Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Category: GRC Governance Frameworks

GRC Capability Model (OCEG Red Book)

Also known as: OCEG Red Book, Red Book, GRC Capability Model, GRC Capability Model 3.5
Simply put

The GRC Capability Model, commonly known as the OCEG Red Book, is a voluntary framework designed to help organizations bring together their governance, risk management, compliance, and ethics activities in a more coordinated way. It offers practices that professionals can use to plan, assess, and improve how these functions work, with the stated aim of achieving what OCEG calls 'Principled Performance.' First released in 2004, it is described by its publisher as an early standard for integrating these disciplines.

Formal definition

The GRC Capability Model (OCEG Red Book) is a framework published by OCEG that provides practices for integrating governance, risk, compliance, and ethics activities across an organization. According to OCEG, the first edition was released in 2004 as an early GRC standard, and the model has since evolved through subsequent versions, including version 3.5. It is intended to help GRC professionals plan, assess, and improve their GRC capabilities in pursuit of OCEG's concept of 'Principled Performance.' Certain premium editions include supplementary materials such as a Tools & Techniques Appendix. As a voluntary framework rather than a binding legal requirement, its adoption and application vary by organization; specific version content, edition features, and any detailed practice requirements should be verified against the primary OCEG source, as framework language evolves across editions.

Why it matters

Organizations frequently develop governance, risk management, compliance, and ethics activities in isolation, with separate teams, tools, and reporting lines that do not communicate effectively. This fragmentation can lead to duplicated effort, gaps in coverage, and inconsistent information reaching decision-makers. The GRC Capability Model (OCEG Red Book) matters because it offers a structured, voluntary framework for coordinating these traditionally siloed disciplines, giving professionals a common reference point for how integrated governance, risk, compliance, and ethics activities can work together.

As described by its publisher OCEG, the framework was first released in 2004 as an early standard for integrating these disciplines, and it frames its purpose around the concept of 'Principled Performance.' For GRC professionals, having a named model to plan, assess, and improve their capabilities can support more consistent conversations across functions and with leadership about how mature their combined governance, risk, compliance, and ethics practices are, and where improvement may be warranted.

Because the model is a voluntary framework rather than a binding legal requirement, it does not by itself create obligations or guarantee compliance with any law or regulation. Its value lies in providing a shared vocabulary and set of practices that organizations may adapt to their own context. Adoption and application vary, and organizations should treat the framework as guidance to be tailored rather than a prescriptive mandate, verifying specific content against the primary OCEG source.

Who it's relevant to

Compliance officers
Compliance professionals may use the model as a reference for coordinating compliance activities with adjacent risk, governance, and ethics functions rather than operating them in isolation. Because the framework is voluntary and not a substitute for meeting specific legal or regulatory obligations, it is best treated as guidance to help structure and assess compliance capabilities.
Risk managers
Risk managers may find the model useful as a shared framework for aligning risk management practices with governance, compliance, and ethics activities. It offers a way to plan, assess, and improve integrated capabilities, though how it is applied will depend on the organization's own risk context and existing frameworks.
Governance professionals and general counsel
Those responsible for organizational governance and legal oversight may reference the model when considering how decision-making structures connect with risk, compliance, and ethics activities. As a voluntary framework, it informs rather than determines governance arrangements, and specific legal or regulatory matters continue to require professional judgment and advice.
Internal auditors
Internal auditors may draw on the model as one reference point when evaluating how well an organization coordinates its governance, risk, compliance, and ethics activities. Because it is guidance rather than a binding standard, auditors should be clear about whether they are assessing against this voluntary framework or against applicable regulatory requirements.
GRC practitioners pursuing integration
Professionals tasked with bringing together traditionally siloed governance, risk, compliance, and ethics functions may use the model to plan, assess, and improve integrated capabilities in pursuit of what OCEG describes as Principled Performance. Practitioners should verify current version content and edition features, such as any supplementary Tools & Techniques resources, against the primary OCEG source.

Inside GRC Capability Model (OCEG Red Book)

Integrated GRC Definition
The model articulates governance, risk management, and compliance as capabilities that can be integrated rather than managed in isolation, using the concept often summarized as 'Principled Performance', the reliable achievement of objectives while addressing uncertainty and acting with integrity. It is a voluntary capability framework, not a binding regulatory requirement.
Component Structure (LEARN, ALIGN, PERFORM, REVIEW)
The model is commonly organized around a set of high-level components that group related practices, typically covering understanding the internal and external context, aligning strategy and objectives with risk and compliance considerations, executing controls and activities, and reviewing and improving performance. Specific component names and groupings have evolved across editions and should be verified against the current Red Book.
Elements and Practices
Within each component the model breaks down into more granular elements and associated practices intended to serve as a reference set from which organizations select what fits their context. It is descriptive of capabilities rather than prescriptive of a single mandatory implementation.
Scope Across the Three Pillars
By design the model spans governance (structures and decision rights), risk management (addressing uncertainty against objectives), and compliance (adherence to external laws, regulations, and internal policies), and treats them as interconnected rather than separate disciplines.
Relationship to Other Standards
The model is often positioned as complementary to, rather than a replacement for, standards and frameworks such as COSO's internal control and ERM frameworks, ISO 31000, and ISO 37301. Organizations frequently map it against these sources, but the model does not itself constitute a legal or regulatory obligation.

