Governance, Risk, and Compliance

GRC Assessment & Benchmarking  

Evaluate your governance, risk, and compliance performance. Receive your GRC Score. Join organisations building verifiable, standards-based trust.

Homae banner image
Homae banner image

Who Benefits from Our Platform

Our platform empowers organizations, industries, stakeholders, and customers with trusted insights, stronger governance, and measurable compliance improvements.

Who Benefits from GRC Assessment

Our platform empowers organizations, industries, stakeholders, and customers with trusted insights, stronger governance, and measurable compliance improvements.

For Organisations
img
01
An independent, evidence-based GRC Score validated against COSO, ISO 27001, and SOC 2 standards. Identify governance gaps, demonstrate compliance to customers, and reduce regulatory risk.
For Industries
02
Sector-wide GRC benchmarking that identifies collective improvement opportunities. Compare performance across your industry and build sector credibility through transparent, standards-based assessment.
For Stakeholders & Investors
03
Third-party-verified GRC data to support due diligence, investment decisions, and regulatory reporting. Replace self-certification with independently assessed compliance performance.
For Customers & Partners
04
A verified GRC Index listing demonstrates your organisation's commitment to governance, data security, and compliance. Reduce vendor assessment burden with a publicly visible, standards-backed GRC Score.

How the GRC Index Assessment Works

 Understand the step-by-step process to measure, benchmark, and improve your organization's governance, risk, and compliance performance.

Our process

Small star icon

Assessment

Complete a structured questionnaire aligned to COSO, ISO 27001, SOC 2, and ISAE 3402 frameworks. Submit documentary evidence to validate your governance policies, risk controls, and compliance practices.

Expert Scoring

Your submission is analysed by both algorithmic scoring and independent GRC expert reviewers. Performance is evaluated across all five GRC domains: Governance, Risk Management, Compliance, Resilience, and Data Security.

Index Inclusion & GRC Score

Approved organisations receive a GRC Score, a public profile in the GRC Index, and a prioritised set of improvement recommendations to advance their compliance maturity further.

Your GRC Score — What It Measures

Your GRC Score is a quantified, evidence-backed measure of your organisation's governance, risk management, and compliance maturity. It is calculated by GRC Index expert reviewers across five weighted domains, benchmarked against recognised international standards.

Governance Board-level oversight, policy framework, accountability structures, and strategic risk alignment

Risk Management Risk identification methodology, risk appetite statements, control testing, and risk reporting cadence

Compliance Regulatory mapping, audit readiness, internal policy adherence, and third-party compliance evidence

Resilience Business continuity plans, incident response procedures, disaster recovery testing, and operational resilience

Data Security Information security controls aligned to ISO 27001; SOC 2 Trust Services Criteria coverage; access controls and encryption standards

LEARN MORE

Why Organisations Trust the GRC Index

GRC Index is an independent, nonprofit benchmarking initiative headquartered at 63–66 Hatton Garden, London EC1N 8LE. Our mission is to make governance, risk, and compliance performance transparent, measurable, and improvable for every organisation operating in the UK and Europe.

Best

Organisations Assessed

86
%

Achieve Measurable Improvement

100
%

Independent & Nonprofit

5

International Standards

Our assessment framework draws on five recognised international and professional standards:

  • COSO (Committee of Sponsoring Organizations) — Internal control and enterprise risk management
  • ISO 27001 — Information security management systems
  • SOC 2 (AICPA Trust Services Criteria) — Data security and availability for service organisations
  • ISAE 3402 — International assurance standard for service organisation controls
  • ISAE 3000 — Assurance engagements and sustainability/non-financial reporting

Frequently Asked Questions About GRC Assessment

What is a GRC assessment?

+

A GRC assessment is a structured evaluation of an organisation's governance, risk management, and compliance (GRC) practices against internationally recognised standards such as COSO, ISO 27001, and SOC 2. It produces a benchmarked GRC Score that identifies strengths, control gaps, and priority improvement actions.

What is the GRC Index?

+

The GRC Index is an independent, nonprofit platform where UK and European organisations can assess, score, and publicly demonstrate their governance, risk, and compliance performance. Organisations that pass expert review receive a GRC Score and a public profile in the Index.

How does the GRC Index assessment work?

+

The process has three stages: (1) complete a standards-based questionnaire and submit supporting evidence; (2) undergo expert review and algorithmic scoring across five GRC domains; (3) receive a GRC Score, public Index listing, and prioritised improvement recommendations upon approval.

Who should complete a GRC assessment?

+

Any UK or European organisation wishing to demonstrate governance, risk, and compliance maturity to customers, regulators, or investors should complete a GRC assessment. It is most valuable for organisations in financial services, technology, professional services, and regulated industries.

Is the GRC Index assessment free to complete?

+

Yes. The initial GRC assessment at GRC Index is free to complete. After submitting your questionnaire and evidence, your responses are reviewed by GRC experts. Organisations meeting the benchmark standard receive a GRC Score and Index listing at no charge.

How can my organisation improve its GRC score?

+

GRC Index provides personalised recommendations based on your assessment results, covering governance structure, risk management frameworks, compliance controls, data security, and resilience. For structured training, Securance offers CPD-certified courses in GRC Essentials, SOC 2, ISAE 3402, ISO 27001, and ISAE 3000.

What standards does GRC Index use to score organisations?

+

GRC Index assessments are aligned to five internationally recognised frameworks: COSO (internal controls and ERM), ISO 27001 (information security), SOC 2 AICPA Trust Services Criteria, ISAE 3402 (service organisation controls), and ISAE 3000 (assurance engagements). Scoring reflects best practice across all five standards.

What is the difference between a GRC assessment and a GRC audit?

+

A GRC assessment is a self-reported evaluation of governance, risk, and compliance practices, validated by expert review and evidence submission. A GRC audit is a formal third-party examination of specific controls. GRC Index assessments provide an accessible, structured entry point before formal audit engagement.