Governance, risk and compliance (GRC) is the coordinated approach an organization uses to set direction, manage uncertainty and meet internal and external obligations. IGA is a specialized identity-security discipline that supplies preventive controls, monitoring and evidence to GRC processes.
GRC may define a control objective such as timely removal of terminated-user access; IGA implements and proves the identity processes supporting that objective.