1. Take the requirement 2. Identify Framework that applies 3. Define control objective 4. Map the controls to requirement 5. Carry out crosswork 6. Identify risk event 7. Collect objective evidence that the control exists and operates 8. Testing to check and Determine whether the control is designed and operating effectively. 9. Gap identification that exist 10. Remediation level to fix 11. Reporting its where i turn GRC results into information management can act on.