UTBMS Code Database

Governance, Risk and Compliance Codes

The LOC governance, risk, and compliance codes (G series) built on the six OCEG capability components, the only UTBMS set mapped to an external maturity model. Annotations render at the sub-phase level.

Take me to the UTBMS Code Lookup ToolUTBMS Code Lookup Tool

UTBMS governance, risk, and compliance codes structure GRC work across the six OCEG capability components: Context, Organize, Assess, Proact, Detect, and Respond.

This is the only UTBMS set built on an external management framework, which means coded GRC spend maps directly onto a maturity model. For legal departments buying compliance program work, investigations, and risk advisory, the set turns diffuse governance spend into a picture of which capability areas are actually being funded. Every code is searchable alongside all sets at the UTBMS code database.

Because GRC work is scoped and reviewed at the capability-area level, its annotations sit at the sub-phase rather than the individual code, and that capability lens is what makes GRC spend legible to a legal spend management program: you can see where compliance investment concentrates and whether it matches the program's maturity goals.

What are governance, risk and compliance codes used for?

GRC codes classify governance, risk, and compliance work by the OCEG capability it advances rather than by matter phase, because compliance programs are built and measured as capabilities. Coded this way, GRC spend maps onto the same maturity model a program uses to plan.

The review signals here are about scope and ownership. Because capability work often serves a whole program rather than a single matter, the recurring question is whether the cost belongs to a matter or to the program, and several codes are designated by the standard as internal management work where external charges should not apply.

What does each GRC capability area cover?

Annotations in this set live at the sub-phase level (G110, G120, and so on), because GRC engagements are scoped and reviewed by capability area. Each sub-phase carries its guidance once, above its task codes.

Annotations in this set live at the sub-phase (G110, G120...) level rather than per code, because GRC engagements are scoped and reviewed at the capability-area level. Each task code carries an original description; the official standard also maps every code to its OCEG counterpart. Several codes are designated by the standard itself as internal management opinions where external charges should not apply; those are flagged.

G100 Context
G110 External Context

When to use this code: Analysis of the external business, legal, regulatory, and geopolitical environment and external stakeholder needs.

Patterns reviewers commonly see: Broad environmental scanning billed to a specific matter when it serves the whole compliance program.

What invoice review checks: Whether context work is scoped to a program or a matter, since that decides where the cost belongs.

G111: Analyze the External Business ContextLOC (2015)

Identifying and analyzing external business context factors, including the legal, regulatory, and geopolitical climate.

G112: Analyze External Stakeholder and Influencer NeedsLOC (2015)

Identifying key external stakeholders and influencers, including issuing authorities, and analyzing their requirements.

G120 Internal Context

When to use this code: Work on entity structures and internal alignment, including entity creation, M&A-driven changes, and entity maintenance.

Patterns reviewers commonly see: Routine entity maintenance billed at advisory rates.

What invoice review checks: Entity-maintenance volume against a managed-service alternative; this is commodity work at scale.

G121: Define the Internal ContextLOC (2015)

Identifying key structures and assets defining the internal context, including entity creation, mergers, joint ventures, and dissolutions.

G122: Determine Changes Needed to Align the Internal Context and GRC CapabilityLOC (2015)

Identifying internal changes affecting GRC capability design, including entity maintenance and governance resolutions.

G130 Culture

When to use this code: Analysis of ethical culture, leadership tone, risk culture, board engagement, governance style, and workforce engagement.

Patterns reviewers commonly see: Culture assessments repeated without connection to prior findings.

What invoice review checks: Deliverable continuity across assessment cycles.

G131: Analyze Ethical CultureLOC (2015)

Analyzing the organizational climate and workforce mindsets on ethics, including ethics program requirements across jurisdictions.

G132: Analyze Ethical LeadershipLOC (2015)

Analyzing leadership tone at the top in words and conduct.

G133: Analyze Risk CultureLOC (2015)

Analyzing how the workforce perceives and engages with risk.

G134: Analyze Board InvolvementLOC (2015)

Analyzing board engagement, fiduciary duties, and reporting of irregularities.

