Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
Category: GRC Governance Frameworks

Principled Performance

Also known as: Principled Performance®
Simply put

Principled Performance is a concept developed by OCEG that describes an organization's ability to reliably reach its goals while dealing with uncertainty and operating with integrity. In simple terms, it brings together achieving objectives, managing the unexpected, and behaving ethically as connected parts of running an organization well.

Formal definition

Principled Performance® is a concept developed by OCEG that refers to an organization's capability to reliably achieve objectives, address uncertainty, and act with integrity. It is closely associated with integrated governance, risk, and compliance (GRC) practices, spanning all three GRC pillars rather than treating governance, risk management, and compliance as separate disciplines, and is often used as an outcome-oriented framing for GRC actions, controls, and capability maturity. As an OCEG-originated concept rather than a binding regulatory obligation, its specific application varies by organizational context, and readers should consult OCEG source materials for authoritative elaboration.

Why it matters

Principled Performance matters because it reframes governance, risk, and compliance not as separate, often siloed functions but as interconnected contributors to a single outcome: reliably achieving objectives while addressing uncertainty and acting with integrity. For many organizations, governance structures, risk management processes, and compliance programs evolved independently, sometimes creating duplication, gaps, or conflicting priorities. The concept, developed by OCEG, offers an outcome-oriented framing that encourages these disciplines to work toward a shared purpose rather than pursuing narrow, function-specific goals.

For GRC professionals, the value of this framing lies in its emphasis on integration. By treating the achievement of objectives, the management of uncertainty, and ethical conduct as connected elements, Principled Performance can help leadership evaluate whether their combined GRC efforts actually support the organization's mission, or merely satisfy discrete requirements. It positions integrity and reliability as measures of organizational quality, not simply as constraints imposed by regulation or policy.

It is important to note that Principled Performance is an OCEG-originated concept rather than a binding regulatory obligation. Its adoption is voluntary, and how it is applied varies considerably by organizational context. Professionals seeking authoritative elaboration should consult OCEG's own source materials rather than treating the concept as a prescriptive standard.

Who it's relevant to

GRC and Compliance Leaders
Professionals responsible for governance, risk, and compliance programs may use Principled Performance as an integrating concept to align traditionally separate functions toward the shared aim of reliably achieving objectives while acting with integrity. It can inform how they evaluate and elevate the maturity of combined GRC capabilities.
Risk Managers
Because the concept places addressing uncertainty at its center, risk managers may find Principled Performance useful for connecting risk activities to broader organizational objectives and ethical conduct, rather than treating risk management as a standalone discipline.
Internal Auditors
Auditors assessing the effectiveness and integration of GRC activities may reference Principled Performance as an outcome-oriented framing when reviewing whether governance, risk, and compliance efforts work together to support the organization's goals. As a voluntary concept rather than a regulatory requirement, it informs perspective rather than constituting an audit criterion in itself.
Executive Leadership and Boards
Directors and senior executives responsible for setting objectives and overseeing organizational integrity may use the concept to consider how well combined GRC efforts contribute to reliably achieving goals, since it frames integrity and reliability as measures of organizational performance.

Inside Principled Performance

Objective-Centered Orientation
Principled Performance is oriented around reliably achieving objectives. The concept frames governance, risk management, and compliance activities as means to help an organization define and pursue its intended outcomes rather than as ends in themselves.
Addressing Uncertainty
The approach incorporates the management of uncertainty, both threats and opportunities, that may affect the achievement of objectives, aligning conceptually with risk management as the treatment of uncertainty against objectives.
Acting with Integrity
Principled Performance emphasizes operating within boundaries set by mandatory obligations (such as laws and regulations) and voluntary commitments (such as values, policies, and ethical standards). This spans the compliance pillar and elements of governance.
Integration of the GRC Pillars
The concept is commonly associated with coordinating governance, risk management, and compliance activities so they work together toward common objectives, rather than operating in isolated silos. Governance concerns direction and control, risk management concerns treating uncertainty, and compliance concerns adherence to obligations.
Definition of Boundaries
A core element is the identification of the mandatory and voluntary boundaries within which the organization chooses to operate, which informs how objectives are pursued and how conduct is constrained.

Common questions

Answers to the questions practitioners most commonly ask about Principled Performance.

