Bert Kondruss, KonBriefing Research
On this page you will find the latest news, trends and developments in GRC tools, with a strong focus on AI. From companies and markets around the world. Curated for industry professionals, product managers, and decision-makers.
Both perspectives are taken into account: the use of AI within GRC tools, as well as the use of GRC tools for the oversight and governance of AI. Key questions: How can AI be applied in the GRC context? And what are specific use cases for AI in Governance, Risk & Compliance? What do GRC vendors do?
 

GRC News January 2026

January 14, 2026 - CoreStream GRC

Short videos from CoreStream

CoreStream GRC has released five short videos demonstrating various features: Compliance management, conflict of interest, gift and hospitality management, policy management, and action tracking.
https://www.youtube.com/@CoreStreamGRC/videos...
January 12, 2026 - Donald Farmer, TreeHive Strategy

AI governance: Lineage and provenance – Distinguishing between data origin and the creation of a specific result in RAG systems

The article describes a very interesting aspect of AI governance in RAG systems (Retrieval-Augmented Generation): Here, it is not only important to know where the data comes from and how it enters the system (lineage), but also the history of each individual data point and output (provenance) with the origin of each chunk, the time of recording, changes, and the context in which it was retrieved.
https://irmuk.co.uk/2026/01/article-ai-governance-...
January 9, 2026 - Wolters Kluwer

Wolters Kluwer acquires GRC tool vendor StandardFusion

The international information and software group Wolters Kluwer is acquiring the Canadian GRC software provider StandardFusion. The GRC software will be integrated into the TeamMate platform.
https://www.wolterskluwer.com/en/news/wolters-kluw...
January 6, 2026 - Axiom GRC

With AssurancePoint, Axiom GRC acquires another US GRC service provider

Axiom GRC, the company that owns CoreStream, is acquiring another US service provider and integrating it into IS Partners, which was acquired in November 2025.
https://www.prnewswire.com/news-releases/axiom-grc...
January 6, 2026 - Swiss GRC

Swiss GRC listed in the Forrester GRC Landscape

Swiss GRC is delighted to be the only provider from the DACH region to be named in Forrester's latest Governance, Risk, and Compliance Platforms Landscape, Q4 2025.
https://swissgrc.com/en/news/swiss-grc-included-in...
 

GRC News December 2025

December 16, 2025 - Vanta

Vanta compares itself with Drata and Delve

Another episode of a self-made comparison with other products
https://www.vanta.com/resources/vanta-vs-drata-vs-...
December 12, 2025 - Vanta

New in Vanta in December 2025

Vanta has introduced new AI-powered features for rapid policy creation and editing, structured risk and data protection management (including ROPAs), more efficient vendor assessments, direct security responses in Slack, and numerous new and improved integrations for greater transparency and automation.
https://www.vanta.com/resources/new-in-vanta-decem...
December 11, 2025 - GRC Report / Samuel Rasmussen

AI requires real-time governance

This article argues that the central risk of modern AI is not individual malfunctions, but rather the growing gap between the rapid development of AI systems and the slow cycles of regulation and governance.
https://www.grcreport.com/post/when-ai-moves-faste...
December 10, 2025 - HiSolutions

Introduction of an ISMS according to ISO 27001 using agile methods

Implementation with Scrum and Git; English audio track available.
https://www.youtube.com/watch?v=4ngy_FHcAwQ...
December 10, 2025 - Joshua's Tech Tips

Demo of the open source tool CISO Assistant

56:25
CISO Assistant is a GRC application that is also available as an open source version under AGPL.
https://www.youtube.com/watch?v=0YqJHkqYaU8...
December 10, 2025 - Neumetric

GDPR Privacy Audit Scanner

The Indian provider has announced a 'GDPR Privacy Audit Scanner,' a continuous monitoring tool for data protection. However, details on how it works remain unclear.
https://www.neumetric.com/journal/gdpr-privacy-aud...
December 9, 2025 - Battleground Group, Yields

Interactive simulation of an AI crisis in a company

53:00
Simulated crisis simulation: After 1,800 test applications, a journalist reports that a large company's AI-supported screening of resumes is biased. Is this a crisis? Who should be on the crisis management team? How to communicate externally and internally? With results from interactive participation in this webinar and commentary from the experts involved.
https://www.youtube.com/watch?v=s4yafVZ-Wb8...
December 8, 2025 - BABL AI

Insights into the work of an AI compliance officer

42:35
Discussion round on the question of what it actually means to be responsible for AI risks, compliance, and governance in a modern company.
https://www.youtube.com/watch?v=gIilYGV4qUY...
December 8, 2025 - Vanta

Vanta compares itself with Drata and Auditboard

Vanta continues her series of comparative articles. Drata has also published similar articles.
https://www.vanta.com/resources/vanta-vs-drata-vs-...
December 7, 2025 - Audit Control Governance Risk and Compliance