G135: Analyze Governance Culture and Management StyleLOC (2015)

Analyzing the existing approach to governing and managing the workforce, including delegations of authority.

G136: Analyze Workforce EngagementLOC (2015)

Analyzing workforce satisfaction and engagement, including advice on benefits and leave programs.

G140 Objectives

When to use this code: Defining mission, vision, values, business objectives, risk appetite, indicators, and related commitments and communications.

Patterns reviewers commonly see: Strategy facilitation billed as legal work.

What invoice review checks: The advisory-versus-legal boundary in the engagement letter.

G141: Define Mission and VisionLOC (2015)

Creating formal mission and vision statements, including permissible entity purposes.

G142: Define ValuesLOC (2015)

Creating formal core value statements, including post-merger integration advisory work.

G143: Define Business ObjectivesLOC (2015)

Defining measurable business objectives aligned with mission, vision, and values.

G144: Define Risk Appetite and Decision CriteriaLOC (2015)

Defining risk appetite, tolerance, and decision criteria, including risk measurement advisory work.

G145: Define Indicators, Targets and TolerancesLOC (2015)

Defining leading and lagging indicators, targets, and tolerances.

G146: Obtain Commitment to Mission, Vision, Values and ObjectivesLOC (2015)

Securing management and board commitment, including approval of measurement programs.

G147: Communicate Mission, Vision and ValuesLOC (2015)

Communicating mission, vision, and values, including legal review of corporate and shareholder communications.

G200 Organize
G210 Commitment

When to use this code: Defining GRC capability scope, style, goals, and obtaining authorization.

Patterns reviewers commonly see: Program design cost recurring annually without capability change.

What invoice review checks: Design spend against the maturity movement it produced.

G211: Define GRC Capability ScopeLOC (2015)

Defining the scope of the GRC capability or subsystem, including strategic and operational planning advice.

G212: Define GRC Capability Style and GoalsLOC (2015)

Defining capability style, goals, and relationship to business objectives.

G213: Obtain Commitment to the GRC CapabilityLOC (2015)

Securing written authorization and high-level support, including approval presentations.

G220 Roles

When to use this code: Defining oversight, management, leadership, operational, and assurance roles for the GRC capability.

Patterns reviewers commonly see: Role-definition work rebilled per department rather than designed once.

What invoice review checks: Reuse of role frameworks across the organization.

G221: Define and Enable GRC Capability Oversight Roles and AccountabilityLOC (2015)

Defining oversight roles, responsibilities, and accountability, including job descriptions.

G222: Define and Enable Management Roles and AccountabilityLOC (2015)

Defining management roles and accountability for the capability.

G223: Define and Enable Leadership Roles and AccountabilityLOC (2015)

Defining leadership champion roles for the capability.

G224: Define and Enable GRC Capability Operational RolesLOC (2015)

Defining operational delivery roles, including background check requirements.

G225: Define and Enable Assurance Roles and AccountabilityLOC (2015)

Defining assurance roles such as audit leadership, including training on legal requirements.

G230 Accountability

When to use this code: Allocating accountability, defining GRC processes and their business integration, measurement approach, change management, and business case.

Patterns reviewers commonly see: Process documentation billed at counsel rates where consulting staffing fits.

What invoice review checks: Staffing mix on process and workflow documentation.

G231: Allocate Accountability to Individuals and CommitteesLOC (2015)

Allocating roles to individuals and committees, including delegation of authority and segregation of duties documentation.

G232: Define GRC Capability Processes and Integrate with Business ProcessesLOC (2015)

Defining GRC processes and synchronizing them with business workflows.

G233: Define Measurement and Evaluation ApproachLOC (2015)

Defining how capability effectiveness and efficiency will be measured.

G234: Define Organizational Change Management ApproachLOC (2015)

Defining the change readiness approach for people, process, and technology impacts.

G235: Develop, Maintain and Authorize a Business CaseLOC (2015)

Developing and presenting the GRC business case for authorization.

