We recently acquired a new Governance, Risk, and Compliance system and have been migrating policies, automating evidence collection, and using the built-in tests to identify issues. We’d had our previous system for many years, and I’m impressed by how much these tools have improved since I’d last looked. It’s already clear the new tool will save time, not just for the compliance team but for the entire engineering organization. I’m looking forward to less shuffling of screenshots, spreadsheets, and PDFs, and I especially won’t miss wasting the software and deployment engineers’ time with meetings to tick through access lists and scan reports.

The GRC system is facilitating many of the activities of our security and compliance team, including:

  • Ensuring compliance with the requirements of all the frameworks we observe
  • Managing policies, procedures, standards, and other documentation
  • Collecting evidence for and managing audits
  • Tracking program improvements
  • Hosting a trust center for current and prospective customers
  • Conducting third-party assessments (the system we have meshes nicely with my lean but targeted approach)
  • Managing customer security questionnaires
  • Keeping a risk registry
  • Inventorying assets

Choosing a system with a large number of built-in of integrations (linkages to other SaaS services and IT systems) was wise—every time we integrate the GRC system with another existing IT system, we discover new vulnerabilities or broken processes.

But strategically, I’m most excited about the automated testing, which boosts our program from merely achieving to fully monitoring compliance. At this level, compliance really gets tied back to security because if the tests are properly designed, when they fail, they’ve found a security issue you need to address.

There are of course some systems for which no integrations have been built. The GRC system’s API becomes very important here. The more fully developed the API is, the easier it will be for you to write your own automations. Ours also has its own Model Context Protocol (MCP) service. Between the API and the MCP, it’s easy to have an LLM like Claude develop the automations for you. That’s how I automated the migration of our existing trust center FAQ to the new GRC system (which has a built-in, integrated trust center), a task which otherwise would have cost an employee hours of time and much of the feeling in their mouse-clicking hand.