Introductory series on ISO 42001

20:17
Another video from a series on ISO 42001.
https://www.youtube.com/watch?v=q8SMnuVDKMQ...
December 4, 2025 - Drata

Demo: Workflows definition in Drata

2:02
Brief introduction to the definition of no-code workflows.
https://www.youtube.com/watch?v=IGxO2hJ8KKU...
December 4, 2025 - Swimlane

Business Continuity Management mit Swimlane Turbine

3:44
This short demo shows how BCM is handled in Swimlane Turbine, an AI platform for IT security.
https://www.youtube.com/watch?v=mkN6Mx70Nuo...
December 2, 2025 - Gartner

Where do GRC platforms stand today?

Where are GRC platforms headed, where does Agentic AI stand, and what should buyers look for when choosing a platform?
https://www.forrester.com/blogs/grc-platforms-ente...
December 1, 2025

With Openli, Triple Private Equity acquires its fourth Danish GRC provider

Following the acquisition of RISMA, ComplyCloud, and Wired Relations in July 2025, investor Triple Private Equity is now acquiring another tool provider from Denmark: Openli.
https://www.complycloud.com/blog/triple-strengthen...
 

GRC News November 2025

November 28, 2025 - Risma Systems, Wired Relations, ComplyCloud

Newly united founding trio from Denmark presents joint vision for an integrated GRC future

Joint statement by the founders of Risma Systems, Wired Relations, and ComplyCloud, which recently merged under a private equity umbrella. They explain how their combined strengths will be incorporated into a new integrated GRC solution. Their aim is not only to further mature the Danish market, but also to address Nordic and European markets.
November 27, 2025 - miss cyberpenny by Jane Lo

AI Agents as a new insider threat

22:33
This interview highlights new threats posed by AI agents and Agentic AI.
https://www.youtube.com/watch?v=yoxEGJmbuLY...
November 26, 2025 - Conveyor

Demo: AI agent in the Trust Center

3:35
In this video, Conveyor demonstrates how an AI chatbot supports the use of their Trust Center.
https://www.youtube.com/watch?v=jYG7ziD8yiQ...
November 20, 2025 - SAP

AI-powered GRC tools – from SAP's perspective

An article from SAP on the capabilities and challenges of AI-powered GRC tools.
https://www.sap.com/spain/resources/ai-powered-grc...
November 19, 2025 - SmartSuite

Various AI use cases for GRC in SmartSuite

59:41
Demo in policy management, risk management, third-party risk management, evidence assessment, control mapping, and incident handling.
https://www.youtube.com/watch?v=iJkJPkYswso...
November 19, 2025 - GBTEC Group

GRC implementation at Universal Investment with GBTEC

28:15
Presentation at the BIC User Conference on the introduction of various practices based on the BIC GRC tool at a financial services provider. The presentation highlights the advantages of the chosen self-service approach, in which the customer made important adjustments independently.
November 18, 2025 - Complyance Ltd

Free vendor risk scoring tool from Complyance

With the 'Vendor Risk Scorer', Complyance has released a free and publicly accessible tool for assessing supplier risks, which is also integrated into the Complyance platform. The tool searches various databases and, in testing, provided a summary, while the detailed report is available upon providing an email address.
https://score.complyance.com/
November 18, 2025 - Vanta

Vanta introduces 'Agentic Trust Platform'

Vanta presents the new Agentic Trust Platform, which uses Vanta AI Agent 2.0 to link and automate security, compliance, and risk processes. The equally new Risk Graph links internal and external risks to provide a holistic view. Customer Commitments provides a tool for tracking and fulfilling given commitments.
https://www.vanta.com/resources/introducing-vantas...
November 18, 2025 - Risk Professionals / Wasim Malik

Webinar on the implementation of ISO 42001 - Part 2

1:02:15
This second part shows how to set up an AI Management System (AIMS) in practice, ideally integrating it with existing systems such as ISO 27001 (ISMS) and ISO 22301 (BCM), and how the certification audit is then carried out.
https://www.youtube.com/watch?v=iBDGf_sqUqo...
November 17, 2025 - Business Continuity Institute (BCI) / Wasim Malik

BCM in the AI era

AI systems fail differently than traditional IT systems: technically, they remain functional, but may make incorrect, biased, or business-damaging decisions without anyone noticing. That is why classic approaches to business continuity management, such as ISO 22301, need to be expanded to include new concepts.
https://www.thebci.org/news/when-ai-fails-everythi...
November 11, 2025 - Sprinto

AI functionalities in Sprinto

The GRC platform Sprinto has introduced a range of AI functions with Sprinto AI, e.g., in risk management and questionnaires, and there is also control mapping and an AI chat function. In addition, the AI Playground allows users to define their own AI functions.
https://sprinto.com/blog/introducing-ai-powered-ri...
https://sprinto.com/blog/introducing-ai-powered-co...
https://sprinto.com/blog/introducing-ai-powered-in...
https://sprinto.com/blog/introducing-ai-playground...
November 6, 2025 - CoreStream GRC

Short videos on use cases in CoreStream

Including short screen recordings and references to the AI ​​bot. The bot is explicitly described as 'optional'. One screenshot shows a request not to enter any PII so that it is not sent to ChatGPT.
https://www.youtube.com/watch?v=VGodXFim6Lo...
https://www.youtube.com/watch?v=CiqN-vFncbo...
https://www.youtube.com/watch?v=i3YHsqDnxU0...
https://www.youtube.com/watch?v=-ZeXIFqTjUk...
November 5, 2025 - risk3sixty

Experience report on the introduction of an AI management system according to ISO 42001

1:01:33
Juvare, a provider of emergency management solutions, reports on its implementation of ISO 42001 and certification, supported by risk3sixty.
https://www.youtube.com/watch?v=JrsuKHVrtCo...
November 4, 2025 - Security Boulevard / OneTrust

Another urgent warning: AI agents will radically change GRC

It's just a short text, but it sums up what's happening right now: Agentic AI will completely transform GRC processes in companies. Even if the first thesis is somewhat bold in the literal sense, namely that agents will 'solve' the chaos of information, they will nevertheless make it manageable. And this makes the further predictions realistic: elimination of silos, acceleration, and real-time support for business processes.
Blake Brannon:Chief Product and Strategy Officer of OneTrust
https://securityboulevard.com/2025/11/ai-agents-ma...
November 4, 2025 - Diligent

Diligent is a Leader in the Gartner MQ for Governance, Risk and Compliance Tools, Assurance Leaders

In addition to Gartner, the article lists four other successful analyst evaluations. It also highlights the solution's AI capabilities.
https://www.diligent.com/resources/blog/2025-gartn...
 

GRC News October 2025

October 30, 2025 - MaryEllen O'Connell

Study: Use of AI risk scorecards in GRC

Result: The use of AI risk scorecards can bring significant efficiency gains. At the same time, success does not come automatically; it depends heavily on the integration of governance structures, in particular Explainable AI (XAI).
https://papers.ssrn.com/sol3/papers.cfm?abstract_i...
October 29, 2025 - SmartSuite

Demo: GRC with SmartSuite

1:00:24
This webinar shows how GRC processes are mapped on the no-code SmartSuite platform and how AI can be used, e.g., for risk scoring.
https://www.youtube.com/watch?v=bAisMA44ICA...
October 29, 2025 - Empowered GRC

Release-Demo of Connected Risk v25.3.0

6:49
This video shows the first AI integration, which is only available to hosting customers.
https://www.youtube.com/watch?v=EIjTNoFfB4Y...
October 2025 - The British Standards Institution

Survey on the status of AI in companies, including AI governance

This British study analyzed 123 annual reports on the topic of AI and surveyed 850 specialists and executives.
https://www.bsigroup.com/en-GB/insights-and-media/...
October 28, 2025 - Formalize

Formalize collects €30 million in Series B financing for further expansion, with focus on SMEs in Germany/Austria/Switzerland, and France

The Danish vendor raises €30 million for further expansion. The focus is on the DACH region (Germany, Austria, Switzerland) and France, with plans to expand the Munich office to 30 employees.
https://formalize.com/en/formalize-raises-30-milli...
October 27, 2025 - Risk Professionals / Wasim Malik

Webinar on the implementation of ISO 42001 - Part 1

Excellent introduction to ISO 42001 with examples and tips for integration with ISO 27001.
https://www.youtube.com/watch?v=jfjw_HHv-m4...
October 24, 2025 - Cloud Security Alliance

Cloud Security Alliance activities related to the security of Agentic AI

Overview of the CSA's extensive activities, including: 7-layer reference architecture for Agentic AI; MAESTRO for threat modeling; Risk Rubric for evaluating LLMs.
Jim Reavis:CEO, Cloud Security Alliance
October 23, 2025 - ServQual

Demo video of the SUSAN compliance platform

https://www.youtube.com/watch?v=EvUIHP_0F4s...
October 22, 2025 - Cloud Security Alliance

How AI improves institutional memory

Until now, logs only explained what happened. With conversation-based AI interfaces (e.g., MCP), the 'why' is also documented as a byproduct. This records both the human's reasoning and the AI's reasoning, fundamentally improving traceability and auditability.
Kurt Seifried:Chief Innovation Officer, CSA
https://cloudsecurityalliance.org/blog/2025/10/22/...
October 22, 2025 - Forrester

Forrester's AEGIS framework as a mapping of other frameworks for AI governance

In this article, Forrester presents how its AEGIS framework for AI governance maps to other standards such as ISO 42001 and NIST AI RMF.
AI Governance AI Regulation
https://www.forrester.com/blogs/forrester-aegis-th...
October 21, 2025 - Hive Systems

