Skip to main content
Category: GRC Frameworks

OCEG GRC Capability Model

Also known as: OCEG Red Book, GRC Capability Model, Red Book
Simply put

The OCEG GRC Capability Model, commonly called the Red Book, is a framework published by OCEG to help organizations organize and improve how they handle governance, risk, and compliance activities. It is intended to help GRC professionals plan, assess, and improve their capabilities toward what OCEG describes as Principled Performance. The model is structured around four components: Learn, Align, Perform, and Review.

Formal definition

The GRC Capability Model, known as the OCEG Red Book, is a structured framework issued by OCEG that seeks to simplify, clarify, and augment integrated governance, risk management, and compliance practices. Version 3.5 is organized around four components, LEARN, ALIGN, PERFORM, and REVIEW, that GRC professionals may use to plan, assess, and improve GRC capabilities in pursuit of Principled Performance. Because it spans all three GRC pillars, the model functions as an integrating reference rather than a single-pillar standard; per OCEG, a premium edition includes a Tools & Techniques Appendix with additional supporting resources. The evidence provided does not specify clause-level requirements, adoption statistics, or jurisdiction-specific obligations, and this entry does not address implementation specifics or tooling.

Why it matters

Governance, risk management, and compliance activities often develop in isolation within organizations, with separate teams, vocabularies, and reporting lines for each pillar. The OCEG GRC Capability Model, commonly known as the Red Book, matters because it offers an integrating reference that spans all three pillars rather than addressing any one of them in isolation. For GRC professionals, this integration provides a common structure for thinking about how governance direction, risk treatment, and compliance obligations relate to one another and to broader organizational objectives.

The model's orientation toward what OCEG calls Principled Performance signals that its purpose is not merely to catalog activities but to help organizations plan, assess, and improve their GRC capabilities over time. By framing GRC as a set of capabilities that can be evaluated and matured, the Red Book gives practitioners a vocabulary for identifying gaps and articulating improvement priorities to stakeholders. According to OCEG, the model was developed in collaboration with hundreds of members and experts in the GRC community, which reflects its intent to consolidate practitioner input into a shared reference.

It is important to note the limits of what the model provides. The evidence available describes the model as a structured framework built around four components; it does not establish clause-level mandatory requirements, adoption statistics, or jurisdiction-specific obligations. Organizations should therefore treat the Red Book as a reference for organizing and maturing GRC practice rather than as a legal or regulatory standard that imposes binding duties.

Who it's relevant to

GRC and compliance professionals
Practitioners responsible for integrated governance, risk, and compliance work may use the model as a shared reference to plan, assess, and improve capabilities across the three pillars, and to structure conversations using its LEARN, ALIGN, PERFORM, and REVIEW components.
Risk managers
Those managing risk within an organization can use the model to situate risk activities within a broader integrated framework that also accounts for governance direction and compliance obligations, rather than treating risk management in isolation.
Governance professionals
Individuals concerned with organizational structures, roles, and decision rights may reference the model to understand how governance connects to risk and compliance activities in pursuit of what OCEG describes as Principled Performance.
Internal auditors and assurance functions
Assurance professionals may find the model's REVIEW component and capability orientation useful as context when evaluating GRC practices, while maintaining the independence and objectivity distinctions that separate assurance activities from the management activities being assessed.

Inside OCEG GRC Capability Model

Integrated GRC Approach
The model's central premise that governance, risk management, and compliance activities should be coordinated rather than operated in isolated silos, aiming to align these disciplines toward organizational objectives. It is a capability model rather than a legal standard, and it does not itself impose regulatory requirements.
Principled Performance Orientation
OCEG positions the model around the concept of achieving objectives while addressing uncertainty and acting with integrity. This framing spans all three pillars and is intended as a guiding orientation rather than a prescriptive control set.
Core Component Areas
The model organizes GRC capabilities into grouped components that commonly cover activities such as understanding the internal and external context, aligning strategy and objectives, performing actions and controls, and reviewing and monitoring performance. The specific grouping and terminology are defined by OCEG and may differ from other frameworks.
Capability Maturity Perspective
The model is used to assess and develop the maturity of an organization's integrated GRC capabilities over time, focusing on how well activities are designed and coordinated rather than certifying compliance with any particular law.
Cross-Pillar Scope
Because it deliberately spans governance structures, risk treatment, and compliance with laws, regulations, and internal policies, the model addresses all three pillars together; users should still map its guidance to the distinct requirements applicable in their jurisdiction and sector.