G300 Assess
G310 Identification

When to use this code: Identifying objectives, sources and forces, opportunities and threats, requirements, trends, and high-level risk and conformance analysis.

Patterns reviewers commonly see: Requirement-identification research repeated across matters for the same jurisdictions and products.

What invoice review checks: Cross-matter reuse of regulatory research, the compliance version of the A102 portfolio pattern. Note the standard designates some analysis here as internal management opinion where external charges should not apply.

G311: Review Business Objectives, Processes and ResourcesLOC (2015)

Reviewing key objectives, processes, and resources in capability scope.

G312: Identify External Sources and ForcesLOC (2015)

Identifying external sources and forces affecting objectives, including regulator enforcement trend profiling.

G313: Identify Internal Sources and ForcesLOC (2015)

Identifying internal sources and forces, including impacts of implemented business model changes.

G314: Identify Opportunities and ThreatsLOC (2015)

Identifying opportunities and threats to objectives, including competitive IP and threat assessments.

G315: Identify Mandatory and Voluntary RequirementsLOC (2015)

Identifying mandatory and voluntary requirements from applicable sources, including new-jurisdiction and new-product research.

G316: Identify Interrelatedness and TrendsLOC (2015)

Analyzing how opportunities, threats, and requirements interrelate and trend across regulatory levels.

G317: Conduct High Level Analysis of Risk/RewardLOC (2015)

High-level analysis of inherent, current, and planned residual risk and reward.

G318: Conduct High Level Analysis of Requirements Impact/ConformanceLOC (2015)

High-level conformance and impact analysis, including industry-level exposure opinions.

G319: Assign Accountability to Monitor ChangesLOC (2015)

Assigning monitoring accountability for sources of change, including establishing monitoring service relationships.

G320 Analysis

When to use this code: Analyzing approaches to requirements and risk, current controls, residual risk, and prioritization.

Patterns reviewers commonly see: External charges on items the standard designates as internal management opinions (G324 is flagged in the standard).

What invoice review checks: The standard's own internal-opinion designations are enforceable review rules.

G321: Analyze Approach to RequirementsLOC (2015)

Analyzing current and planned actions and controls addressing requirements, including cost.

G322: Analyze Inherent Risk/RewardLOC (2015)

Analyzing threat and opportunity effects without regard to current controls.

G323: Analyze Current Approaches to Risk/RewardLOC (2015)

Analyzing presence and effectiveness of current controls, including sufficiency opinions.

G324: Determine Current Residual Risk/RewardLOC (2015)

Determining residual risk given current controls. Designated internal management opinion; external charges should not apply.

G325: Prioritize Threats, Opportunities and RequirementsLOC (2015)

Prioritizing and categorizing for approach and resource allocation.

G330 Planning

When to use this code: Exploring options, determining planned residual risk, addressing high risk, developing indicators, and building the integrated plan.

Patterns reviewers commonly see: Option-exploration engagements without decision outputs.

What invoice review checks: Each planning deliverable should end in a decision artifact. G333 and G334 are designated internal opinions in the standard.

G331: Explore Options to Address RequirementsLOC (2015)

Exploring additional actions and controls where conformance is unacceptable or suboptimal.

G332: Explore Options to Address Risk/RewardLOC (2015)

Exploring alternative controls where residual risk is unacceptable.

G333: Determine Planned Residual Risk/Reward and ConformanceLOC (2015)

Determining post-implementation residual levels. Designated internal management opinion; external charges should not apply.

G334: Address Inherently High RiskLOC (2015)

Identifying controls specifically addressing inherently high risk. Designated internal management opinion; external charges should not apply.

G335: Develop Key IndicatorsLOC (2015)

Developing performance, risk, and conformance indicators, including monitoring implementation.

G336: Develop Integrated PlanLOC (2015)

Developing the integrated plan to govern, assure, and manage performance, risk, and compliance.

G400 Proact
G410 Proactive Actions and Controls

When to use this code: Establishing proactive management, process, human capital, technology, and physical controls, including contract templates and playbooks.