Presentation of 'Derive'

Derive combines cyber risk management, governance, and operations, and aims to replace traditional GRC platforms.
https://www.youtube.com/watch?v=hcYbccZQ6Aw...
October 19, 2025 - CAIF

Training video: Embedding AI risks into enterprise risk management

How can AI risks be integrated into a company's GRC processes, and how do they fit in with frameworks such as ISO 31000 and COSO ERM?
https://www.youtube.com/watch?v=f7lkElsg4oQ...
October 17, 2025 - Safeshield Training

Fairness and Non-Discrimination in AI Systems

Good overview of this topic from a governance and compliance perspective.
https://www.youtube.com/watch?v=w3P6mTI8SkU...
October 16, 2025 - CompliSolv / MohaMar LLC

CompliSolv: a new AI-supported compliance platform specializing in US financial institutions

With over 82,000 requirements recorded, structured by topic and subcategory, the platform aims to help financial institutions comply with complex compliance requirements. The new system is scheduled to be unveiled on October 19.
CompliSolv:Regulatory intelligence; founded 2024
John Martini:Founder
October 15, 2025 - RegASK

RegASK launches AI command center

RegASK, a provider of AI-powered regulatory intelligence, announces the launch of the 'Action Hub', an agentic AI command center for regulatory affairs.
RegASK:Regulatory intelligence; HQ: Singapore, offices in the US and in Switzerland; founded 2018; approx. 60 employees
Caroline Shleifer:Founder and CEO
Amenallah Reghimi:Chief Product and Technology Officer
https://regask.com/regask-launches-first-vertical-...
October 15, 2025 - LatticeFlow AI

Integration of Vanta with LatticeFlow

LatticeFlow, a provider of solutions for trustworthy and compliant AI, announces an integration with Vanta. The collaboration connects technical evaluations of AI systems with Vanta’s governance and compliance workflows, helping organizations deploy AI securely and in compliance with regulations.
LatticeFlow AI:Solutions for AI Governance; HQ: Zurich (Switzerland), offices in Bulgaria and the US; founded 2020; approx. 30 employees
https://latticeflow.ai/news/latticeflow-ai-vanta-t...
October 15, 2025 - Kovrr

Kovrr Launches New Modules for AI Risk Assessment and Quantification

Kovrr, a provider of cyber, GRC, and risk modeling solutions, announced the launch of its new AI Risk Assessment and AI Risk Quantification modules. The tools help organizations gain visibility into AI risk, evaluate governance maturity, and quantify potential financial losses from AI-related incidents.
October 14, 2025 - Onspring Technologies

Onspring launches AI capabilities

These include content generation, recommendations for related content, redundancy detection, OCR, and a workbench for editing prompts. The basis is Claude from Anthropic.
Onspring:GRC platform; HQ: Overland Park, KS (USA); founded 2010; approx. 120 employees.
https://onspring.com/introducing-onspring-ai/...
October 14, 2025 - Qualio

Qualio reports general availability of AI functionalities

Under the name 'Compliance Intelligence', Qualio offers a number of AI features for its GRC platform. These include gap analysis, continuous compliance monitoring, dashboards, and guided remediation workflows. Launching frameworks include FDA QMSR, ISO 13485, ISO 9001, ISO 27001, and MDSAP.
Qualio:GRC platform für Life Sciences; HQ: San Francisco, CA (USA), Office in Dublin (Ireland); founded 2012; approx. 120 employees.
October 13, 2025 - E-V-E GRC / Evolve Solutions ApS

Webinar with demo of EVE GRC

This video shows the process in EVE GRC of analyzing documents against control requirements using OpenAI's AI. Support for the Secure Controls Framework (SCF) is also announced.
Evolve Solutions ApS:Compliance plattform; HQ: Gentofte (Denmark); founded 2024
Anders Søborg:Co-founder of Evolve Solutions
https://www.youtube.com/watch?v=rEuWhOoT36o...
October 13, 2025 - risk3sixty

Short demo of the AI chat bot of fullCircle

risk3sixty:Consulting company and GRC platform 'fullCircle GRC'; HQ: Roswell, GA (USA); founded 2016, approx. 60 employees.
AI Assistant
https://www.youtube.com/watch?v=gr-p-4mKE4g...
October 13, 2025 - Workiva

Podcast on AI governance

Topics: Unregulated AI use poses significant risks; Traditional governance models are coming under pressure; Technology is overtaking governance and control systems; Avoiding the 'Department of No' - collaboration instead of rejection; Opportunity to reposition audit and risk
AI Governance
https://www.workiva.com/resources/auditing-ai-new-...
October 9, 2025 - CoreStream GRC