Common questions

Answers to the questions practitioners most commonly ask about OCEG GRC Capability Model.

Is the OCEG GRC Capability Model a certification or compliance standard that an organization can be audited against?
No. The Capability Model published by OCEG is a voluntary framework describing capabilities for integrating governance, risk, and compliance activities; it is not a certifiable standard in the way that, for example, an ISO management system standard is. It does not function as a legal or regulatory requirement, and adherence to it is not a substitute for meeting applicable laws, regulations, or internal policy obligations. Organizations sometimes describe themselves as aligned with the model, but this reflects an internal design choice rather than conformity assessed by an accredited third party.
Does implementing the OCEG GRC Capability Model mean governance, risk, and compliance become a single merged function?
No. The model promotes integration and coordination across governance, risk management, and compliance so that these disciplines share information and work toward common objectives, but integration is not the same as consolidation into one function. Governance concerns direction and decision rights, risk management concerns treating uncertainty against objectives, and compliance concerns adherence to external and internal requirements; these remain analytically distinct. The model addresses how they can be aligned, not a claim that their roles or accountabilities collapse into one another. Independence distinctions relevant to assurance functions are also not overridden by pursuing integration.
How does an organization typically decide where to begin when applying the model?
Organizations commonly start by assessing current-state capabilities against the areas the model describes, then prioritizing based on objectives, risk profile, and identified gaps rather than attempting to adopt every element at once. Because the model is descriptive rather than prescriptive about sequencing, the starting point varies with organizational size, sector, and maturity. This entry does not cover specific implementation roadmaps or tooling.
How can use of the model be reconciled with existing frameworks the organization already uses?
The Capability Model is generally intended to be complementary to, rather than a replacement for, other frameworks and standards an organization may rely on. Many organizations map its capability areas to structures they already maintain so that integration efforts build on existing governance, risk, and compliance activities. Reconciliation typically involves identifying overlaps and terminology differences; the specifics depend on which other frameworks are in use and how they are applied.
Who typically owns or sponsors an initiative based on the model?
Ownership varies by organization. Because the model spans governance, risk, and compliance, an initiative often involves multiple stakeholders and commonly benefits from senior-level sponsorship to coordinate across functions. Care should be taken to preserve the independence and objectivity of assurance functions, so that management-led integration activities are kept distinct from the assurance activities that evaluate them. This entry does not prescribe a particular reporting line or organizational structure.
How might an organization evaluate progress after adopting elements of the model?
Progress is commonly evaluated by reassessing capabilities against the areas the model describes and tracking whether integration objectives are being met over time. Because the model is a framework rather than a metrics standard, organizations typically define their own indicators aligned to their objectives and context. Evaluation of this kind is a management activity; where independent evaluation is desired, it is generally performed separately by an assurance function. This entry does not cover specific measurement methodologies or tooling.

Common misconceptions

The OCEG GRC Capability Model is a regulatory standard or certifiable requirement like ISO 37301 or SOX.
It is a voluntary capability model published by OCEG, not a law or an accredited certification standard. It does not create legal obligations, and adopting it does not by itself demonstrate compliance with any specific regulation.
The model replaces or duplicates frameworks such as COSO ERM or ISO 31000.
It is intended to integrate governance, risk, and compliance capabilities rather than to serve as a substitute for a dedicated risk management framework. Organizations commonly use it alongside such frameworks, mapping their respective scopes.
Following the model guarantees effective governance, risk, and compliance outcomes.
The model describes capabilities that may support coordination and maturity, but no framework guarantees outcomes. Effectiveness depends on implementation, organizational context, and the quality of underlying controls and assurance activities.

Best practices

Treat the model as an integrating overlay and map its components explicitly to the governance structures, risk management framework, and compliance obligations already in use, noting where each pillar's distinct requirements apply.
Adapt the model's terminology and grouping to your organization's jurisdiction, sector, and size rather than assuming its language matches your regulatory obligations verbatim.
Use the maturity perspective to assess how well GRC activities are coordinated, and prioritize improvements where silos create gaps or duplication across governance, risk, and compliance.
Preserve the independence of assurance functions when applying the model, keeping management's GRC activities distinct from the objective evaluation of those activities.
Complement the model with dedicated frameworks or standards where deeper technical requirements exist, and avoid relying on it as a sole source for control design or legal compliance.
Document the scope of what your GRC program covers and does not cover, and revisit the mapping periodically as regulations, objectives, and organizational context change.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps