Skip to main content
Category: GRC Frameworks

Learn-Align-Perform-Review

Also known as: Learn, Align, Perform, Review, LAPR, Four Components of the GRC Capability Model
Simply put

Learn-Align-Perform-Review refers to the four components that make up OCEG's GRC Capability Model, a management framework for integrating governance, risk, and compliance. The model organizes GRC activities into four stages: understanding the organization and its context (Learn), setting direction and objectives (Align), taking action and operating controls (Perform), and monitoring and improving (Review). It is intended to help organizations coordinate governance, risk, and compliance work rather than treating them as separate silos.

Formal definition

Learn-Align-Perform-Review is the set of four components that structure OCEG's GRC Capability Model, a management framework designed to integrate governance, risk management, and compliance activities. In this model, compliance management practices are described as weaving throughout all four components rather than residing in a single stage. The components are also used as an organizing structure within OCEG's GRC assessment tooling to evaluate GRC capabilities. Practitioners should note that the model represents a proprietary OCEG framework and organizing schema; the specific practices assigned to each component, and their alignment with other frameworks such as COSO ERM or ISO 31000, are not detailed in the evidence provided here and this entry does not cover implementation specifics.

Why it matters

Many organizations develop their governance, risk management, and compliance activities in isolation, with separate teams, tools, and reporting lines that rarely coordinate. Learn-Align-Perform-Review matters because it offers an explicit organizing structure intended to counter this fragmentation, describing GRC as an integrated set of activities rather than three parallel disciplines. For practitioners, the value lies less in any single component and more in the framing that governance, risk, and compliance work can be sequenced and connected across a common set of stages.

The model is also notable for how it positions compliance. Rather than confining compliance to a discrete phase, OCEG describes compliance management practices as weaving throughout all four components. This framing can help compliance officers articulate why their work depends on understanding organizational context (Learn), aligning with objectives (Align), operating controls (Perform), and monitoring outcomes (Review), rather than being reducible to a checklist activity. It should be read as a conceptual and structural framework, however, and not as a source of specific mandated practices.

Because Learn-Align-Perform-Review is a proprietary OCEG framework, practitioners should be careful not to treat it as an external legal or regulatory requirement, and not to assume its alignment with other frameworks such as COSO ERM or ISO 31000 without independent verification. The evidence available here describes the components and their role as an organizing schema, but does not detail the specific practices within each component or how they map to other standards.

Who it's relevant to

Governance professionals
Those responsible for organizational direction and decision rights may use the Align component as a reference point for connecting objectives to broader GRC activity, and the model as a whole to argue for integrated rather than siloed governance structures.
Compliance officers
Compliance practitioners may find the model useful for articulating how compliance management weaves throughout all four components rather than functioning as an isolated stage, helping frame compliance as connected to organizational context, objectives, operations, and monitoring.
Risk managers
Risk professionals may reference the model as a way to position risk activities within an integrated GRC structure, though the specific practices assigned to each component are not detailed in the evidence here and would need to be drawn from OCEG's own materials.
Internal auditors and assurance functions
Assurance professionals may encounter the four components where OCEG's GRC assessment tooling is used to evaluate GRC capabilities. Auditors should maintain the distinction between assessing how management has structured GRC activities and independently evaluating whether those activities operate effectively.

Inside Learn-Align-Perform-Review

Learn
The initial phase in which an organization builds understanding of its objectives, obligations, and context. In a GRC setting this commonly involves gathering knowledge of applicable laws, regulations, internal policies, and the risk environment relevant to the organization. This phase is foundational rather than corrective, and its scope depends on the organization's jurisdiction, sector, and size.
Align
The phase concerned with connecting the knowledge gained to organizational direction, so that objectives, risk-taking, and control activities are consistent with governance intent. In many frameworks this reflects the governance pillar's concern with decision rights and direction, and it may include aligning activities to stated risk appetite and policy requirements.
Perform
The execution phase in which planned activities and controls are carried out. This is typically a management (first line) activity rather than an assurance activity, and it covers the operation of controls and processes designed to meet objectives and obligations.
Review
The evaluative phase in which performance is assessed against expectations, findings are identified, and improvements feed back into the cycle. Depending on how it is structured, review may involve management monitoring, second line oversight, or independent assurance; these carry different independence and objectivity implications and should not be conflated.

Common questions

Answers to the questions practitioners most commonly ask about Learn-Align-Perform-Review.