Integration of CoreStream GRC with AscentAI

CoreStream GRC announces a partnership with AscentAI, a provider of Regulatory Lifecycle Management. The solution will be integrated to help U.S. financial institutions identify regulatory changes and implement them efficiently.
CoreStream GRC:GRC plattform; London (HQ), New York; founded 2004; approx. 50 employees
https://corestreamgrc.com/resources/news/ascentai-...
October 9, 2025 - Verano.AI

Verano.AI available in the ServiceNow Store

Verano.AI is pleased to announce that it has launched its Agentic AI solution for Regulatory Monitoring in the ServiceNow Store.
Verano.AI:Regulatory Monitoring; HQ: Calgary, AB (Canada), Houston, TX (USA); founded 2023.
https://www.linkedin.com/posts/verano-ai_veranoai-...
October 8, 2025 - Zania AI

Interview on the use of Zania AI for GRC at a FinTech provider

Risk management at Plaid, introduction of AI agents, FAIR framework, human-machine collaboration, KPIs, results, unexpected benefits, recommendations
Zania:GRC with Agentic AI; HQ: Palo Alto, CA (USA); founded in 2023
Shruti Gupta:Founder and CEO of Zania
https://www.youtube.com/watch?v=zr1YrEanjBA...
October 6, 2025 - Hubscale Podcast

Interview with the CRO of Vanta

Lara Scott interviews Stevie Case, Chief Revenue Officer at Vanta. Topics include target customers and their needs, entering new markets, including the needs in the EMEA region, internationalization, company culture and hiring talents.
https://www.youtube.com/watch?v=YZZ-WBDTOJA...
October 6, 2025 - Telos

Short video about the AI capabilities of Xacta.ai

Telos:Network solutions, Cyber security, GRC; HQ: Ashburn, VA (USA); approx. 520 employees
https://www.youtube.com/watch?v=BwIuguwXWRs...
October 5, 2025 - Centraleyes

Italy brings national AI law into force

On October 10, 2025, a national AI law will come into force in Italy.
AI Regulation
https://www.centraleyes.com/italys-ai-law-comes-in...
October 1, 2025 - Telos

Telos brings AI capabilities to its GRC platform

Under the name Xacta.ai, Telos is expanding its GRC platform with a range of AI functions. These include control implementation and validation, risk identification and mitigation. Mentioned technologies include: Prompt library, RAG, and AI-supported data tagging.
Telos:Network solutions, Cyber security, GRC; HQ: Ashburn, VA (USA); approx. 520 employees
 

GRC News September 2025

September 30, 2025 - Zania AI

Zania raises $18 million in Series A funding round

US provider Zania has secured $18 million in a funding round. Zania relies on Agentic AI for its GRC platform and wants to use the money to expand the product in order to automate the entire GRC lifecycle. This includes expanding its own AI models and tripling its team. The focus is on Fortune 500 companies.
Zania:GRC with Agentic AI; HQ: Palo Alto, CA (USA); founded in 2023
Agentic AI
https://zania.ai/blog/series-a-fundraise-announcem...
September 29, 2025 - Iskera, Pocket Result, Optimiso Group, Acuredge

Merger of three GRC providers from France and Switzerland

Acuredge, Pocket Result (France), and Optimiso Group (Switzerland) merge to form Iskera. The new company has approximately 100 employees and more than 400 customers in Europe.
https://optimiso-group.com/en/news/optimiso-group-...
September 29, 2025 - F5, Inc.

Dashboard for AI model security

F5 displays monthly updated dashboards on the security and performance of well-known models such as GPT, Claude Sonnet, and DeepSeek.
https://www.f5.com/company/blog/introducing-the-ca...
September 2025 - E-V-E GRC / Evolve Solutions ApS

E-V-E GRC plans expansion into the Middle East

Evolve Solutions announces that its platform now supports Arabic and that it has launched a partner program.
Evolve Solutions ApS:Compliance plattform; HQ: Gentofte (Denmark); founded 2024
September 28, 2025 - Safeshield Training

Short training session: Transparency and explainability in AI systems

AI systems are highly complex and elude our direct understanding. At the same time, explainability is crucial for their use in many areas. This presentation by Safeshield provides a good introduction to the topic from the perspective of AI governance (The AI ​​voice reading allows the video to be played at a higher speed)
AI Governance
https://www.youtube.com/watch?v=eJ3wJEk9Fbs...
September 25, 2025 - risk3sixty

Integration of ISO 42001 into an existing ISO 27001 program

Discussion of ISO 42001 and comparison with ISO 27001; certification process and example.
risk3sixty:Consulting company and GRC platform 'fullCircle GRC'; HQ: Roswell, GA (USA); founded 2016, approx. 60 employees.
Christian Hyatt:Founder and CEO of risk3sixty
Danny Manimbo:Principal & ISO AI Services Leader, Schellman
AI Governance
September 24, 2025 - EQS Group

Study: How effective are well-known AI models at GRC tasks?

