Protect cluster · GRC, legal
Technology Rewired: Governance, Risk and Compliance
Governance, risk and compliance moved from spreadsheets, consultants, and annual audits to SaaS platforms that connect to cloud systems and monitor controls. Agents now collect evidence, map controls across frameworks, and draft answers to security questionnaires. Auditors and compliance leads still own judgment, exceptions, and the signature on the report.
The shift: Continuous, agent-collected evidence replaces annual audits.
Supervised agents today
4.0 in five years
How has the governance, risk and compliance team changed across five eras?
Era 1 · On-prem
Before 2005
0.2Compliance was a project, not a system. A compliance manager and outside consultants gathered screenshots, policies, and sign-offs into shared folders before each audit. I ran this work at Sageworks, building the SOC 2, PCI, and ISO programs, and most of the effort was collecting the same evidence again every year.
Era 2 · SaaS and cloud
2005 to 2020
1.2GRC platforms and then compliance automation tools connected to cloud providers, identity systems, and HR tools and checked controls on a schedule. Startups could reach SOC 2 without a full-time compliance hire, which I explain in SOC 2 for startups. Teams added security questionnaire owners and vendor risk analysts.
Era 3 · AI-assisted
2020 to 2024
2.0AI suggested policy text, mapped controls between frameworks, and drafted questionnaire answers from past responses. A person still checked every answer before it went to a customer.
Era 4 · Agentic
2024 onward
2.8Agents now pull evidence from connected systems, flag failing controls, draft remediation tickets, and answer questionnaires from a trust library, with a human reviewing what goes out. The vendor landscape is in compliance automation platforms compared. The hard limit is that an auditor's opinion and a company's attestation are human acts with legal weight.
GRC teams also inherit AI governance itself: inventories of models and agents, and policies for what they may touch.
Era 5 · Next 5 years
2026 to 2031
4.0My bet: point-in-time audits give way to continuous assurance, where agents keep evidence current and auditors sample and test the agents' work. GRC teams get smaller on evidence collection and larger on risk judgment, AI governance, and regulator relationships.
Which governance, risk and compliance software is being rewired?
- SOC 2 and Compliance Automation
SOC 2 and compliance automation has moved from spreadsheets, screenshots and consultant-run annual audits to SaaS platforms like Vanta and Drata that pull evidence through integrations. Since 2025, AI agents collect and evaluate evidence, map controls across frameworks, and draft security questionnaire answers, while humans still own risk decisions and a licensed auditor still signs the opinion.
Coming next
- Security questionnaires
- Vendor risk management
- Policy management
- Audit management
- Privacy and consent management
- Contract management (CLM)
- E-signature
- AI governance
Also wired into this category: Identity and Access Management (IAM and CIAM), SIEM and SOC Platforms.
Keep reading
Essays and analysis
- Compliance Automation Platforms Compared (2026): Vanta vs Drata vs Sprinto vs Secureframe vs Scytale vs Thoropass
- Demystifying SOC 2 Compliance for Startups: A Simple Guide
- SOC 2 Policies: What Founders Actually Need to Write
- The Shadow AI Governance Crisis: Why 80% of Fortune 500 Companies Have Already Lost Control of Their AI Infrastructure
- Cybersecurity Compliance and Regulatory Frameworks: A Comprehensive Guide for Companies