping, testing and improvements.17

These expectations connect activities that can otherwise be treated separately. Understanding whether an important service can withstand disruption requires knowledge of its people, processes, technology and external dependencies. Assessments, incidents, continuity plans and outstanding actions therefore become relevant to the same question: how much disruption can the organisation absorb without causing unacceptable harm?

Artificial intelligence has added another area requiring coordinated oversight. NIST released its voluntary AI Risk Management Framework on 26 January 2023, addressing risks and trustworthiness considerations in the design, development, use and evaluation of AI systems. Its publication demonstrates how established risk management ideas continue to be adapted to emerging technologies.18

For GRC teams, such developments introduce new subjects while retaining familiar responsibilities. Someone must understand the objective, assess the uncertainty, decide what controls are appropriate and review the evidence as circumstances change. As organisations adopt new technology, clear ownership and informed judgement remain essential.

Demonstrating that controls work

Recent UK corporate governance developments continue this longer history of accountability. The 2024 UK Corporate Governance Code applies to financial years beginning on or after 1 January 2025, with the revised Provision 29 applying to financial years beginning on or after 1 January 2026. Under the Code’s comply-or-explain approach, boards of companies within scope are asked to declare the effectiveness of their material internal controls.

This puts the quality of supporting evidence into focus. A list of controls provides a starting point; assessments, monitoring, identified weaknesses and corrective actions help a board judge how those controls perform. The practical implication is a need for a traceable relationship between material risks, the controls addressing them and the information used to assess effectiveness.

GRC as a continuing organisational capability

The progression from early reporting rules to modern GRC frameworks reveals a consistent concern: how can an organisation know whether it is being directed responsibly, managing uncertainty effectively and meeting its obligations? Over time, the methods have become more structured and the information more connected. The need for accountability has endured.

For technology, this history provides a useful measure of value. A GRC platform should help people relate objectives to risks, connect controls with evidence, identify who owns an issue and follow actions through to completion. Symbiant’s catalogue describes these relationships across its modules, including links between business objectives and risks and between incidents and the risks they reveal.

The next stage of GRC will continue to be shaped by regulation, changing business models and new technology. Its effectiveness will depend on how well organisations turn those developments into informed decisions and coordinated action. Frameworks provide structure, software supports the work, and people remain responsible for the judgement and conduct on which good governance depends.

Sources

1. OCEG. What is GRC (Governance, Risk, and Compliance)?

2. U.S. Securities and Exchange Commission, Investor.gov. The Laws That Govern the Securities Industry.

3. The Institute of Internal Auditors. About The Institute of Internal Auditors.

4. U.S. Department of Justice. Foreign Corrupt Practices Act Unit — An Overview. Updated 18 August 2026.

5. Committee on the Financial Aspects of Corporate Governance. Report of the Committee on the Financial Aspects of Corporate Governance. December 1992.

6. COSO. Internal Control — Integrated Framework.

7. ICAEW. Internal Control: Guidance for directors on the Combined Code.

8. OCEG. About OCEG.

9. OCEG. What is Principled Performance?.

10. COSO. About Us.

11. OCEG. Celebrating 20+ years of OCEG. Undated organisational timeline.

12. Scott L. Mitchell. GRC360: A framework to help organisations drive principled performance.

13. International Organization for Standardization. ISO 31000:2009 — Risk management — Principles and guidelines.

14. Basel Committee on Banking Supervision, Bank for International Settlements. Basel III: international regulatory framework for banks.

15. International Organization for Standardization. ISO 31000:2018 — Risk management — Guidelines.

16. European Commission. Legal framework of EU data protection.

17. Financial Conduct Authority. Operational resilience.

18. National Institute of Standards and Technology. AI Risk Management Framework. Undated overview; framework released 26 January 2023.

19. Financial Reporting Council. UK Corporate Governance Code 2024. Code published 22 January 2024

Put connected GRC into practice with Symbiant

Connect risks, controls, incidents, audits and actions in one configurable platform. Give your teams a single source of truth and your decision-makers a clearer view of what needs attention, who is responsible and how improvements are progressing.

Discover Symbiant's AI-Assisted Governance, Risk Management, Compliance (GRC) and Audit Management Software. Affordable, agile, fully customisable.