Testing different LLMs on various GRC tasks
https://www.eqs.com/compliance-wpapers/ai-performa...
September 24, 2025 - SolidCore

And another company in the field of AI security and compliance

Founded in 2024 and previously in stealth mode, SolidCore is another company now offering a solution for LLM security and compliance.
SolidCore:Solution for AI security and AI governance; HQ: Menlo Park, CA (USA); founded in 2024
Hemma Prafullchandra:Founder and CTO
Eric Chiu:Founder and CEO
AI Governance AI Security
https://www.linkedin.com/posts/solidcore-ai_solidc...
September 24, 2025 - Protecht

Demo of Protecht's AI assistant

Starting at 17:00, introduction and demonstration of AI functionalities in Protecht, both embedded and conversational, under the name 'Cognita.' Unfortunately, the video is constantly interrupted by YouTube ads.
Protecht:GRC platform (SaaS); HQ: Sydney (Australia), branches: Los Angeles (USA), London (UK); founded 1999
Kelly Ngai:Head of Product Marketing
Terence Lee:VP North America
AI Assistant
https://www.youtube.com/watch?v=A5lPj7530Uo...
September 23, 2025 - risk3sixty

GRC Agentic AI Roadmap: Part 2 - Real World Use Cases to Use Agentic AI in Your GRC Program

Part 2 of this high-quality series: Business Case for Agentic AI; A vision for the journey to maturity; Real world examples. With demos in the GRC platform fullCircle.
risk3sixty:Consulting company and GRC platform 'fullCircle GRC'; HQ: Roswell, GA (USA); founded 2016, approx. 60 employees.
Christian Hyatt:Founder and CEO of risk3sixty
Sawyer Miller:Director of Advisory and Assurance
Agentic AI
September 23, 2025 - Corporate Compliance Insights / Lighthouse

A plea to balance AI innovation and AI governance

Three employees of the provider Lighthouse advocate for balance in dealing with AI.
Lighthouse:Solutions for eDiscovery, Records Management and others; HQ: Seattle, Washington (USA); founded 1995; approx. 1000 employees
Karl Sobylak:Senior director of product management at Lighthouse
Fernando Delgado,:Executive director of Lighthouse’s AI & analytics group
Lon Troyer:Vice President of Review and Advanced Analytics at Lighthouse
https://www.corporatecomplianceinsights.com/open-l...
September 22, 2025 - Hyperproof

Hyperproof announces AI-based GRC platform

Hyperproof announces end-to-end AI functionalities with “Hyperproof AI.” The emphasis is on transparency, explainability, and the possibility of human oversight.
Hyperproof:GRC platform; HQ: Seattle, Washington (USA); founded 2018; approx. 170 employees
Craig Unger:CEO
Alam Ali:SVP of Product at Hyperproof
https://hyperproof.io/resource/introducing-hyperpr...
September 19, 2025 - VComply

Summary on the EU AI Act

VComply:GRC platform; HQ: Sunnyvale, California (USA); founded 2019
Harshvardhan Kariwala:Founder and CEO of VComply
AI Governance EU AI Act
https://www.v-comply.com/blog/eu-ai-act-essential-...
September 18, 2025 - Strike Graph

Report 'State of AI in Compliance'

How is the burden of regulatory requirements perceived, and how willing are companies to use AI to solve the growing number of tasks? US provider Strike Graph conducted a survey and presents the results here.
Compliance
https://www.strikegraph.com/strike-graph-2025-stat...
September 17, 2025 - Themis Press Release

Themis launches AI-based due diligence platform

Themis, a provider of solutions for combating financial crime, has introduced the 'AI Investigator', an LLM-based platform for due diligence processes. The launch took place in Abu Dhabi, aligning with the United Arab Emirates' national agenda to establish the country as the global leader in artificial intelligence by 2031.
TPRM VRM
https://www.wearethemis.com/uk/press/themis-launch...
September 17, 2025 - RegScale

RegScale raises $30 million in Series B

RegScale has raised an additional $30 million in a Series B financing round.
RegScale:GRC platform focused on Continuous Control Monitoring; HQ: Tysons, Virginia (USA); approx. 70 employees
https://regscale.com/blog/path-to-series-b-disrupt...
September 17, 2025 - LatticeFlow AI

LatticeFlow AI introduces platform for the technical assessment of AI systems

The AI GO! platform enables enterprises to operationalize their AI governance. The solution provides evidence-based evaluations of AI systems through reproducible technical tests. This allows regulatory requirements to be systematically verified and audit-ready documentation for compliance and risk management to be generated.
LatticeFlow AI:Solutions for AI Governance; HQ: Zurich (Switzerland), offices in Bulgaria and the US; founded 2020; approx. 30 employees
AI Governance
https://latticeflow.ai/news/latticeflow-ai-sets-a-...
September 16, 2025 - ACA Group

ACA Group launches AI engine for regulatory compliance

The 'Encore AI' engine will be integrated into the provider's GRC solutions.
ACA Group:GRC for financial institutions; HQ: New York (USA), offices in Europe and Asia; founded 2002; 1,400 employees
Compliance
https://www.acaglobal.com/news-and-announcements/a...
September 15, 2025 - Heise

Experiment: Can AI further develop an ISMS standard?