Patterns reviewers commonly see: Template and playbook development billed to individual matters rather than the program.

What invoice review checks: Program-level assets funded at program level; G411 explicitly covers template and playbook development.

G411: Establish Proactive Management Actions and ControlsLOC (2015)

Establishing proactive controls that incent desirable events, including contract template and playbook development.

G412: Establish Preventive Process ControlsLOC (2015)

Establishing preventive process controls, including departmental procedures for consistent provider engagement.

G413: Establish Preventive Human Capital ControlsLOC (2015)

Establishing preventive workforce controls, including role design and background check advice.

G414: Establish Preventive Technology ControlsLOC (2015)

Establishing preventive technology controls, including access control configuration advice.

G415: Establish Preventive Physical ControlsLOC (2015)

Establishing preventive physical controls such as badging and access systems.

G420 Codes of Conduct

When to use this code: Developing, implementing, and managing the code of conduct and ethical decision-making guidelines.

Patterns reviewers commonly see: Full code rewrites where update cycles suffice.

What invoice review checks: Cost per code refresh cycle against the scope of change.

G421: Develop the Code of ConductLOC (2015)

Developing code content with stakeholders, covering mission, values, and key policies.

G422: Implement and Manage the Code of ConductLOC (2015)

Distributing, certifying, and maintaining the code, including training services.

G423: Develop and Implement Ethical Decision-Making GuidelinesLOC (2015)

Developing and implementing decision-making guidelines consistent with organizational values.

G430 Policies

When to use this code: Establishing policy structure, developing policies, and implementing and managing them.

Patterns reviewers commonly see: Per-policy drafting costs varying widely for policies of similar scope.

What invoice review checks: Cost per policy as a unit benchmark across the program.

G431: Establish Policy StructureLOC (2015)

Establishing the organizing structure for policies supporting the capability.

G432: Develop PoliciesLOC (2015)

Developing preventative and directive policy content.

G433: Implement and Manage PoliciesLOC (2015)

Implementing, communicating, and maintaining policies.

G440 Education

When to use this code: Awareness and education planning, curriculum, content, delivery, helpline, and integrated support.

Patterns reviewers commonly see: Custom content development where licensed content meets the need, and helpline services priced without volume data.

What invoice review checks: Build-versus-license decisions on content, and helpline cost per contact.

G441: Define an Awareness and Education PlanLOC (2015)

Developing the enterprise education and awareness plan.

G442: Define a Curriculum PlanLOC (2015)

Developing role-specific curricula for board, management, workforce, and extended enterprise.

G443: Develop or Acquire ContentLOC (2015)

Developing or acquiring training content and updating existing materials.

G444: Implement EducationLOC (2015)

Delivering education programs to learning objectives.

G445: Provide HelplineLOC (2015)

Establishing guidance channels, including outsourced helpline services.

G446: Provide Integrated SupportLOC (2015)

Establishing in-workflow guidance and self-help resources.

G450 Incentives

When to use this code: Conduct-aligned hiring, compensation, and rewards program design.

Patterns reviewers commonly see: Compensation design work overlapping regular employment counsel scope.

What invoice review checks: The advisor-boundary definition, as with B220.

G451: Hire and Promote Based on Conduct ExpectationsLOC (2015)

Embedding conduct expectations in job design, career paths, and reviews.

G452: Develop Compensation and Remuneration that Consider Conduct ExpectationsLOC (2015)

Designing compensation aligned with desired conduct.

G453: Develop Rewards ProgramsLOC (2015)

Establishing recognition programs for conduct and capability contributions.

G460 Stakeholder Relations

When to use this code: Stakeholder analysis, relations planning, authority tracking, and participation in mandate development.

Patterns reviewers commonly see: Regulatory monitoring subscriptions billed as bespoke tracking work.

What invoice review checks: Monitoring service costs against subscription alternatives; G463 explicitly covers tracking services and feeds.

G461: Understand StakeholdersLOC (2015)

Researching stakeholder organizations and individuals, including enforcement temperament profiling.

G462: Develop Stakeholder Relations PlansLOC (2015)

Developing relations and communications plans per constituency.

