SECAI Core · phase 8 of 15 · noun
Governance, Risk, and Compliance
An integrated approach that aligns an organization's direction and accountability (governance), the identification and treatment of threats to its objectives (risk), and its adherence to laws, regulations, and internal policies (compliance), applied to AI systems across their lifecycle.
The Explain card
- Plain English
- Governance, Risk, and Compliance (GRC) is how an organization sets direction and accountability (governance), identifies and manages threats to its objectives (risk), and proves it meets laws, standards and internal rules (compliance).
- Example
- A bank rolling out an AI fraud model uses GRC to define who owns the model, assess the risk of biased or manipulated decisions, map it against the EU AI Act and internal policy, and keep the evidence an auditor would ask for.
- Why it matters
- AI security controls only stick when anchored in ownership, risk appetite and regulatory obligation. GRC is the scaffolding that holds the technical work up.
- Hook
- Who decides, what could go wrong, and can we prove we did it right.
Word knowledge
How the word is built, where it came from, and what it sits beside in memory.
In a sentence
The release gate requires a Governance, Risk, and Compliance sign-off that binds the model card, residual-risk score, and EU AI Act evidence to the same ticket.
Why these words
- Governance Old French gouvernance, from Latin gubernare, to steer names the steering half, the oversight the other two words serve
- Risk Italian rischio via French risque, hazard, of uncertain further origin names the hazard half, the exposures the phrase treats as a managed inventory
- Compliance English comply plus -ance, from Latin complere, to fill up names the proof half, the written rules the phrase requires people to meet and show
Where it came from
- Origin
- English business coinage, from Latin gubernare (to steer), Italian rischio via French risque (hazard), and Latin complere (to fill up)
- Entered the language
- c. 2004
- What changed
- Governance had meant the act of ruling, then the machinery of corporate oversight after the 1990s reporting scandals. Risk had meant a sailor's hazard, then a priced financial exposure. Compliance had meant a yielding temperament, then the act of meeting a written rule. A 2004 PricewaterhouseCoopers paper locked the three nouns into one label for a single office and a single platform, and AI teams later borrowed the same three-part name for the work around models.
How it is spelled
- Pattern
- a final y becomes i before -ance, so comply writes compliance
- Pattern
- -ance nouns sit beside -ant adjectives
- Pattern
- the serial comma before and is part of the canonical name
- Breaks the pattern
- the three nouns stay capitalized when they name the function, even mid-sentence
- Breaks the pattern
- risk is a Romance loan that looks native: one syllable, sk, no silent letters
- Breaks the pattern
- Latin gubernare had a b; English govern writes v
Spelled like
- reliance
- government
- compliant
Broken into chunks
-
govern
- government
- governor
- ungovernable
-
ance
- performance
- appearance
- guidance
-
risk
- risky
- riskless
-
com
- complete
- compose
- commit
-
pli
- comply
- compliant
What it sits beside
Same subject
- EU AI Act
- NIST AI Risk Management Framework (AI RMF)
- ISO/IEC 42001:2023
- General Data Protection Regulation
Same shape
- tactics, techniques, and procedures
- people, process, and technology
- confidentiality, integrity, and availability
GRC frameworks
Coordinate triples
- tactics, techniques, and procedures
- confidentiality, integrity, and availability
Steer family
- government
- governor
- cybernetics
Where it sits in the deck
Phase 8: Governance, Risk, and Compliance Frameworks
Individual controls need a governance envelope — introduce the risk and compliance structures, standards bodies, and regulations that frame AI accountability at scale.