Once companies address the question of whether to create a governance, risk-management, and compliance program with a broad organizational charter, an even bigger question looms: How do we actually structure and implement something like that?

The question poses challenges. After all, GRC policies and processesโ€”of varying degrees of effectiveness and efficiencyโ€”already exist throughout the business. Organizing these disparate and sometimes conflicting policies and processes requires GRC leaders to select one of the following governance structures: