Reference
Every GRC and compliance tool, in one place.
109 governance, risk and compliance platforms, sorted into 12 categories you can actually compare: SOC 2 and ISO 27001 automation, enterprise GRC, AI governance, privacy, third-party risk, questionnaires, and the tools built for one regulation. Free, no signup, no vendor pays to appear.
Browse by what you need
Each vendor describes itself differently, so every one is sorted into a category you can compare across.
- SOC 2 and ISO 27001 automation25Gets a company audit-ready and keeps it there. Connects to your stack, collects evidence continuously, and maps it to SOC 2, ISO 27001 and similar frameworks.
- Enterprise GRC platform25Runs the whole governance, risk and compliance programme in one place: risk register, policies, controls, and audit workflow across many frameworks at once.
- AI governance11Governs AI systems themselves. Model inventories, risk classification, and evidence for the EU AI Act, ISO 42001 and internal AI policy.
- Privacy and data governance11Finds personal data, maps where it flows, and handles consent and subject requests under GDPR, CCPA and the rest.
- Industry-specific10Purpose-built for one regulation or sector, such as CMMC for defense suppliers or the EU Cyber Resilience Act.
- Healthcare compliance6Built for HIPAA, clinical and life-sciences obligations, including credentialing and validated systems.
- Financial services compliance5Covers AML, KYC, recordkeeping and supervision duties for regulated financial firms.
- Third-party risk4Assesses and monitors the vendors you buy from, from onboarding due diligence through continuous monitoring.
- Compliance training4Delivers and tracks the training and attestations that most frameworks require of staff.
- Questionnaires and trust centers3Answers inbound security questionnaires and publishes a trust center, so a buyer's review stops blocking your sales cycle.
- Supply chain and ESG3Tracks obligations that run through suppliers: CSRD and ESG reporting, product compliance, and customs.
- Tax and e-invoicing2Handles sales tax, VAT and the country-by-country e-invoicing mandates now coming into force.
Common questions
- What is GRC software?
- Governance, risk and compliance software helps an organisation prove it is meeting its obligations. In practice that means collecting evidence, tracking controls and risks, managing policies, and producing what an auditor asks for without rebuilding it by hand each year.
- What kinds of compliance tools are there?
- They fall into 12 broad groups: audit-readiness automation for SOC 2 and ISO 27001, enterprise GRC platforms, AI governance, privacy and data governance, third-party risk, security questionnaires and trust centers, healthcare, financial services, supply chain and ESG, tax and e-invoicing, training, and tools built for one specific regulation.
- How do I choose between them?
- Start from the obligation you actually have. A startup that needs one SOC 2 report buys a different product from a bank running supervision duties or a manufacturer facing CSRD. Company size, the frameworks in scope, and whether you need auditor access matter far more than feature counts.
How this list is built
Inclusion needs a live product and a compliance, risk or audit product as the main offering. Nobody pays to be listed. Categories are our editorial call, and each vendor's own wording is kept on its page so you can disagree with it. Listings point at a company's own site and are worth confirming before you act on them. Read the methodology.
For how SOC 2, GDPR, HIPAA and the other major frameworks map to identity and access controls specifically, see CIAM Compass.