In banking, GRC stands for Governance, Risk, and Compliance — a single framework that ties together how a bank makes decisions, how it controls the threats to its business, and how it meets the demands of regulators. Rather than running strategy, risk management, and legal compliance as three separate departments with three separate views of the world, GRC treats them as one operating system. That integration matters more in banking than in almost any other industry: regulators can shut down a poorly governed bank, and a single compliance failure can trigger fines in the billions.
The Three Components
Governance is the decision-making architecture. It defines who has authority to approve what, how the board sets strategic direction, and what ethical standards apply across the organization. In practice, the board signs off on major policies, states how much risk the bank is willing to take, and holds senior management accountable when things go wrong. For large national banks, the OCC’s heightened standards require a formal written risk governance framework with clearly defined roles across business lines and control functions, and the board must include at least two independent directors.1Federal Register. OCC Guidelines Establishing Heightened Standards for Certain Large Insured National Banks, Insured Federal Savings Associations, and Insured Federal Branches
Risk management is the systematic process of identifying, measuring, and controlling threats to the bank’s objectives. Banking risks sort into a few broad categories. Credit risk covers borrowers defaulting on loans. Market risk covers losses from changes in interest rates or asset prices. Liquidity risk covers not having enough cash on hand to meet obligations. Operational risk covers failures in people, processes, or technology. Each category has its own controls, limits, and monitoring, but under GRC they all feed into a single picture of the bank’s total exposure.
Compliance translates external laws and regulations into internal procedures that front-line employees can actually follow. The scope is enormous: anti-money-laundering rules, consumer protection statutes, data privacy requirements, fair lending obligations, and capital adequacy standards, among others. Compliance teams don’t just write policies. They monitor adherence, train staff, and manage the bank’s day-to-day relationship with regulators.
How GRC Is Structured Inside a Bank
Banks organize GRC responsibilities using the Three Lines Model developed by the Institute of Internal Auditors. The idea is simple: separate the people who take risks from the people who monitor risks from the people who audit everything.
The first line is the business itself — loan officers, traders, branch managers, product teams, and their support functions. These are the risk owners. They run operations, implement controls, and are responsible for managing the risks inside their own activities. The IIA describes first-line roles as “most directly aligned with the delivery of products and/or services.”2The Institute of Internal Auditors. The IIA’s Three Lines Model – An Update of the Three Lines of Defense
The second line is the independent control functions: Risk Management and Compliance. These teams set policies, define risk appetite metrics, design monitoring programs, and challenge the first line’s decisions. The IIA describes their role as providing “complementary expertise, support, monitoring, and challenge related to the management of risk.” The Chief Risk Officer and Chief Compliance Officer typically lead the second line and report to the CEO and board committees, which keeps them independent from the revenue-generating units they oversee.2The Institute of Internal Auditors. The IIA’s Three Lines Model – An Update of the Three Lines of Defense
The third line is Internal Audit. This function operates independently from both the first and second lines and reports directly to the board. Internal auditors don’t set policy or manage risk. They assess whether the other two lines are doing their jobs. Their findings often drive governance changes and remediation. Without this final layer of independent review, a bank has no reliable way to verify its own framework is working.2The Institute of Internal Auditors. The IIA’s Three Lines Model – An Update of the Three Lines of Defense
The OCC’s heightened standards codify this structure for large national banks. Risk governance frameworks must explicitly define roles for front-line units, independent risk management, and internal audit. The guidelines also require processes for escalating risk-limit breaches and for the board to exercise what regulators call “credible challenge” — the ability to question and, when necessary, oppose management decisions that would push the bank’s risk profile past its stated appetite.1Federal Register. OCC Guidelines Establishing Heightened Standards for Certain Large Insured National Banks, Insured Federal Savings Associations, and Insured Federal Branches
How the Three Pieces Work Together
Treating governance, risk, and compliance as one framework — rather than three disconnected departments — is what eliminates blind spots. When a bank launches a new product, governance sets the approval authority, risk management evaluates credit and market exposure, and compliance checks whether the product’s disclosures and marketing meet regulatory requirements. In an integrated framework, all three assessments happen at the same time using shared data, instead of in silos that can produce contradictory conclusions.