Is Learn-Align-Perform-Review a recognized standard or framework issued by a body such as COSO, ISO, or the IIA?
No. Learn-Align-Perform-Review is not, on the basis of what can be reliably stated here, a formally issued standard or framework attributable to bodies such as COSO, ISO, or the IIA. It should not be presented as carrying the authority of those published frameworks. Where an organization adopts it, it is typically as an internally defined or vendor-defined operating cycle rather than an external mandatory requirement. Users should confirm its origin and status before treating it as authoritative.
Does completing a Learn-Align-Perform-Review cycle constitute assurance over the organization's controls?
Not by itself. Running the cycle is generally a management activity directed at improving performance and alignment, not an independent assurance activity. Assurance in the sense used by third line functions depends on independence and objectivity from the processes being examined. A management-run improvement cycle does not substitute for independent assurance, and conflating the two blurs the distinction the three lines model is designed to preserve.
How can the four stages be mapped to existing governance, risk, and compliance responsibilities?
Mapping typically involves assigning ownership for each stage to the functions that already hold the relevant responsibilities rather than creating a parallel structure. In many organizations the Learn and Align stages engage governance and management roles that set direction and decision rights, Perform sits with the operational owners who execute activities and controls, and Review may draw on second line oversight while remaining distinct from independent third line assurance. The specific allocation depends on the organization's operating model, size, and sector, and should be documented so accountabilities are clear.
How does the cycle relate to an organization's existing risk management processes?
It is generally best treated as complementary to, not a replacement for, established risk processes such as those informed by ISO 31000 or COSO ERM. The Learn and Align stages may inform how objectives and context are understood, while Perform and Review can support monitoring and follow-up. Organizations commonly integrate such a cycle into existing risk identification, assessment, and treatment activities rather than running it separately, to avoid duplicated or conflicting processes.
What documentation typically supports each stage of the cycle?
Documentation practices vary by organization, but each stage commonly produces its own records: Learn may generate captured findings or lessons; Align may produce agreed objectives, decision records, or updated policies; Perform may be evidenced through operational records and control execution; and Review may yield evaluation outputs and follow-up actions. The level of formality that is appropriate depends on the organization's context and any applicable internal policy or regulatory expectations. This entry does not prescribe specific templates or tooling.
How can an organization tell whether the cycle is being applied effectively?
Indicators are typically defined by the organization in relation to its own objectives, since the cycle itself does not carry universal metrics. Common approaches include checking whether findings from Review feed back into subsequent Learn and Align stages, whether accountabilities for each stage are clear, and whether the cycle produces documented, actioned outcomes rather than activity without follow-through. Because this is an operating practice rather than a mandated framework, effectiveness measures should be tailored to context and should not be presented as guaranteeing improved outcomes.

Common misconceptions

The 'Review' phase is equivalent to an internal audit and therefore provides independent assurance.
Review can be performed as a management or oversight activity as well as an independent assurance activity. Only review conducted by a suitably independent and objective function provides assurance in the sense used by the three lines model; a self-review by those who performed the work does not carry the same independence.
Completing the Learn-Align-Perform-Review cycle guarantees compliance and eliminates risk.
A structured cycle can support, but does not guarantee, compliant outcomes or risk elimination. Residual risk commonly remains after controls operate, and adherence to laws, regulations, and internal policies depends on effective design and consistent execution rather than on following a cycle alone.
Learn-Align-Perform-Review is a formally issued standard from a recognized standards body.
It is presented here as a conceptual cyclical model rather than a named standard attributed to a specific issuing body. Practitioners should not treat it as carrying the authority of published frameworks such as those issued by COSO, ISO, or the IIA unless a specific source is cited.

Best practices

Treat the cycle as iterative, ensuring that findings from the Review phase feed back into the Learn phase rather than ending the process at a single pass.
Clearly distinguish which activities in the cycle are management (first line) execution and which are oversight or independent assurance, preserving the independence and objectivity of any assurance element.
Scope the Learn phase to the organization's applicable jurisdiction, sector, and size, rather than assuming a single universal set of obligations applies.
In the Align phase, make the link between objectives, risk appetite, and control activities explicit and documented, so alignment can be evidenced and challenged.
Define review criteria and expected outcomes before the Perform phase, so that assessment during Review is measured against pre-agreed expectations.
Document residual risk and open findings from each Review, acknowledging that completing the cycle supports but does not guarantee compliant or risk-free outcomes.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.