Diligent Logo
Diligent Logo
Products
arrow_drop_down
Solutions
arrow_drop_down
Resources
arrow_drop_down
Diligent AI

Bringing together top-down and bottom-up views of GRC

August 20, 2026
10 min read
A professional who is excited to integrate a top-down board view and GRC with a bottom-up operational view.

In this article

  • Intro
  • The foundation of successful integrated GRC strategies
  • The rhythm of risk: a new approach to risk management
  • The relationship between risk, strategy and objectives
  • Stepping into mature GRC management
  • How technology accelerates integrated GRC
  • Frequently asked questions about integrated GRC
Michael Rasmussen

Michael Rasmussen

GRC Analyst & Pundit

An integrated GRC strategy brings a top-down board view of GRC together with a bottom-up operational view.

The Tunnel of Eupalinos runs for over one kilometer through Mount Kastro in Samos, Greece. Built as an aqueduct in the 6th century BCE, it was dug simultaneously from both sides of the mountain until the two tunnels met. This feat of engineering dates back 2,700 years.

If the ancient Greeks can build a tunnel coming together to meet in the middle, then organizations should be able to deliver an integrated GRC strategy that delivers a top-down view of GRC from the board to meet up with a bottom-up view of GRC in operations.

The GRC Capability Model defines governance as achieving objectives reliably and risk management as addressing uncertainty. It defines compliance as acting with integrity. This definition requires a top-down view of GRC starting with the organization's objectives, but too often, the G in GRC has gone missing. You could compare it to risk and compliance teams who build tunnel(s) without coordinating with the G on what is needed to meet them in the middle.

This guide covers how to connect the two views:

  • Why an integrated GRC strategy has to start with objectives, not risk
  • How the board's top-down view depends on operational infrastructure underneath it
  • What separates mature GRC management from an unattached layer of oversight
  • Where technology closes the gap between board materials and operational risk data

The foundation of successful integrated GRC strategies

Delivering a successful integrated GRC strategy starts with the board in its governance role. Here the organization needs to clearly define the organization's objectives in its strategy, performance, goals and initiatives. Once the entity-level objectives are in place, the organization can then define the divisional, department, project, process and even asset-level objectives that align with the entity objectives the board has established. This is the foundation of a solid GRC strategy. It starts with objectives.

Clearly defined objectives provide the context needed to understand and measure risk. ISO 31000, the international standard on risk management, defines risk as the effect of uncertainty on objectives. Governance establishes the objectives used to identify and assess risk.

From a top-down view of GRC, the board needs to monitor the performance and objectives of the organization clearly and see how risk and uncertainty impact the organization in achieving those objectives. The board needs a dashboard view into objectives to provide data and insights into the organization's uncertainty and exposure in achieving those objectives. But to deliver on this top-down view of GRC starting with objectives requires a solid infrastructure of risk and compliance within operations, the bottom-up view.

The rhythm of risk: a new approach to risk management

My favorite approach to GRC throughout my research was with Microsoft from 2003 to 2008 when Brad Jewett was the enterprise risk management director. At the time, Jewett defined his approach to risk management at Microsoft as 'The Rhythm of Risk.'

He focused on integrating risk management into daily decision-making that would follow the corporate calendar for key processes. For instance, multiyear planning, annual planning, mergers and acquisitions, audit planning, SEC reporting, investor communications, product and service roadmaps, etc. It is an aspirational agenda. It set the tone and expectation that risk management in GRC was a priority that should influence and be integrated into how things get done every day. This approach covered corporate planning and daily operations, including top-down and bottom-up risk management.

The relationship between risk, strategy and objectives

To maintain the organization's integrity and execute on strategy, the organization has to see the individual risk (the tree) and the interconnectedness of risk to strategy and objectives (the forest). Some risk analysis must go even deeper, showing how leaves and branches connect to each tree and how each tree fits within the forest.

Risk management in business involves a mesh of exponential and sometimes chaotic relationships and impacts in which 1 + 1 may equal 3, 30 or 300. What seems like a small disruption or exposure may have a massive effect or no effect at all. In a linear system, the effect is proportional to the cause. In the non-linear world of business, risks are exponential. Business is chaos theory realized. The small flutter of risk exposure can disrupt objectives or even bring down the organization. Failing to see the interconnections of risk in the non-linear world of business objectives can produce exponentially unpredictable outcomes.

Build a risk-ready organization

Learn how to connect enterprise objectives with practical risk identification and reporting.

Stepping into mature GRC management

Mature GRC management helps the organization to understand performance in the context of risk. It can weigh multiple inputs from both a top-down view of risk to objectives and a bottom-up view of risk within operations and processes. It can combine internal and external contexts and analyze risk through qualitative and quantitative modeling. Mature GRC management is an integrated part of governance and operations. It requires:

  • The organization to take a top-down view of risk, led by the executives and the board, that is not an unattached layer of oversight.
  • An integrated process and information architecture that can connect a top-down view of objectives with the bottom-up view of risk from operations. This allows the organization to identify, analyze, manage and monitor risk and capture changes in the organization's context and risk profile from internal and external events as they occur.
  • Bottom-up participation where business functions at all levels identify and monitor uncertainty and the impact of risk down in the depth of the business.

