Pergunta de entrevista da empresa Deloitte

IT Risk Management process.. How would you implement it? How would you use a GRC tool and where would it fit in?