Your security and compliance glossary

All the terms you need to know when you’re trying to get compliance audit ready, fast.

Show filters

What is GRC?

Governance, risk and compliance (GRC) refers to a company’s strategy for managing their organization's overall governance, enterprise risk management and compliance with regulations.

Investing in governance, risk, and compliance at your company can have many benefits: better risk analysis, faster decision making, consistent communications, and more efficient risk mitigation across the business.


Using a GRC tool allows you to create and coordinate policies and controls and automatically monitor them, creating efficiencies across your compliance efforts.

{{cta_withimage8="/cta-modules"}}

Additional resources you might like:

Vendor Risk Management
Video
Vanta Delivers: Agent for Risk

The Agent for Risk is your 24/7 GRC engineer for internal risk. It helps risk owners move from surfacing a risk to acting on it.

Vendor Risk Management
Video
Vanta Delivers: Internal Risk

New internal risk capabilities give security and compliance teams real-time confidence in their security posture.

Product updates
Video
Vanta Delivers: TPRM

Third-party assessments have historically meant a lot of manual work. As vendor ecosystems grow and AI tools multiply, that process doesn’t scale. Here’s what’s new in Vanta’s TPRM product to help your team keep up.

Additional resources you might like:

Vendor Risk Management
Video
Vanta Delivers: Agent for Risk

The Agent for Risk is your 24/7 GRC engineer for internal risk. It helps risk owners move from surfacing a risk to acting on it.

Vendor Risk Management
Video
Vanta Delivers: Internal Risk

New internal risk capabilities give security and compliance teams real-time confidence in their security posture.

Product updates
Video
Vanta Delivers: TPRM

Third-party assessments have historically meant a lot of manual work. As vendor ecosystems grow and AI tools multiply, that process doesn’t scale. Here’s what’s new in Vanta’s TPRM product to help your team keep up.

Vendor Risk Management
Blog
The “builder” boom breaking security

Our latest Trust Signals drop explores how builder culture is changing the risk landscape, and what happens when security is still built for a world where only product engineers shipped.

Compliance
Blog
The 9 compliance risks hiding in your organization (and how to fix them)

Learn what compliance risk is and what its most common types are. Find out how to assess and manage your compliance risk and best practices to follow.

Comparisons and reviews
Blog
Top 5 OneTrust alternatives

Check out top OneTrust alternatives for compliance and risk management.

Vendor Risk Management
Blog
GDPR, NIS 2, and DORA converge on one problem: Third-party risk

Discover how EU regulations, GDPR, NIS 2, and DORA, make third-party risk a direct, continuous business liability. Find out why most teams still lack visibility.

Compliance
Events
Auditor basics: A 30 minute guide for startups

In this exclusive live event, we'll cover what audits are, and why continuous compliance separates smooth audits from painful ones.

Product updates
Events
Vanta Delivers: Live from New York

Watch on demand to see new product capabilities and demos, and learn how Vanta is delivering a unified risk experience for GRC teams.