Most banks reach this integration through GRC software platforms that centralize control monitoring, policy distribution, and regulatory change tracking. These systems give senior management a single source of truth for risk and compliance metrics. Dashboards show current risk posture against stated risk appetite, so emerging problems can be spotted before they become enforcement actions.
A consolidated view also improves audit readiness. When regulatory requirements map directly to internal controls and testing results in the same system, control failures get flagged to compliance and governance functions right away. Small problems get caught before they compound.
The Federal Regulations That Shape a Bank’s GRC Program
A bank’s GRC program doesn’t exist in a vacuum. Its scope is largely dictated by the federal regulations the bank must follow. Each of the major ones creates distinct governance, risk, and compliance obligations.
Basel III Capital and Liquidity Standards
The Basel III framework, developed by the Basel Committee on Banking Supervision, sets international minimum standards for how much capital banks must hold, how much leverage they can take on, and how much liquidity they must maintain. It was created in response to the 2007–2009 financial crisis.3Bank for International Settlements. Basel III: International Regulatory Framework for Banks Capital requirements push banks to hold higher-quality capital as a buffer against unexpected losses, which directly limits how aggressively a bank can lend or invest. The Liquidity Coverage Ratio requires banks to hold enough high-quality liquid assets to cover net cash outflows over a 30-day stress period.4Federal Reserve Board. Liquidity Coverage Ratio FAQs U.S. regulators implemented these standards through domestic rulemaking, and compliance requires continuous monitoring and board-level reporting.5Federal Register. Liquidity Coverage Ratio – Liquidity Risk Measurement Standards
Dodd-Frank and Stress Testing
Dodd-Frank reshaped banking regulation after 2008. Among its provisions, large bank holding companies with $100 billion or more in consolidated assets must undergo supervisory stress tests conducted by the Federal Reserve.6Federal Reserve. Dodd-Frank Act Stress Test 2019 – Introduction Stress testing is a GRC exercise in the truest sense. Governance decides who oversees the process and validates the models. Risk management builds the scenarios and runs the projections. Compliance makes sure results meet regulatory submission requirements. A bank that fails a stress test can be restricted from paying dividends or buying back stock.
The Volcker Rule
Section 619 of Dodd-Frank, known as the Volcker Rule, prohibits banks from engaging in proprietary trading or acquiring ownership interests in hedge funds and private equity funds.7FDIC. Selected Sections of the Dodd-Frank Wall Street Reform and Consumer Protection Act The implementing regulations add that no permitted trading activity can involve a material conflict of interest with clients, expose the bank to high-risk assets or strategies, or threaten its safety and soundness.8eCFR. 12 CFR Part 248 – Proprietary Trading and Certain Interests in and Relationships With Covered Funds Compliance teams have to monitor trading desks and separate permissible market-making and hedging from prohibited speculative positions, a line that can be difficult to draw in real time.
Bank Secrecy Act and Anti-Money-Laundering
The Bank Secrecy Act requires financial institutions to file reports on cash transactions exceeding $10,000, keep records of certain negotiable instrument purchases, and report suspicious activity that could indicate money laundering, tax evasion, or other financial crimes.9Financial Crimes Enforcement Network. The Bank Secrecy Act These obligations require transaction monitoring systems, customer due diligence programs, and trained staff who can recognize red flags. This is the area where GRC failures have produced the largest penalties in banking history. In 2024, FinCEN assessed a $1.3 billion penalty against TD Bank — the largest ever against a depository institution in U.S. Treasury history — after the bank willfully failed to file suspicious activity reports on thousands of transactions totaling roughly $1.5 billion.10FinCEN. FinCEN Assesses Record $1.3 Billion Penalty Against TD Bank BSA violations carry both civil and criminal penalties, and a civil monetary penalty can be imposed on top of criminal prosecution for the same violation.11Internal Revenue Service. Internal Revenue Manual 4.26.7 – Bank Secrecy Act Penalties
Consumer Protection and Data Privacy
The Gramm-Leach-Bliley Act requires banks to provide customers with privacy notices explaining what personal information the bank collects, how it’s shared, and how the customer can opt out of certain disclosures. Banks must also disclose their practices for protecting the security and confidentiality of that information.12FDIC. VIII-1 Gramm-Leach-Bliley Act (Privacy of Consumer Financial Information) The Community Reinvestment Act adds another dimension by requiring regulators to evaluate each bank’s record of meeting the credit needs of its entire community, including low- and moderate-income neighborhoods. CRA performance ratings directly affect whether regulators will approve applications for new branches, mergers, or charter conversions.13OCC. 12 CFR Part 25 – Community Reinvestment Act and Interstate Land Development Full Disclosure Act A poor CRA rating can effectively block a bank’s growth strategy.