"If you've got a good platform, that's an open platform that can accept best of breed technologies, then it becomes less of an issue for the people doing the work. All the data goes into one platform. That's the goal. You can have consistent reporting to the executives. Imagine having one report going to the executives showing all the risks," says Philip D. Harris, Research Director, Governance, Risk, and Compliance Services and Software at IDC.

According to the GC Risk Index 2026 by Diligent Institute, only 19% of the 147 senior legal leaders surveyed have fully integrated GRC systems. Fragmented systems prevent legal and risk teams from consolidating operational signals into a consistent enterprise view. Integration should begin with shared taxonomies that allow teams to classify and compare risk information consistently. Clear reporting ownership can then help ensure those signals reach the board.

The connection between internal audit, risk and board governance appears throughout the literature, including Dan Fornelius's internal audit case in Internal Auditor's risk integration. RIMS dedicated a 2025 ERM Special Edition of Risk Management magazine to enterprise risk practice. Board oversight is also benchmarked by the Deloitte Center for Board Effectiveness in its Board Practices Quarterly pulse surveys.

The same report found that only 21% of senior legal leaders are very confident their board receives the right mix of risk information. This confidence gap shows why system integration must translate into reporting that directors can use. Most are still digging from one end only.

Only when these pieces come together can the board's GRC view connect with the operational GRC view. Connecting these views requires consistent risk definitions and clear reporting ownership. Information must also reach the board on time. Technology can support that operating model by bringing board materials and operational risk data into a shared reporting environment.

Simplify compliance management

See how governance teams can reduce compliance overhead while improving oversight quality.

How technology accelerates integrated GRC

Fragmented reporting makes it difficult to connect operational risk signals with the information directors need. Technology can bring board materials together with operational risk reporting in a shared environment so both ends work from the same plans.

Diligent Boards supports the board's top-down view. Smart Builder assembles a polished board book draft from uploaded documents. Before materials circulate, Smart Risk Scanner identifies risky language and legal red flags, while SmartPrep 360 suggests discussion questions and talking points for each director, with citations back to source pages.

For pre-IPO companies, these capabilities support current audit committee reporting and preparation for public-company oversight. For enterprise and public companies, they support integrated oversight across business units, committees and assurance functions while helping independent directors review institutional-quality materials.

For risk practitioners, the Diligent One Platform provides the C-suite and the board with a consolidated view of the organization's GRC practice. This helps operational teams connect risk, compliance and assurance information with enterprise reporting needs.

"Diligent One is intriguing because we've been clamoring as board members to have more access to information. Where can I go to get that information a) swiftly, b) in a palatable, absorbable way? That's what we're looking for and that's something unique. Risks are all integrated, they're not isolated," says Edna Conway, board director and executive advisor.

Telepass shows the payoff. Using the Diligent One Platform, the company cut risk management follow-up time by 50%. Faster follow-up supports more timely remediation when teams identify risk or control issues. It also helps management provide the board with current information instead of reports delayed by manual processes.

The company monitors 100% of potentially fraudulent transactions and combines assurance across audit, risk, compliance and data protection, with unified reporting and real-time insights that improved transparency and trust. Risk leaders can use this model to prioritize automated follow-up and continuous transaction monitoring where manual processes create reporting delays.

Teams can remediate issues sooner, give boards current reports and connect operational activity with enterprise objectives more clearly.

Get governance, risk and compliance news and insights delivered to your inbox. Subscribe to the Diligent GRC Newsletter.

Frequently asked questions about integrated GRC

What does integrated GRC mean in practice?

Governance focuses on achieving objectives reliably, and risk management addresses uncertainty. Compliance calls for acting with integrity. Integrated GRC connects the board's top-down view of organizational objectives with the bottom-up view of risk and compliance in operations. Like the Tunnel of Eupalinos, both sides must coordinate so the board and operational views meet in the middle.

Why should GRC start with objectives instead of risk?

Objectives provide the context needed to understand and measure risk. ISO 31000 defines risk as the effect of uncertainty on objectives. The board sets entity-level objectives through strategy, performance, goals and initiatives, while divisional, department, project, process and asset-level objectives align with them.

How can boards improve the quality of risk reporting?

Boards need dashboard views that connect objectives with current uncertainty and exposure. Shared risk definitions and clear reporting ownership help ensure information moves from business functions to directors. Operational inputs must also arrive on time. An integrated process and information architecture can then capture changes in the organization's context and risk profile as they occur.

What makes GRC management mature?

Mature GRC management helps the organization to understand performance in the context of risk. It weighs multiple inputs from both a top-down view of risk to objectives and a bottom-up view of risk within operations and processes. It integrates internal and external contexts and uses various methods to analyze risk and provide qualitative and quantitative modeling. It is an integrated part of governance and operations, led by the executives and the board, rather than an unattached layer of oversight.

How does technology support integrated GRC?

Technology supports integrated GRC by reducing the manual effort required to connect board-level objectives with operational risk and compliance data. Integrated platforms bring materials, risk visibility and meeting preparation into one environment so boards can receive a clearer top-down view while management benefits from faster, more accurate bottom-up reporting. Decision-makers need the right information at the right time.

Ready to connect board oversight with operational risk reporting? Schedule a demo to see how Diligent Boards and Diligent One support integrated GRC.