G463: Identify and Track Activity by Requirement Issuing AuthoritiesLOC (2015)

Tracking significant issuing authorities, including monitoring services and feeds.

G464: Comment on Planned or Proposed ItemsLOC (2015)

Participating in mandate and standards development through comment pathways.

G465: Propose Mandates, Standards or GuidanceLOC (2015)

Proactively proposing mandates and standards to issuing authorities.

G470 Risk Financing

When to use this code: Assessing, designing, and implementing risk financing including insurance, captives, and indemnification structures.

Patterns reviewers commonly see: Placement-adjacent work where broker services already cover it.

What invoice review checks: The counsel-versus-broker division on risk financing. G472 is a designated internal opinion.

G471: Assess Risk Financing Need and OptionsLOC (2015)

Assessing financing needs and options across insurance, captives, and contractual risk transfer.

G472: Set Risk Financing ObjectivesLOC (2015)

Setting risk sharing objectives and limits. Designated internal management opinion; external charges should not apply.

G473: Design Risk Financing StrategyLOC (2015)

Designing the portfolio of risk-sharing instruments.

G474: Implement Risk Financing StrategyLOC (2015)

Implementing instruments and acquiring insurance.

G500 Detect
G510 Detective Actions and Controls

When to use this code: Establishing detective management, process, human capital, physical, and technology controls, and consolidating findings.

Patterns reviewers commonly see: Control design rebilled per business unit where enterprise design applies.

What invoice review checks: Enterprise reuse of control frameworks.

G511: Establish Detective Actions and ControlsLOC (2015)

Establishing detective controls such as fraud reporting and vendor auditing programs.

G512: Establish Detective Process ControlsLOC (2015)

Establishing process controls detecting adverse events, including transaction monitoring design.

G513: Establish Detective Human Capital ControlsLOC (2015)

Establishing workforce reporting controls, including exit interview programs.

G514: Establish Detective Physical ControlsLOC (2015)

Installing surveillance and physical detection controls.

G515: Establish Detective Technology ControlsLOC (2015)

Implementing automated detection technology controls.

G516: Consolidate and Analyze Control FindingsLOC (2015)

Consolidating detection information to identify patterns.

G520 Notification

When to use this code: Hotline and notification system establishment, routing, and data protection compliance.

Patterns reviewers commonly see: Hotline data-protection advice repeated per jurisdiction without a consolidated framework.

What invoice review checks: Jurisdiction-framework reuse; the standard designates routing (G523) as internal.

G521: Capture NotificationsLOC (2015)

Implementing notification systems alerting the organization to suspected noncompliance.

G523: Filter and Route NotificationsLOC (2015)

Vetting and routing notifications for handling. Designated internal management opinion; external charges should not apply.

G524: Adhere to Data Protection RequirementsLOC (2015)

Ensuring hotline pathways comply with local data protection requirements, including anonymity rules.

G530 Inquiry

When to use this code: Surveys, self-assessments, observation programs, and reporting of findings.

Patterns reviewers commonly see: Survey programs run bespoke each cycle.

What invoice review checks: Cost per inquiry cycle over time.

G531: Establish Multiple Pathways to Obtain Workforce and Stakeholder ViewsLOC (2015)

Defining channels for workforce and stakeholder views, including outside-facilitated interviews.

G532: Establish an Organization-Wide Integrated Approach to SurveysLOC (2015)

Establishing integrated survey approaches reducing subject burden.

G533: Establish an Integrated Approach to Self-AssessmentsLOC (2015)

Integrating GRC self-assessment with other assessment programs.

G534: Gather Information Through Observations and ConversationsLOC (2015)

Informal information gathering through observation, focus groups, and interviews.

G535: Report Information and FindingsLOC (2015)

Reporting aggregated inquiry findings to management.

G600 Respond
G610 Responsive Actions and Controls

When to use this code: Establishing responsive and corrective process, human capital, technology, and physical controls, and monitoring them.

Patterns reviewers commonly see: Corrective control design blending into the remediation of specific incidents under G650.

