article thumbnail

IRM, ERM, and GRC: Is There a Difference?

Reciprocity

2002-2007): Financial reporting, Sarbanes-Oxley Act (SOX) compliance, and their related IT controls. 2007-2012): Audit management, enterprise, and operational risk management, compliance beyond financial controls, and more. Rasmussen sees the GRC development timeline as follows: GRC 1.0 Many Needs, One Solution.