Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Exploring the entities

Entities are one of the most fundamental and crucial elements for using Governance, Risk, and Compliance. Entities can be people, processes, departments, applications, or objects that are examined for risks.

To effectively maintain the risk and compliance universe of your organization, you have to define entity types, entity classes, and entity tiers. A risk universe refers to a list of risks that your organization either faces or might face in the future. The list contains a description of each risk's criticality and frequency.

Entities are used within all offerings of GRC such as GRC: Policy and Compliance Management, Audit Management, GRC: Privacy Management and GRC: Regulatory Change Management.

  • Entities in GRC
    An entity is a person, process, department, application, or other object whose compliance exposure is tracked in GRC. Each entity has an owner, so non-compliant items and their owners can be identified individually.
  • Composite entity in Governance, Risk, and Compliance
    Composite entity in Governance, Risk, and Compliance is a combination of two or more entities created from different entity classes. The Composite Entity Management application enables you to create multidimensional entities and manage them in a more granular level.
  • An entity in the workspace view
    The Entity form in the workspace provides a complete view of an entity across your organization. The Entity form is listed under the Library menu of the List view in the workspace. Select an entity in the list view so that you can display its overview, details, hierarchy, entity types, or downstream risks.
  • Functionality enhancements for the entities
    You can configure some functionality enhancements for the entities as part of the GRC updates.
  • Entity scoping in GRC
    Entity scoping is permitted in each of the core GRC applications. Scoping provides a way to allocate risks and controls at different levels. Dependencies are created using the dependency map in the GRC Workbench.
  • Entity classes
    Entity classes are used to add a conceptual information about the entity or to tag the entity. They are used to classify the entities and they represent a collection of entities that have the same attributes.
  • Entity class rules
    Entity class rules help to assign classes to the entities at the table level. Any new entity created on the table gets that entity class automatically. Entity classes are used to tag your entities.
  • Entity types
    Entity type is a grouping of the entities that match a set of filter conditions. You can create a hierarchy of the entity types within the entity classes. The Entity types option is displayed under the Lists view in the workspace. Click an entity type to display its details.
  • Entity tiers
    When you create entity tiers, you can apply a level or hierarchy to the entity classes. This level applies to all the entities that are associated with the entity classes. Entity tiers enable you to select and view the status of the most critical items in the business.

Parent Topic:Common Governance, Risk, and Compliance features