OCEG GRC Capability Model 3.5 (Red Book)
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
The GRC Capability Model, known as the OCEG Red Book, is OCEG's open-source standard for integrating governance, risk management, and compliance into a single organizational capability. OCEG describes version 3.5 as the first and only open-source standard that integrates the sub-disciplines of governance, strategy, risk, audit, compliance, ethics and culture, and IT into a unified approach, with simplified, clarified, and augmented content.
OCEG is a global nonprofit founded in 2002 with more than 225,000 members in over 180 countries. It publishes the model free of charge in a general version, with a premium edition of additional tools available to its All Access Pass holders, and the model underpins OCEG's GRC Professional certification and its definition of Principled Performance, the reliable achievement of objectives while addressing uncertainty and acting with integrity.
Organizations apply the model through its four components. They learn about the organization's context, culture, and key stakeholders; align strategy with objectives and actions with strategy; perform actions that promote and reward desirable conduct and prevent and remediate undesirable conduct; and review the design and operating effectiveness of the strategy and actions. Each component holds elements and practices that GRC, risk, compliance, and audit teams use to design or assess their programs.
Why it Matters
Most organizations run governance, risk, compliance, audit, and ethics as separate functions with separate vocabularies and tools. The Red Book gives them a shared structure and language so that those functions work as one capability, which is why GRC platform vendors, consultancies, and certification bodies reference it.
Key benefits include:
- Unify vocabulary across disciplines
Give governance, risk, compliance, audit, and IT teams one set of terms and a common map of components and elements.
- Define common information requirements
Standardize what the organization needs to know about objectives, obligations, risks, controls, and events so it can be captured once and reused.
- Standardize core practices
Apply consistent practices for policies, training, controls, and monitoring rather than a different approach in every function.
- Design or assess a GRC program
Use the elements and practices as a checklist for building a program or benchmarking an existing one.
- Achieve Principled Performance
Connect GRC work to the reliable achievement of objectives while addressing uncertainty and acting with integrity.
How it Works
The model is organized into four components, each containing elements and practices. LEARN covers the organization's external and internal context, culture, and stakeholders. ALIGN covers direction, objectives, identification of opportunities, obstacles, and obligations, and the design of actions and controls. PERFORM covers controls, policies, communication, education, incentives, notification, inquiry, and response. REVIEW covers monitoring, assurance, and improvement of the design and operation of the strategy and actions.
Teams implement the model by mapping their existing governance, risk, compliance, and audit activities to the components and elements, identifying gaps in practices or information, and then building the missing practices in a prioritized order. Many use it alongside a management system standard, a risk standard such as ISO 31000, or a control framework such as COSO, since the Red Book integrates those rather than replacing them.
SmartSuite operationalizes the Red Book by holding the components, elements, and practices as a requirement set linked to objectives, obligations, risks, controls, policies, training, incidents, and reviews, so that a GRC program can be assessed and evidenced against the model in one place.
Key Elements
- LEARN
Understand the organization's external context, internal context, culture, and key stakeholders before setting direction.
- ALIGN
Set direction and objectives, identify opportunities, obstacles, and obligations, and design actions and controls that align strategy with objectives and actions with strategy.
- PERFORM
Operate the controls, policies, communication, education, incentives, notification, inquiry, and response practices that promote desirable conduct and prevent and remediate undesirable conduct.
- REVIEW
Monitor, assure, and improve the design and operating effectiveness of the strategy and actions.
- Common information requirements
A defined set of information about objectives, obligations, risks, controls, and events shared across the disciplines.
- Standardized practices
Consistent practices for recurring activities such as policy management and training that every function can apply.
Framework Scope
The model applies to any organization, in any sector, that wants to integrate governance, strategy, risk, audit, compliance, ethics and culture, and IT into one capability. It is used by GRC, risk, compliance, internal audit, and IT governance teams, by consultancies designing programs, and by technology providers structuring GRC software, and it is the reference for OCEG's GRC Professional certification.
Framework Objectives
OCEG publishes the Red Book so that organizations can achieve Principled Performance through an integrated GRC capability.
Unify the vocabulary used across governance, risk, compliance, audit, and IT disciplines.
Define common components and elements that any GRC program can be built from or assessed against.
Define the information every organization needs about objectives, obligations, risks, controls, and events.
Standardize practices for recurring activities such as policies and training.
Connect GRC activity to the reliable achievement of objectives while addressing uncertainty and acting with integrity.
Remain open source so that professionals, consultancies, and vendors can adopt the model freely.
Framework in Context
The Red Book is an integrating model rather than a control catalog. It is commonly used with ISO 31000 for risk management, COSO for internal control and enterprise risk management, COBIT for IT governance, the IIA's Three Lines Model for assurance roles, and compliance program benchmarks such as USSG §8B2.1 and the DOJ's Evaluation of Corporate Compliance Programs, each of which maps to one or more of its components.
Common Framework Mappings
Organizations map the Red Book's components, elements, and practices to the standards and frameworks their program already follows so that one integrated capability satisfies several references.
Mapped frameworks include:
ISO 31000:2018
COSO ERM 2017
COSO IC 2013
COBIT 2019
IIA Three Lines Model
USSG §8B2.1
DOJ ECCP
ISO 27001:2022
NIST CSF 2.0
ISO 42001
ISO 37301:2021
- ClassificationCategoryGovernance, Risk, and ComplianceDomainRisk ManagementFramework FamilyOther
- Regulatory ContextTypeFrameworkLegal InstrumentOpen-Source StandardSectorCross-SectorIndustryCross-Industry
- Region / PublisherRegionGlobalRegion DetailGlobal (OCEG)PublisherOCEG (Open Compliance and Ethics Group)
- VersioningVersion3.5Effective DateVersion 3.5 (current edition)Issue DateRelease date not stated on the publisher page
- AdoptionAdoption ModelVoluntaryImplementation ComplexityMedium
- Official ReferenceOpen Link in New TabSource
License included / downloadable: No
OCEG publishes the Red Book free of charge in a general version, with a premium edition for All Access Pass holders; the text is obtained from OCEG and is not included with the platform.
Framework text is licensed by its publisher and is included only where stated above.
How SmartSuite Supports OCEG GRC Capability Model
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
For the Red Book, SmartSuite holds the four components and their elements as a requirement set linked to objectives, obligations, risks, controls, policies, training, incidents, and reviews, so a GRC program can be assessed against the model with evidence in one place.
GRC Capability Model Library
Hold the LEARN, ALIGN, PERFORM, and REVIEW components with their elements and practices as structured requirements linked to your program.
Ownership, Cadence, and Accountability
Assign owners to each element, set review cycles, and track maturity assessments against the model over time.
Evidence Collection and Audit Trail
Attach policies, training records, control results, and review outputs to the practices they evidence, with timestamps and reviewers.
Program Assessment and Testing
Run gap assessments against the elements and practices, document findings, and track remediation to closure.
Risk, Obligation, and Objective Alignment
Link objectives, obligations, risks, and controls so that ALIGN and PERFORM activities trace back to what the organization is trying to achieve.
Integrated GRC Reporting
Produce dashboards by component, element, and business unit that show program maturity, open gaps, and review status for leadership and the board.
Related frameworks

