OCEG GRC Capability Model
The OCEG GRC Capability Model, commonly called the Red Book, is a framework published by OCEG to help organizations organize and improve how they handle governance, risk, and compliance activities. It is intended to help GRC professionals plan, assess, and improve their capabilities toward what OCEG describes as Principled Performance. The model is structured around four components: Learn, Align, Perform, and Review.
The GRC Capability Model, known as the OCEG Red Book, is a structured framework issued by OCEG that seeks to simplify, clarify, and augment integrated governance, risk management, and compliance practices. Version 3.5 is organized around four components, LEARN, ALIGN, PERFORM, and REVIEW, that GRC professionals may use to plan, assess, and improve GRC capabilities in pursuit of Principled Performance. Because it spans all three GRC pillars, the model functions as an integrating reference rather than a single-pillar standard; per OCEG, a premium edition includes a Tools & Techniques Appendix with additional supporting resources. The evidence provided does not specify clause-level requirements, adoption statistics, or jurisdiction-specific obligations, and this entry does not address implementation specifics or tooling.
Why it matters
Governance, risk management, and compliance activities often develop in isolation within organizations, with separate teams, vocabularies, and reporting lines for each pillar. The OCEG GRC Capability Model, commonly known as the Red Book, matters because it offers an integrating reference that spans all three pillars rather than addressing any one of them in isolation. For GRC professionals, this integration provides a common structure for thinking about how governance direction, risk treatment, and compliance obligations relate to one another and to broader organizational objectives.
The model's orientation toward what OCEG calls Principled Performance signals that its purpose is not merely to catalog activities but to help organizations plan, assess, and improve their GRC capabilities over time. By framing GRC as a set of capabilities that can be evaluated and matured, the Red Book gives practitioners a vocabulary for identifying gaps and articulating improvement priorities to stakeholders. According to OCEG, the model was developed in collaboration with hundreds of members and experts in the GRC community, which reflects its intent to consolidate practitioner input into a shared reference.
It is important to note the limits of what the model provides. The evidence available describes the model as a structured framework built around four components; it does not establish clause-level mandatory requirements, adoption statistics, or jurisdiction-specific obligations. Organizations should therefore treat the Red Book as a reference for organizing and maturing GRC practice rather than as a legal or regulatory standard that imposes binding duties.
Who it's relevant to
Inside OCEG GRC Capability Model
Common questions
Answers to the questions practitioners most commonly ask about OCEG GRC Capability Model.
