INFORMATION SYSTEMS: GOVERNANCE, RISK & COMPLIANCE (GRC) FOR INFORMATION SYSTEMS: A HIGH-LEVEL PROCESS MODEL
DOI:
https://doi.org/10.46121/pspc.51.4.9Keywords:
Information Systems; IT Governance; Risk Management; Compliance; GRC Framework; COBIT; ISO 27001; Cybersecurity; Data Privacy; Regulatory ComplianceAbstract
The digital transformation of enterprises has elevated Information Systems (IS) Governance, Risk Management, and Compliance (GRC) from operational necessity to strategic imperative, yet organizations struggle with fragmented frameworks, siloed implementations, and misaligned processes. This paper presents a systematic review of 287 peer-reviewed studies published between 2015 and 2022, drawn from Scopus, Web of Science, IEEE Xplore, and AIS Electronic Library. We synthesize empirical evidence across three dimensions: (i) the evolution of IS GRC frameworks from COBIT, ISO 27001, and NIST to integrated, agile governance models; (ii) the risk landscape including cybersecurity threats, third-party vulnerabilities, data privacy, and emerging AI-related risks; and (iii) compliance mechanisms spanning regulatory mandates (GDPR, SOX, HIPAA, CCPA, EU AI Act) and industry standards. Results reveal that 63.7% of reviewed studies identify framework fragmentation as the primary implementation barrier, while 58.4% flag the absence of real-time risk monitoring capabilities as the dominant operational gap. Organizations implementing integrated GRC process models demonstrate 2.8x improvement in incident response effectiveness and 41% reduction in compliance costs compared to siloed approaches. We propose the Integrated GRC Process Model (IGPM) comprising six interconnected phases—Strategy Alignment, Risk Identification, Risk Assessment, Control Implementation, Monitoring & Reporting, and Continuous Improvement—supported by enabling factors including organizational culture, technology infrastructure, and skilled expertise. We identify five priority research directions for 2022–2030, grounded in identified gaps.

