SECAI Core · phase 8 of 15
Governance, Risk, and Compliance
An integrated approach that aligns an organization's direction and accountability (governance), the identification and treatment of threats to its objectives (risk), and its adherence to laws, regulations, and internal policies (compliance), applied to AI systems across their lifecycle.
The Explain card
- Plain English
- Governance, Risk, and Compliance (GRC) is how an organisation sets direction and accountability (governance), identifies and manages threats to its objectives (risk), and proves it meets laws, standards and internal rules (compliance).
- Example
- A bank rolling out an AI fraud model uses GRC to define who owns the model, assess the risk of biased or manipulated decisions, map it against the EU AI Act and internal policy, and keep the evidence an auditor would ask for.
- Why it matters
- AI security controls only stick when anchored in ownership, risk appetite and regulatory obligation. GRC is the scaffolding that holds the technical work up.
- Hook
- Who decides, what could go wrong, and can we prove we did it right.
Where it sits in the deck
Phase 8: Governance, Risk, and Compliance Frameworks
Individual controls need a governance envelope — introduce the risk and compliance structures, standards bodies, and regulations that frame AI accountability at scale.