Is Principled Performance just another name for compliance?
No. While compliance, adherence to external laws, regulations, and internal policies, is one component, Principled Performance is broader. It is oriented toward reliably achieving objectives while addressing uncertainty and acting with integrity, which spans governance, risk management, and compliance rather than reducing to compliance alone. Treating the two as synonymous typically understates the governance and risk dimensions the concept is meant to integrate.
Does adopting Principled Performance mean risk should be minimized or eliminated?
No. Principled Performance does not equate to risk avoidance, and no approach eliminates risk. The concept typically frames uncertainty as something to be addressed in relation to objectives, meaning some risk may be knowingly accepted within an organization's stated risk appetite and tolerance in pursuit of value. The emphasis is on informed, principled decision-making rather than suppression of all risk.
How might an organization begin operationalizing Principled Performance?
Organizations often begin by clarifying objectives and the decision rights, roles, and accountability structures (the governance layer) that direct and control activities toward those objectives. From there, they typically work to connect risk identification and treatment and compliance obligations to those same objectives, so that the three pillars inform one another rather than operating in isolation. The specific starting point varies by organization size, sector, and maturity, and no single sequence is universally required.
How can the effectiveness of a Principled Performance approach be evaluated?
Evaluation generally focuses on whether the organization is reliably achieving its objectives while addressing uncertainty and acting with integrity. Practitioners often look at whether governance, risk, and compliance activities are integrated and mutually informing, whether decisions reflect the stated risk appetite and tolerance, and whether controls are performing as intended against identified risks. Because the concept is context-dependent, meaningful measures should be tailored to the organization's objectives, and specific metrics fall outside any single definition.
How does Principled Performance relate to established frameworks such as COSO ERM or ISO 31000?
Principled Performance is an integrating orientation rather than a substitute for such frameworks. Organizations frequently continue to draw on internal control and enterprise risk frameworks like the COSO materials or risk management standards such as ISO 31000 to structure specific activities. The value proposition is typically alignment, connecting these framework-based activities to shared objectives across governance, risk, and compliance. The precise language and structure of each framework evolves across editions and should be confirmed against the primary source.
Who typically holds responsibility for Principled Performance within an organization?
Because the concept spans governance, risk management, and compliance, responsibility is generally distributed rather than assigned to a single function. Governing bodies and senior leadership often set objectives, decision rights, and tone, while risk, compliance, internal audit, legal, and operational functions contribute within their remits. The allocation of roles varies by jurisdiction, sector, and organizational structure, and questions of legal accountability may require professional advice.

Common misconceptions

Principled Performance is simply another name for compliance.
Compliance, adherence to external laws, regulations, and internal policies, is one component within the concept, but Principled Performance is broader. It also encompasses governance structures and the management of uncertainty against objectives, and these pillars should not be conflated.
Adopting Principled Performance guarantees that objectives will be achieved and risks eliminated.
No approach can guarantee outcomes or eliminate risk. The concept is oriented toward reliably achieving objectives while addressing uncertainty and acting with integrity, but residual risk typically remains and outcomes are influenced by factors outside any single framework's control.
Principled Performance is a binding regulatory standard organizations must implement.
It is generally presented as a leading-practice orientation or philosophy rather than a binding legal requirement. Its applicability and how it is operationalized vary by jurisdiction, sector, and organization, and it should be distinguished from mandatory obligations.

Best practices

Define objectives clearly first, then align governance, risk, and compliance activities to support their reliable achievement, treating those activities as means rather than ends.
Explicitly identify both mandatory boundaries (applicable laws, regulations) and voluntary boundaries (values, policies, ethical commitments) within which the organization intends to operate, and verify jurisdiction-specific requirements against primary sources.
Coordinate the governance, risk management, and compliance functions to reduce silos, while preserving the distinct role of each pillar and clear decision rights.
Incorporate the management of uncertainty, both threats and opportunities, into how objectives are pursued, distinguishing between risks (potential events) and the controls that modify them.
Use qualified, evidence-based language when reporting on performance and integrity, avoiding claims that controls eliminate risk or guarantee compliance.
Periodically reassess objectives, boundaries, and the integration of GRC activities as regulations, standards, and organizational context evolve, and seek professional advice for matters of legal interpretation.
Promotional banner for the Penetration Report Template Kit