Common questions

Answers to the questions practitioners most commonly ask about GRC Capability Model (OCEG Red Book).

Is the GRC Capability Model a regulatory requirement that organizations must comply with?
No. The GRC Capability Model is a voluntary framework published by OCEG, not a binding law or regulation. It offers guidance and a common vocabulary for integrating governance, risk management, and compliance activities, but it does not impose legal obligations. Organizations may draw on it as leading practice, and its applicability varies by jurisdiction, sector, and organization size. Regulatory obligations themselves arise from applicable laws and regulations, which should be assessed independently, typically with professional advice.
Does the GRC Capability Model simply combine three separate disciplines that would otherwise stay in their own silos?
Not exactly. While the model spans the three pillars, governance (the structures and decision rights by which an organization is directed and controlled), risk management (addressing uncertainty against objectives), and compliance (adherence to external and internal requirements), its purpose is to help organizations coordinate these activities toward what OCEG often describes as 'principled performance,' rather than merely bundling them. The pillars remain conceptually distinct, and the model is intended to align them rather than erase the boundaries between them.
How might an organization begin applying the GRC Capability Model in practice?
Organizations often start by using the model as a reference to assess how their existing governance, risk, and compliance activities are currently organized and where they overlap or leave gaps. Because the model is a framework rather than a prescriptive checklist, implementation typically involves adapting its components to the organization's own objectives, structure, and regulatory context. The specific approach varies considerably by organization size and sector, and no single sequence is mandated.
How does the model relate to other frameworks such as COSO ERM or ISO 31000?
The GRC Capability Model is generally intended to be complementary rather than a replacement for risk or control frameworks. Organizations frequently use it alongside sources such as COSO ERM, the COSO Internal Control-Integrated Framework, or ISO 31000, which address risk and internal control in more depth. The model tends to focus on integrating governance, risk, and compliance more broadly, so mapping its components to whichever frameworks an organization already uses is a common implementation step. Framework language evolves across editions, so specifics should be verified against the primary sources.
Who within an organization typically owns or coordinates work aligned to the model?
Because the model spans multiple pillars, responsibilities are often shared across governance bodies, risk management functions, compliance officers, internal audit, and legal, with coordination frequently supported by senior leadership. There is no universally required ownership structure; assignment of roles and decision rights is a governance matter that varies by organization. Clarifying accountability across these functions is commonly part of applying the model.
How can an organization measure progress or maturity against the model?
The model is often used as a basis for assessing capability and identifying areas for improvement over time, but any maturity assessment should be adapted to the organization's own objectives and context. Measurement approaches vary, and improvement in capability does not by itself guarantee compliance or eliminate risk. Organizations typically define their own indicators and review cadence rather than relying on a single prescribed scoring method, and specifics should be confirmed against the current OCEG materials.

Common misconceptions

The GRC Capability Model is a regulatory standard organizations are required to follow.
It is a voluntary capability framework published by OCEG, not a binding law, regulation, or certifiable standard. Regulatory obligations arise from applicable laws and rules in a given jurisdiction and sector, and adopting the model does not by itself satisfy or replace those obligations.
Implementing the model integrates governance, risk, and compliance into a single undifferentiated function.
The model promotes integration and coordination among the three pillars, but each retains a distinct focus, governance concerns direction and control, risk management concerns uncertainty against objectives, and compliance concerns adherence to requirements. Integration refers to aligning these capabilities, not merging their distinct purposes.
The model prescribes a fixed, mandatory set of steps every organization must implement identically.
It is intended as a reference set of capabilities from which organizations select and tailor practices to their context, size, sector, and objectives. Applicability and implementation typically vary, and the model's components and terminology have also evolved across editions.

Best practices

Treat the model as a reference for tailoring GRC capabilities to your organization's context, size, and sector rather than as a checklist to be adopted wholesale.
Verify component names, element groupings, and terminology against the current edition of the Red Book, since the model's language has evolved across versions.
Map the model against the frameworks and standards you already use, such as COSO's internal control and ERM frameworks, ISO 31000, or ISO 37301, to identify overlaps and gaps rather than duplicating effort.
Keep the three pillars distinct in your implementation, clarify governance decision rights, risk assessment and treatment activities, and compliance obligations separately, while using the model to coordinate them.
Confirm binding regulatory obligations through the applicable laws and rules in your jurisdiction and sector, and do not rely on the model alone to demonstrate legal compliance.
Establish review and improvement practices so that selected capabilities are periodically reassessed against changing objectives, risks, and regulatory expectations.
Promotional banner for the Penetration Report Template Kit