An organization is conducting a self-assessment of its GRC framework to ensure alignment with its governance, risk management, and compliance goals. The assessment team is looking for a document that offers a structured approach to reviewing GRC capabilities and outlines what to expect during the assessment.
What is the most appropriate resource for the team to use?