Skip to content
Draft. This page is in editorial review and is not indexed yet.

Protect cluster · GRC, legal

Technology Rewired: Governance, Risk and Compliance

Governance, risk and compliance moved from spreadsheets, consultants, and annual audits to SaaS platforms that connect to cloud systems and monitor controls. Agents now collect evidence, map controls across frameworks, and draft answers to security questionnaires. Auditors and compliance leads still own judgment, exceptions, and the signature on the report.

The shift: Continuous, agent-collected evidence replaces annual audits.

Verified
2.8

Supervised agents today
4.0 in five years

How has the governance, risk and compliance team changed across five eras?

  1. Era 1 · On-prem

    Before 2005

    0.2

    Compliance was a project, not a system. A compliance manager and outside consultants gathered screenshots, policies, and sign-offs into shared folders before each audit. I ran this work at Sageworks, building the SOC 2, PCI, and ISO programs, and most of the effort was collecting the same evidence again every year.

  2. Era 2 · SaaS and cloud

    2005 to 2020

    1.2

    GRC platforms and then compliance automation tools connected to cloud providers, identity systems, and HR tools and checked controls on a schedule. Startups could reach SOC 2 without a full-time compliance hire, which I explain in SOC 2 for startups. Teams added security questionnaire owners and vendor risk analysts.

  3. Era 3 · AI-assisted

    2020 to 2024

    2.0

    AI suggested policy text, mapped controls between frameworks, and drafted questionnaire answers from past responses. A person still checked every answer before it went to a customer.

  4. Era 4 · Agentic

    2024 onward

    2.8

    Agents now pull evidence from connected systems, flag failing controls, draft remediation tickets, and answer questionnaires from a trust library, with a human reviewing what goes out. The vendor landscape is in compliance automation platforms compared. The hard limit is that an auditor's opinion and a company's attestation are human acts with legal weight.

    GRC teams also inherit AI governance itself: inventories of models and agents, and policies for what they may touch.

  5. Era 5 · Next 5 years

    2026 to 2031

    4.0

    My bet: point-in-time audits give way to continuous assurance, where agents keep evidence current and auditors sample and test the agents' work. GRC teams get smaller on evidence collection and larger on risk judgment, AI governance, and regulator relationships.

Which governance, risk and compliance software is being rewired?

  • 2.8
    SOC 2 and Compliance Automation

    SOC 2 and compliance automation has moved from spreadsheets, screenshots and consultant-run annual audits to SaaS platforms like Vanta and Drata that pull evidence through integrations. Since 2025, AI agents collect and evaluate evidence, map controls across frameworks, and draft security questionnaire answers, while humans still own risk decisions and a licensed auditor still signs the opinion.

Coming next

  • Security questionnaires
  • Vendor risk management
  • Policy management
  • Audit management
  • Privacy and consent management
  • Contract management (CLM)
  • E-signature
  • AI governance

Also wired into this category: Identity and Access Management (IAM and CIAM), SIEM and SOC Platforms.