ISO 31000 provides guidelines for identifying, assessing, and managing organizational risks to improve resilience and decision-making.

COSO ERM is a framework that helps organizations identify, assess, manage, and monitor enterprise risks to achieve objectives.

COSO ICFR guides organizations in designing and evaluating internal controls to ensure reliable financial reporting and regulatory compliance.

COBIT 2019 is a governance framework that helps organizations govern and manage IT to meet business goals, risks, and compliance.

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.
Frequently Asked Questions For OCEG GRC Capability Model
The Red Book is OCEG's GRC Capability Model, an open-source standard for integrating governance, strategy, risk, audit, compliance, ethics and culture, and IT into one organizational capability. Version 3.5 is the current edition.
LEARN about the organization's context, culture, and key stakeholders; ALIGN strategy with objectives and actions with strategy; PERFORM actions that promote and reward desirable conduct and prevent and remediate undesirable conduct; and REVIEW the design and operating effectiveness of the strategy and actions.
OCEG defines Principled Performance as the reliable achievement of objectives while addressing uncertainty and acting with integrity. The Red Book exists to help organizations achieve it.
OCEG offers a free version of the GRC Capability Model for general download. A premium edition with additional tools and techniques is available to OCEG All Access Pass holders.
No. It is a capability model that organizations use to design or assess their GRC programs. OCEG uses it as the body of knowledge for its GRC Professional certification, but organizations are not certified against it.
The Red Book integrates rather than replaces them. ISO 31000 and COSO ERM describe risk management, COSO describes internal control, and the Red Book shows how those and other disciplines fit into one GRC capability with shared vocabulary and information.
SmartSuite holds the components, elements, and practices as a requirement set linked to objectives, obligations, risks, controls, policies, training, incidents, and reviews. GRC teams use it to run gap assessments against the model, evidence each practice, and report program maturity to leadership.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.
