Skip to content

Reference

Every GRC and compliance tool, in one place.

109 governance, risk and compliance platforms, sorted into 12 categories you can actually compare: SOC 2 and ISO 27001 automation, enterprise GRC, AI governance, privacy, third-party risk, questionnaires, and the tools built for one regulation. Free, no signup, no vendor pays to appear.

Browse by what you need

Each vendor describes itself differently, so every one is sorted into a category you can compare across.

Common questions

What is GRC software?
Governance, risk and compliance software helps an organisation prove it is meeting its obligations. In practice that means collecting evidence, tracking controls and risks, managing policies, and producing what an auditor asks for without rebuilding it by hand each year.
What kinds of compliance tools are there?
They fall into 12 broad groups: audit-readiness automation for SOC 2 and ISO 27001, enterprise GRC platforms, AI governance, privacy and data governance, third-party risk, security questionnaires and trust centers, healthcare, financial services, supply chain and ESG, tax and e-invoicing, training, and tools built for one specific regulation.
How do I choose between them?
Start from the obligation you actually have. A startup that needs one SOC 2 report buys a different product from a bank running supervision duties or a manufacturer facing CSRD. Company size, the frameworks in scope, and whether you need auditor access matter far more than feature counts.

How this list is built

Inclusion needs a live product and a compliance, risk or audit product as the main offering. Nobody pays to be listed. Categories are our editorial call, and each vendor's own wording is kept on its page so you can disagree with it. Listings point at a company's own site and are worth confirming before you act on them. Read the methodology.

For how SOC 2, GDPR, HIPAA and the other major frameworks map to identity and access controls specifically, see CIAM Compass.