Governance, Risk, and Compliance
DETAIL

OCEG GRC Capability Model 3.5 (Red Book)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

The GRC Capability Model, known as the OCEG Red Book, is OCEG's open-source standard for integrating governance, risk management, and compliance into a single organizational capability. OCEG describes version 3.5 as the first and only open-source standard that integrates the sub-disciplines of governance, strategy, risk, audit, compliance, ethics and culture, and IT into a unified approach, with simplified, clarified, and augmented content.

OCEG is a global nonprofit founded in 2002 with more than 225,000 members in over 180 countries. It publishes the model free of charge in a general version, with a premium edition of additional tools available to its All Access Pass holders, and the model underpins OCEG's GRC Professional certification and its definition of Principled Performance, the reliable achievement of objectives while addressing uncertainty and acting with integrity.

Organizations apply the model through its four components. They learn about the organization's context, culture, and key stakeholders; align strategy with objectives and actions with strategy; perform actions that promote and reward desirable conduct and prevent and remediate undesirable conduct; and review the design and operating effectiveness of the strategy and actions. Each component holds elements and practices that GRC, risk, compliance, and audit teams use to design or assess their programs.

Why it Matters

Most organizations run governance, risk, compliance, audit, and ethics as separate functions with separate vocabularies and tools. The Red Book gives them a shared structure and language so that those functions work as one capability, which is why GRC platform vendors, consultancies, and certification bodies reference it.

Key benefits include:

  • Unify vocabulary across disciplines

Give governance, risk, compliance, audit, and IT teams one set of terms and a common map of components and elements.

  • Define common information requirements

Standardize what the organization needs to know about objectives, obligations, risks, controls, and events so it can be captured once and reused.

  • Standardize core practices

Apply consistent practices for policies, training, controls, and monitoring rather than a different approach in every function.

  • Design or assess a GRC program

Use the elements and practices as a checklist for building a program or benchmarking an existing one.

  • Achieve Principled Performance

Connect GRC work to the reliable achievement of objectives while addressing uncertainty and acting with integrity.

How it Works

The model is organized into four components, each containing elements and practices. LEARN covers the organization's external and internal context, culture, and stakeholders. ALIGN covers direction, objectives, identification of opportunities, obstacles, and obligations, and the design of actions and controls. PERFORM covers controls, policies, communication, education, incentives, notification, inquiry, and response. REVIEW covers monitoring, assurance, and improvement of the design and operation of the strategy and actions.

Teams implement the model by mapping their existing governance, risk, compliance, and audit activities to the components and elements, identifying gaps in practices or information, and then building the missing practices in a prioritized order. Many use it alongside a management system standard, a risk standard such as ISO 31000, or a control framework such as COSO, since the Red Book integrates those rather than replacing them.

SmartSuite operationalizes the Red Book by holding the components, elements, and practices as a requirement set linked to objectives, obligations, risks, controls, policies, training, incidents, and reviews, so that a GRC program can be assessed and evidenced against the model in one place.

Key Elements

  • LEARN

Understand the organization's external context, internal context, culture, and key stakeholders before setting direction.

  • ALIGN

Set direction and objectives, identify opportunities, obstacles, and obligations, and design actions and controls that align strategy with objectives and actions with strategy.

  • PERFORM

Operate the controls, policies, communication, education, incentives, notification, inquiry, and response practices that promote desirable conduct and prevent and remediate undesirable conduct.

  • REVIEW

Monitor, assure, and improve the design and operating effectiveness of the strategy and actions.

  • Common information requirements

A defined set of information about objectives, obligations, risks, controls, and events shared across the disciplines.

  • Standardized practices

Consistent practices for recurring activities such as policy management and training that every function can apply.

Framework Scope

The model applies to any organization, in any sector, that wants to integrate governance, strategy, risk, audit, compliance, ethics and culture, and IT into one capability. It is used by GRC, risk, compliance, internal audit, and IT governance teams, by consultancies designing programs, and by technology providers structuring GRC software, and it is the reference for OCEG's GRC Professional certification.

Framework Objectives

OCEG publishes the Red Book so that organizations can achieve Principled Performance through an integrated GRC capability.

Unify the vocabulary used across governance, risk, compliance, audit, and IT disciplines.

Define common components and elements that any GRC program can be built from or assessed against.

Define the information every organization needs about objectives, obligations, risks, controls, and events.

Standardize practices for recurring activities such as policies and training.

Connect GRC activity to the reliable achievement of objectives while addressing uncertainty and acting with integrity.

Remain open source so that professionals, consultancies, and vendors can adopt the model freely.

Framework in Context

The Red Book is an integrating model rather than a control catalog. It is commonly used with ISO 31000 for risk management, COSO for internal control and enterprise risk management, COBIT for IT governance, the IIA's Three Lines Model for assurance roles, and compliance program benchmarks such as USSG §8B2.1 and the DOJ's Evaluation of Corporate Compliance Programs, each of which maps to one or more of its components.

Common Framework Mappings

Organizations map the Red Book's components, elements, and practices to the standards and frameworks their program already follows so that one integrated capability satisfies several references.