In this detailed experiment, the German ISMS standard 'BSI IT-Grundschutz' (IT baseline protection) was further developed using AI. This was done on three levels: 1) Conversion of the current standard from PDF documents into machine-readable OSCAL structures, including translation into 14 languages. 2) Further development of the standard's content. 3) AI-based automation of document review, which resulted in the creation of the “BSI Audit Automator” tool (available under the Business Source License). The projects resulted in 8,000 lines of Python code, 4,000 lines of JSON stubs, and 50 prompts, using Gemini 2.5 Pro, 2.5 Flash, ChatGPT o3, and Claude Opus 4.
ISMS
https://www.heise.de/hintergrund/Experiment-KI-ent...
September 15, 2025 - Workiva

Workiva 'Ask Anna'

Not sure if this animated AI assistant from Workiva is really new, but today I discovered it for the first time: “Ask Anna.” The lady dutifully answers all questions about Workiva, but remains at a non-committal, general level. At least she also answers questions such as “What is the capital of Alaska?” or explains “What is Independence Day?”
AI Assistant
https://www.workiva.com/ask-anna
September 12, 2025 - EY

EY survey on the status of AI governance and risk management in Western Europe

AI adoption strategy, risks, governance, compliance with the EU AI Act, etc. at 55 companies surveyed.
AI Governance AI Regulation AI Strategy EU AI Act
https://www.ey.com/en_pt/services/technology-risk/...
September 12, 2025 - Finopotamus

AI in Regtech: A Helper, Not a Decision-Maker

In Governance, Risk & Compliance, critical tasks such as the final approval of policies, the interpretation of regulatory gray areas, and the strategic definition of risk tolerance should not be outsourced to AI. While AI can optimize existing processes, detect patterns, and provide valuable analyses, its lack of contextual understanding and the risk of misinterpretation make human judgment indispensable, that’s the core message of this article. At a time when many vendors in the current AI hype talk only about the upsides, this is a pleasantly down-to-earth voice that identifies today's limits.
ViClarity / YouComply:GRC platform for financial services providers, insurance companies, hospitals, credit unions, and other highly regulated sectors; HQ: Kerry (Ireland), Des Moines, Iowa (USA); founded in 2008
Ogie Sheehy:Founder and global CEO of ViClarity
AI
https://www.finopotamus.com/post/don-t-hand-these-...
September 12, 2025 - AI Wisdom

Integration of AI into Rezilens' DiGRC product

After a general introduction to AI in GRC, there is a DiGRC product demo starting at 26:25. Shown AI features: 31:50: AI support for a maturity assessment was to be demonstrated. 37:23: Integration of AI agents into workflows. 38:29: Use of AI in risk analysis; 42:10: AI-assisted mapping of frameworks; 42:30: Prompt list.
Rezilens:GRC platform DiGRC; HQ: Dubai (UAE); founded 2021
Dr. Sam Mokhtari:Host of AI Wisdom
Dr. Shan Sokhanvar:Founder and CEO of Rezilens
AI
https://www.youtube.com/watch?v=0xEAS6rrJ9o...
September 10, 2025 - Cyberday / Digiturvamalli

Cyberday announces AI assistant

The GRC platform from Finland announces an AI assistant. A first version will be rolled out in September, with further features planned.
Cyberday / Digiturvamalli:GRC platform; HQ: Tampere (Finland); founded 2016; approx. 20 employees
Aleksi Pulkkanen:Co-founder and COO of Cyberday
AI Assistant
https://www.cyberday.ai/blog/introducing-cyberday-...
September 10, 2025 - Vanta Company News

Integration of the Vanta AI Agent into policy management

Vanta announces the integration of its AI agent into policy management. It is designed to assist in drafting, updating, and reviewing policies.
AI Agent
https://www.vanta.com/resources/introducing-proact...
September 9, 2025 - Gartner

Gartner on the importance of AI in tackling regulatory complexity

A report from the Gartner Enterprise Risk, Audit & Compliance Conference in Grapevine, Texas. With interesting insights into how customers use GRC tools and their satisfaction levels. With an excerpt from the Gartner Hype Cycle for Legal, Risk, Compliance and Audit Technologies, 2025.
AI
September 9, 2025 - Workiva

