Terminology Index
Glossary
33 terms starting with "G"
Showing 1-32 of 33 terms
GRC Analyst
A practitioner who carries out governance, risk, and compliance work, running risk assessments, mapping and testing controls, maintaining evidence, supporting audits, and tracking findings, to keep an organization's GRC program functioning.
The GRC analyst is the hands-on role at the center of governance, risk, and compliance: they translate frameworks and policy into operating controls, assess and document risk, gather evidence, coordinate audits, and shepherd findings to closure. It is a role heavy on coordination, documentation, and cross-functional communication, sitting in the second line of defense, advising and overseeing rather than owning the controls the business runs. It is a common entry point into the GRC field.
Introduced in: GRC Analyst Fundamentals
Examples
- Running a risk assessment and updating the risk register.
- Mapping controls to a framework and testing whether they operate.
- Coordinating an audit and tracking the resulting findings.
No related terms linked yet.