Cybersecurity and Third-Party Risk
Cybersecurity has become one of the most resource-intensive areas of banking GRC. The FFIEC’s IT examination guidance expects the board to oversee the information security program and hold management accountable, while management must establish a security culture, define responsibilities, and allocate adequate resources.14FFIEC. FFIEC IT Handbook – Information Security Booklet When a significant cyber incident occurs, the clock starts fast. Under the Computer-Security Incident Notification Rule, a bank must notify its primary federal regulator no later than 36 hours after determining that a “notification incident” has occurred.15eCFR. 12 CFR Part 53 – Computer-Security Incident Notification A notification incident is one that has materially disrupted, or is reasonably likely to materially disrupt, the bank’s ability to serve customers, its critical business lines, or operations whose failure could threaten financial stability.16FDIC. Computer-Security Incident Notification Final Rule Thirty-six hours doesn’t allow for lengthy internal debate about whether something qualifies, so pre-established incident response plans are a GRC essential.
Banks also increasingly rely on outside vendors for core functions: payment processing, cloud hosting, cybersecurity tools, customer-facing software. Regulators have made clear that outsourcing an activity does not outsource the responsibility. Interagency guidance from the OCC, FDIC, and Federal Reserve establishes that a bank’s board has “ultimate responsibility for providing oversight for third-party risk management” and must set the acceptable risk appetite for vendor relationships. The guidance separates routine vendor relationships from those supporting “critical activities,” where a third-party failure could cause significant risk, major customer impact, or material harm to the bank’s financial condition. Critical relationships demand deeper due diligence before a contract is signed, and the rigor of that due diligence should scale with the level of risk.17Federal Register. Interagency Guidance on Third-Party Relationships: Risk Management In practice, GRC teams keep inventories of third-party relationships, tier them by risk, perform periodic reassessments, and build contract terms that let the bank audit vendors and end relationships that create unacceptable exposure.
What Happens When GRC Breaks Down
The most visible consequence of a GRC failure is a consent order — a formal enforcement action that requires the bank to fix identified problems under regulatory supervision. Consent orders can restrict the bank from launching new products, impose asset caps that freeze growth, require independent monitors, and force management changes.
TD Bank’s 2024 enforcement action shows the full cascade. Beyond the $1.3 billion FinCEN penalty, the bank received an asset cap on its U.S. retail banking operations, had to establish a dedicated U.S. office for remediation, and became subject to independent monitors from both FinCEN and the Department of Justice.10FinCEN. FinCEN Assesses Record $1.3 Billion Penalty Against TD Bank Remediation costs alone can reach into the hundreds of millions once new staff, consultants, technology, and shelved growth plans are counted. Reputational damage makes it harder to attract customers and business partners, and every subsequent examination gets heightened scrutiny.
Climate Risk as the Emerging Edge
Climate-related financial risk is the newest addition to the banking GRC agenda. In 2023, the Federal Reserve conducted a pilot climate scenario analysis exercise with six of the nation’s largest banks to learn about their climate risk-management practices and improve the ability of banks and supervisors to identify and manage these risks.18Board of Governors of the Federal Reserve System. Climate Scenario Analysis Exercise Results The OCC, FDIC, and Federal Reserve have jointly issued principles for climate-related financial risk management aimed at banks with more than $100 billion in assets. The framework distinguishes physical risks, such as harm from hurricanes, wildfires, and flooding, from transition risks, meaning financial stress from shifts in policy, technology, or consumer behavior as the economy moves toward lower carbon output.19OCC. Risk Management: Principles for Climate-Related Financial Risk Management Regulators expect large banks to fold climate considerations into their existing risk management frameworks rather than treat them as a separate exercise, which means updated risk taxonomies, new data capabilities, and scenario analyses that go beyond traditional economic stress tests.