article thumbnail

IRM, ERM, and GRC: Is There a Difference?

Reciprocity

Although organizations have always engaged in governance, risk management, and compliance in one form or another, the term “GRC ” seems to have been coined by risk consultant Michael Rasmussen, the “GRC Pundit,” in 2002. Rasmussen sees the GRC development timeline as follows: GRC 1.0