This document summarizes the results of a study on governance, risk management, and compliance (GRC) practices. The study found that GRC activities are most commonly centered in IT departments and that the largest barriers to effective GRC are a lack of collaboration and resources. It also found that establishing a clear GRC strategy and assessing risk are seen as most essential but are still challenges for many organizations. Ensuring security of data shared with third parties and complying with privacy regulations were cited as the top privacy-related issues.