What invoice review checks: The program-versus-incident boundary, which decides whether cost is capability investment or matter cost.

G611: Establish Responsive Actions and ControlsLOC (2015)

Establishing responsive controls including media relations and internal communications programs.

G612: Establish Corrective Process ControlsLOC (2015)

Establishing corrective process controls to stop, slow, and recover from adverse events.

G613: Establish Corrective Human Capital ControlsLOC (2015)

Establishing corrective workforce controls such as authority suspension procedures.

G614: Establish Corrective Technology ControlsLOC (2015)

Establishing corrective technology controls including access restrictions.

G615: Establish Corrective Physical ControlsLOC (2015)

Establishing corrective physical controls including lockdown procedures.

G616: Monitor and Report Corrective ControlsLOC (2015)

Monitoring and reporting corrective control progress.

G620 Internal Investigation

When to use this code: Defining investigation process, preparing, conducting, and reporting internal investigations.

Patterns reviewers commonly see: Investigation scope expanding without checkpoint approvals, blended eDiscovery costs without unit visibility, and privilege posture decisions made implicitly. Investigations are the highest-variance spend category in GRC.

What invoice review checks: Phase budgets at investigation initiation with checkpoint reviews, eDiscovery unit economics read through the L600-series lens, and cost per investigation by matter type as the portfolio benchmark. This sub-phase deserves the most review attention in the entire set.

G621: Define the Inquiry and Investigation ProcessLOC (2015)

Establishing defensible inquiry and investigation procedures and analyzing complaint trends.

G622: Prepare to InvestigateLOC (2015)

Engaging advisors, counsel, investigators, and consultants, including scoping and authorization.

G623: Conduct InvestigationsLOC (2015)

Conducting investigations per plan while maintaining privilege, including documentation and eDiscovery services.

G624: Report Results of InvestigationsLOC (2015)

Communicating results to management, oversight bodies, and regulators as appropriate.

G630 Third-Party Investigations

When to use this code: Preparing for and managing regulator and other third-party investigations, including team selection and response.

Patterns reviewers commonly see: Response teams staffed beyond the matter's regulatory exposure, and duplicated workstreams between regular counsel and specialist investigation counsel.

What invoice review checks: Team composition against exposure, and the division of labor defined at engagement. G632 is a designated internal item.

G631: Prepare for and Address Third Party InquiriesLOC (2015)

Identifying and responding to third-party questions, including engaging response advisors.

G632: Prepare to Identify Third Party InvestigationsLOC (2015)

Establishing methods to surface initiated third-party investigations. Designated internal management opinion; external charges should not apply.

G633: Prepare to Manage Third Party InvestigationsLOC (2015)

Establishing policies and responsibility for managing investigation types, including media relations.

G634: Prepare to Select Team for Third-Party InvestigationLOC (2015)

Establishing team selection procedures, including preferred provider arrangements.

G635: Prepare to Respond to Specific Third-Party InvestigationsLOC (2015)

Establishing response development procedures for specific investigations.

G640 Crisis Response

When to use this code: Crisis and continuity planning, team identification, testing, and plan coordination.

Patterns reviewers commonly see: Plan development without testing follow-through, since untested plans are the common failure mode.

What invoice review checks: The plan-to-test cost ratio; G643 testing spend validates G641 planning spend.

G641: Develop Crisis Response and Continuity PlansLOC (2015)

Developing crisis response, continuity, and disaster recovery plans.

G642: Identify Crisis Readiness and Response TeamsLOC (2015)

Defining preparedness and response team personnel, including pre-identified external advisors.

G643: Test Plans and ProceduresLOC (2015)

Testing and evaluating crisis plans and procedures.

G644: Coordinate PlansLOC (2015)

Reconciling continuity and response plans across facilities.

G650 Remediation

When to use this code: Resolving reported issues, documenting outcomes, proposing capability changes, and individual discipline.

Patterns reviewers commonly see: Remediation advice detached from root-cause pattern analysis.

