GRC Capability Model (OCEG Red Book)
The GRC Capability Model, commonly known as the OCEG Red Book, is a voluntary framework designed to help organizations bring together their governance, risk management, compliance, and ethics activities in a more coordinated way. It offers practices that professionals can use to plan, assess, and improve how these functions work, with the stated aim of achieving what OCEG calls 'Principled Performance.' First released in 2004, it is described by its publisher as an early standard for integrating these disciplines.
The GRC Capability Model (OCEG Red Book) is a framework published by OCEG that provides practices for integrating governance, risk, compliance, and ethics activities across an organization. According to OCEG, the first edition was released in 2004 as an early GRC standard, and the model has since evolved through subsequent versions, including version 3.5. It is intended to help GRC professionals plan, assess, and improve their GRC capabilities in pursuit of OCEG's concept of 'Principled Performance.' Certain premium editions include supplementary materials such as a Tools & Techniques Appendix. As a voluntary framework rather than a binding legal requirement, its adoption and application vary by organization; specific version content, edition features, and any detailed practice requirements should be verified against the primary OCEG source, as framework language evolves across editions.
Why it matters
Organizations frequently develop governance, risk management, compliance, and ethics activities in isolation, with separate teams, tools, and reporting lines that do not communicate effectively. This fragmentation can lead to duplicated effort, gaps in coverage, and inconsistent information reaching decision-makers. The GRC Capability Model (OCEG Red Book) matters because it offers a structured, voluntary framework for coordinating these traditionally siloed disciplines, giving professionals a common reference point for how integrated governance, risk, compliance, and ethics activities can work together.
As described by its publisher OCEG, the framework was first released in 2004 as an early standard for integrating these disciplines, and it frames its purpose around the concept of 'Principled Performance.' For GRC professionals, having a named model to plan, assess, and improve their capabilities can support more consistent conversations across functions and with leadership about how mature their combined governance, risk, compliance, and ethics practices are, and where improvement may be warranted.
Because the model is a voluntary framework rather than a binding legal requirement, it does not by itself create obligations or guarantee compliance with any law or regulation. Its value lies in providing a shared vocabulary and set of practices that organizations may adapt to their own context. Adoption and application vary, and organizations should treat the framework as guidance to be tailored rather than a prescriptive mandate, verifying specific content against the primary OCEG source.
Who it's relevant to
Inside GRC Capability Model (OCEG Red Book)
Common questions
Answers to the questions practitioners most commonly ask about GRC Capability Model (OCEG Red Book).
