In a GRC program, 'integrated GRC' refers to an approach where:
-
A
Governance, risk, and compliance are managed in completely separate silos
-
B
Governance, risk, and compliance activities share common data, processes, and technology
-
C
All GRC functions report directly to the CEO rather than the board
-
D
GRC tools are integrated with external regulatory databases only