What invoice review checks: Remediation deliverables should propose capability changes, not just close incidents. G652 discipline is a designated internal action.

G651: Remediate the GRC CapabilityLOC (2015)

Resolving reported issues, documenting outcomes, and proposing capability improvements from root-cause patterns.

G652: Discipline IndividualsLOC (2015)

Disciplining individuals for misconduct. Designated internal management action; external charges should not apply.

How should legal departments use governance, risk and compliance codes in invoice review?

GRC review is a capability-allocation exercise. Confirm that program-level capability work is charged to the program rather than a specific matter, watch for the codes the standard flags as internal management where external billing should not apply, and read capability spend against the maturity goals it is meant to advance.

Mapping GRC codes to a maturity model only works when the eBilling or matter system captures them at the capability level, which is where legal technology implementation matters: the capability-to-maturity mapping belongs in the system so compliance investment can be tracked against the program it funds.

How do Governance, Risk and Compliance Codes support legal spend management?

Governance, Risk and Compliance Codes only deliver value inside a program that enforces them. Our legal spend management and enterprise legal management hubs cover how coded invoices become spend control, and our guides to building a legal spend management program, spend analytics versus reporting, and what to put in outside counsel billing guidelines go deeper on the review programs, guidelines, and eBilling rules that put UTBMS coding to work.

Bottom Line

GRC is the only UTBMS set that maps spend onto an external maturity model, which makes it uniquely useful for legal departments managing compliance programs rather than matters. Coded at the capability level, it shows where governance investment concentrates and whether program work is being charged as program work. The internal-management flags keep that picture honest.

Coded to OCEG capability, GRC spend stops being a diffuse cost and becomes a map of where your compliance program is actually funded.

Frequently asked questions

What are UTBMS GRC codes used for?

They structure governance, risk, and compliance work across the six OCEG capability components: Context, Organize, Assess, Proact, Detect, and Respond. This lets a legal department map compliance program spend, investigations, and risk advisory onto a recognized capability and maturity model.

Why do GRC annotations appear at the sub-phase level?

GRC engagements are scoped and reviewed at the capability-area level rather than by individual task, so the usage, watch-for, and review-signal guidance lives once at each sub-phase (G110, G120, and so on) above its task codes. Each task code still carries its own description.

What makes the GRC set different from other UTBMS sets?

It is the only UTBMS set built on an external management framework, the OCEG GRC Capability Model. That means coded GRC spend maps directly onto a maturity model, so the codes measure not just cost but where a compliance program is being invested in.

How should GRC codes be used in invoice review?

Confirm that program-level capability work is charged to the program rather than a single matter, watch for codes the standard designates as internal management, and read spend against maturity goals. Each capability area below lists what reviewers watch for and what invoice review checks.

How do UTBMS codes relate to outside counsel billing guidelines and legal spend management?

UTBMS codes are the shared vocabulary that outside counsel billing guidelines and a legal spend management program depend on. Guidelines define what each code should and should not contain, the eBilling system enforces those rules, and consistent coding is what makes spend analytics and cross-firm benchmarking possible. Without agreed codes, guidelines cannot be enforced and spend data cannot be compared.

About this reference

UTBMS code sets are standards published by their respective bodies, including the ABA, the LEDES Oversight Committee, UTBMS.com, the CBA, DRI, the Judiciaries of England and Wales, and the Yerra Global KM Expert Group. All copyrights and trademarks are the property of their respective owners; Swiftwater & Company is not affiliated with or endorsed by any of them.

Code identifiers follow the published standards, while all descriptions and annotations are original Swiftwater commentary, developed with human expertise, proprietary consulting knowledge, and AI assistance.

This is general reference material, not legal advice. Standards are revised over time, so confirm the current version with the originating body before implementing.

Next Step

Ready to talk to a legal operations practitioner who has actually done it?

Start with the free CURRENT Assessment to benchmark your spend program, or use legaltechcalculator.com to build the cost case for the eBilling rules that enforce these codes.

Book a Discovery Call

No commitment and no pitch deck, just a direct conversation with a legal operations practitioner.