Identify
To identify means to recognize or determine who someone is or what something is, and to be able to state or demonstrate that conclusion. In a governance, risk, or compliance setting, it generally refers to the act of pinpointing or naming a relevant item, such as a risk, control, obligation, or stakeholder, so it can be assessed and managed. Failing to identify something typically means overlooking or missing it entirely.
In its general sense, to identify is to perceive, recognize, or establish the identity of a person or thing and to state or prove that identity. Within governance, risk, and compliance practice, identification is typically the initial step in a broader process, in which a practitioner determines and names the relevant subject matter (for example, risks, controls, applicable requirements, or affected parties) before subsequent stages such as assessment, evaluation, treatment, or monitoring. The precise scope and rigor of an identification activity generally depend on the applicable framework, methodology, and the practitioner's own judgment; this entry addresses the term in its plain-language sense rather than as a defined term under any specific statute or framework.
Why it matters
Identification is typically the foundational step in any governance, risk, or compliance process. If a risk, obligation, control, or affected party is never identified, it generally cannot be assessed, prioritized, treated, or monitored; the item simply remains outside the scope of management attention. As the plain-language sense makes clear, the opposite of identifying something is to overlook or miss it entirely, and in a GRC context that gap can propagate through every subsequent stage of a program because later activities operate only on what was named at the outset.
Because so much downstream work depends on it, the quality and completeness of identification tends to shape the effectiveness of the whole process. A risk assessment can be methodologically sound yet still leave an organization exposed if the underlying risk population was incomplete; a compliance program can be well-resourced yet still fall short if an applicable obligation was never recognized. This is why identification is usually treated as a distinct, deliberate activity rather than an afterthought, and why frameworks and methodologies commonly position it explicitly as an early phase before assessment or evaluation.
The rigor expected of identification generally varies with the applicable framework, methodology, and the practitioner's own judgment. This entry addresses "identify" in its plain-language sense; it is not a defined term under any specific statute or framework, and what counts as adequate identification in a given program will depend on the facts, the sector, and the entity involved. Entries here are educational and not legal, audit, or compliance advice.
Who it's relevant to
Inside Identify
Common questions
Answers to the questions practitioners most commonly ask about Identify.