IGA is an identity-focused control discipline, while governance, risk and compliance (GRC) coordinates risk and control oversight across the organization.
GRC defines policies, risks, obligations, controls, owners and testing requirements across many domains. IGA implements and evidences identity-related controls such as timely offboarding, least privilege, access approval, separation of duties and periodic review. IGA data can feed GRC reporting, while GRC requirements help determine IGA policies and control objectives.