Why the three letters belong together
Governance sets the appetite and the accountability; risk management measures exposure against that appetite; compliance proves that the controls the risk analysis asked for actually operate. Run apart, the three drift: the register scores a risk the audit never checks, the audit certifies a control no risk asked for, and the board reads a report that neither produced. Cyber-GRC keeps them on the same facts, so a change in one moves the other two. The register, the audit and the board then read one posture, and disagree about nothing the evidence has already settled.
What changed with NIS2 and DORA
The European texts turned Cyber-GRC from a good practice into a legal design. NIS2 makes management bodies responsible for approving and overseeing risk-management measures; DORA asks financial entities to keep ICT risk, incident reporting, resilience testing and third-party risk in one framework. Both expect proof of effectiveness, not a documented intention. A GRC that produces PDFs once a year cannot answer them; one that verifies continuously can.
From declarations to verification
The historical GRC tool is a form: questionnaires, attestations, screenshots filed as evidence. The current generation replaces the declaration with the verified fact: a control status computed from live evidence, a supplier grade that moves with its signals, a risk score that inherits the residual risk of its controls. That is the shift Mindlapse builds on, and the one the glossary’s other terms describe piece by piece.