Mapped frameworks include:

ISO 31000:2018

COSO ERM 2017

COSO IC 2013

COBIT 2019

IIA Three Lines Model

USSG §8B2.1

DOJ ECCP

ISO 27001:2022

NIST CSF 2.0

ISO 42001

ISO 37301:2021

At a Glance
OCEG GRC Capability Model 3.5 (Red Book)
  • Classification
    Category
    Governance, Risk, and Compliance
    Domain
    Risk Management
    Framework Family
    Other
  • Regulatory Context
    Type
    Framework
    Legal Instrument
    Open-Source Standard
    Sector
    Cross-Sector
    Industry
    Cross-Industry
  • Region / Publisher
    Region
    Global
    Region Detail
    Global (OCEG)
    Publisher
    OCEG (Open Compliance and Ethics Group)
  • Versioning
    Version
    3.5
    Effective Date
    Version 3.5 (current edition)
    Issue Date
    Release date not stated on the publisher page
  • Adoption
    Adoption Model
    Voluntary
    Implementation Complexity
    Medium
  • Official Reference
License Information

License included / downloadable: No

OCEG publishes the Red Book free of charge in a general version, with a premium edition for All Access Pass holders; the text is obtained from OCEG and is not included with the platform.

Framework text is licensed by its publisher and is included only where stated above.

Official Resources
OCEG: GRC Capability Model 3.5 (Red Book)
The publisher page for the model, with the free version download and the description of the LEARN, ALIGN, PERFORM, and REVIEW components.
OCEG: Principled Performance
OCEG's definition of Principled Performance, the reliable achievement of objectives while addressing uncertainty and acting with integrity.
About OCEG
The global nonprofit founded in 2002 that publishes the GRC Capability Model and runs the GRC Professional certification.
SMARTSUITE

How SmartSuite Supports OCEG GRC Capability Model

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.

For the Red Book, SmartSuite holds the four components and their elements as a requirement set linked to objectives, obligations, risks, controls, policies, training, incidents, and reviews, so a GRC program can be assessed against the model with evidence in one place.

GRC Capability Model Library

Hold the LEARN, ALIGN, PERFORM, and REVIEW components with their elements and practices as structured requirements linked to your program.

Ownership, Cadence, and Accountability

Assign owners to each element, set review cycles, and track maturity assessments against the model over time.

Evidence Collection and Audit Trail

Attach policies, training records, control results, and review outputs to the practices they evidence, with timestamps and reviewers.

Program Assessment and Testing

Run gap assessments against the elements and practices, document findings, and track remediation to closure.

Risk, Obligation, and Objective Alignment

Link objectives, obligations, risks, and controls so that ALIGN and PERFORM activities trace back to what the organization is trying to achieve.

Integrated GRC Reporting

Produce dashboards by component, element, and business unit that show program maturity, open gaps, and review status for leadership and the board.

Related frameworks

ISO 31000:2018

ISO 31000 provides guidelines for identifying, assessing, and managing organizational risks to improve resilience and decision-making.

COSO ERM 2017

COSO ERM is a framework that helps organizations identify, assess, manage, and monitor enterprise risks to achieve objectives.

COSO IC 2013

COSO ICFR guides organizations in designing and evaluating internal controls to ensure reliable financial reporting and regulatory compliance.

COBIT 2019

COBIT 2019 is a governance framework that helps organizations govern and manage IT to meet business goals, risks, and compliance.

ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

NIST CSF 2.0

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

IIA Three Lines Model

The IIA's Three Lines Model sets out six principles and the roles of the governing body, management, and internal audit for governance and risk management in any organization.

USSG §8B2.1

§8B2.1 of the U.S. Sentencing Guidelines defines the seven minimum requirements of an effective compliance and ethics program that reduce an organization's culpability score at sentencing.

ONBOARDING FAQS

Frequently Asked Questions For OCEG GRC Capability Model

What is the OCEG Red Book?

The Red Book is OCEG's GRC Capability Model, an open-source standard for integrating governance, strategy, risk, audit, compliance, ethics and culture, and IT into one organizational capability. Version 3.5 is the current edition.

What are the four components of the GRC Capability Model?

LEARN about the organization's context, culture, and key stakeholders; ALIGN strategy with objectives and actions with strategy; PERFORM actions that promote and reward desirable conduct and prevent and remediate undesirable conduct; and REVIEW the design and operating effectiveness of the strategy and actions.

What is Principled Performance?

OCEG defines Principled Performance as the reliable achievement of objectives while addressing uncertainty and acting with integrity. The Red Book exists to help organizations achieve it.

Is the Red Book free?

OCEG offers a free version of the GRC Capability Model for general download. A premium edition with additional tools and techniques is available to OCEG All Access Pass holders.

Is the Red Book a certification standard?

No. It is a capability model that organizations use to design or assess their GRC programs. OCEG uses it as the body of knowledge for its GRC Professional certification, but organizations are not certified against it.

How does the Red Book relate to ISO 31000 or COSO?

The Red Book integrates rather than replaces them. ISO 31000 and COSO ERM describe risk management, COSO describes internal control, and the Red Book shows how those and other disciplines fit into one GRC capability with shared vocabulary and information.

How does SmartSuite support the GRC Capability Model?

SmartSuite holds the components, elements, and practices as a requirement set linked to objectives, obligations, risks, controls, policies, training, incidents, and reviews. GRC teams use it to run gap assessments against the model, evidence each practice, and report program maturity to leadership.

Operationalize OCEG Red Book 3.5 with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.