For years, Governance, Risk, and Compliance (GRC) systems weren’t much more than specialized document repositories. They might integrate with some of your tooling, such as a vulnerability scanner, in some basic way. We did use one, as it helped us map controls of a framework, like ISO 27001 or NIST SP 800-171, to evidence, such as policies, procedures, or other documentation that demonstrate compliance. Then we could easily identify any controls we hadn’t addressed. But we still spent hours manually collecting evidence— shuffling screenshots, spreadsheets, and PDFs, and eating up product engineers’ time with meetings whose entire content could be summarized as, “Yes, that access list is still correct, please let me get back to my actual job.” And validating all this material was also a soul-crushing, manual process, poring over reams of documentation every audit cycle for any needed changes, broken links, or anything else that was missing.
Three things have changed. First, applications have moved from on-premise to the cloud, and they have developed APIs that allow them to communicate and integrate much more easily than before. I can have my vulnerability management tool create Jira tickets, for example, and while that was possible in the data center, it takes seconds today. Second, artificial intelligence has reached the point that anyone, regardless of technical skill level, can create de facto integrations when they aren’t provided.
Now, it’s probably clear from my other posts that I’ve enjoyed programming for a long time, but that doesn’t mean my hobbyist-level skill and pace match the demands of our business. Yet with AI and our GRC system’s rich API and its own Model Context Protocol (MCP) service, we can automate evidence collection and testing in minutes, even where no built-in integration exists. Example: we were able to automate the migration of our existing trust center FAQ to the new GRC system’s built-in, integrated trust center, a task which otherwise would have cost an employee hours of time and much of the feeling in their mouse-clicking hand. This possibility for AI-based automation is the most exciting prospect, especially for small compliance departments with limited resources.
That’s not to say the full power of AI is needed for all or even most
of our evidence collection and testing tasks. The best modern GRC
systems come with hundreds of pre-built integrations that take full
advantage of the APIs of popular cloud services. Within days of
acquiring our GRC system, we integrated it with single sign-on,
vulnerability management, software forge (complete with static
analysis vulnerability findings, if you enjoy drinking from a
firehose), asset management, phishing and awareness training system,
and other services. It immediately found handfuls of stale accounts,
including one called temp—great. These and other gaps were
easily mitigated now that we knew about them. This automated testing
boosts our program from merely achieving compliance to fully
monitoring it and improving security in tangible ways.
So when you’re evaluating your next GRC system, do peruse the pre-built integrations in the vendor’s marketing deck, but also ask about the API and whether it has an MCP service. A well-documented API paired with an AI that can read it means you’re no longer waiting on a vendor’s roadmap—you can build the automation yourself, in an afternoon, without writing a line of code you’d recognize as code. That’s the real shift: it’s not that GRC systems got smarter, it’s that the barrier to automating around their gaps basically disappeared.