Workiva announces major AI enhancements

At its annual Amplify conference in Washington, Workiva announced significant enhancements to its AI capabilities, including Agentic AI, which is integrated directly into workflows.
Workiva:Cloud-based platform for complex financial, reporting, and compliance processes; HQ: Ames, Iowa (USA); founded in 2008; 2,900 employees
Agentic AI
September 9, 2025 - Origami Risk

Origami Risk announces AI solution 'AI Risk and Control Explorer'

The solution automatically generates lists of enterprise exposures based on inputs of key information such as industry, employee count, and geographic location.
Origami Risk:GRC platform; HQ: Chicago, IL (USA); founded 2009; 500+ employees
AI
September 8, 2025 - Workiva Release Notes: August 30 – September 5, 2025

New and enhanced AI capabilities in Workiva

Comparison with SEC reports from other companies; improved waiting screen when using AI; referencing documents in chats; AI support in documents with Workiva AI Intelligent Companion; support for additional document formats
AI
https://support.workiva.com/hc/en-us/articles/4102...
September 8, 2025 - Protecht Product Updates

Protecht announces AI assistant

The Australian GRC platform Protecht ERM announces an AI assistant called Cognita, which will be rolled out in November 2025.
Protecht:GRC platform (SaaS); HQ: Sydney (Australia), branches: Los Angeles (USA), London (UK); founded 1999
AI Assistant
https://www.protechtgroup.com/en-us/news/protecht-...
September 4, 2025 - risk3sixty

Agentic AI in GRC

Part 1 of a four-part series on the role of Agentic AI in GRC. This one-hour session covers the business context and general trends in this field, and includes an example, methodology, and a demo. Another outstanding video from risk3sixty.
risk3sixty:Consulting company and GRC platform 'fullCircle GRC'; HQ: Roswell, GA (USA); founded 2016, approx. 60 employees.
Christian Hyatt:Founder and CEO of risk3sixty
Sawyer Miller:Director of Advisory and Assurance
Agentic AI
September 4, 2025 - Scytale Product Updates

Scytale now supports the EU AI Act

The US provider, which is represented by partners in numerous regions, has incorporated the EU AI Act into the AI governance part of its application.
Scytale:GRC Plattform; HQ: New York (USA); founded 2021; approx. 100 employees
AI Governance EU AI Act
https://scytale.ai/resources/scytale-supports-the-...
September 3, 2025 - Commugen

Commugen announces AI Agents

Israeli provider Commugen announces several AI agents for its GRC platform. It remains unclear what the “first of its kind” refers to.
Commugen:GRC platform; HQ: Tel Aviv (Israel); founded 1999; approx. 25 employees
Itai Sassoon:CEO
AI
https://www.cbs42.com/business/press-releases/ein-...
September 2, 2025 - SimplifyISO Interviews & Podcasts

AI usage to enhance ISMS

Interview with Dejan Kosutic on the role and the challenges of artificial intelligence in information security management systems and in related fields.
Jim Moran:Co-founder of Simplify ISO; London, Ontario (Canada)
AI ISMS
https://www.youtube.com/watch?v=zk3ffckTpZ8...
September 2, 2025 - ISACA

Challenges in the governance of Agentic AI

What are the issues for an auditor when dealing with Agentic AI? How do you deal with these systems that can make decisions autonomously? Three fictional but realistic scenarios are used to illustrate the problems and derive requirements from them.
Agentic AI AI Governance
https://www.isaca.org/resources/news-and-trends/in...
 

GRC News August 2025

August 28, 2025 - ZenGRC

ZenGRC announces AI assisstant

The provider, headquartered in San Francisco, has announced an AI assistant for its GRC platform that performs tasks at an 'analyst-grade'. ZenGRC points to differences compared to other vendors' AI strategies, but has not yet provided details on how exactly this higher level will be achieved.
ZenGRC:GRC plattform; San Francisco (USA)
https://www.zengrc.com/resources/news/zengrc-intro...
August 27, 2025 - Verdantix

Verdantix on the current state of AI in GRC

As part of its Green Quadrant report, Verdantix provides an interesting assessment of the current status of AI in GRC platforms: AI alone does not sell GRC solutions; investment in R&D is the strongest driver of true AI maturity; and regulatory requirements are making governance and explainability the next differentiating factor.
AI Governance XAI
https://www.verdantix.com/venture/blog/ai-in-grc-v...
August 26, 2025 - Workiva Release Notes: August 16 – August 22, 2025

Upgrade to Claude Sonnet 4

Workiva supports various LLMs. Claude Sonnet from Anthropic has been updated from version 3.5 to 4. Knowledge cutoff date: January 2025.
Claude GenAI LLM
https://support.workiva.com/hc/en-us/articles/4058...
August 26, 2025 - Governance Dynamics, Diligent

Webinar on AI in GRC

Particularly interesting from 29:10: This section deals with approaches that can be used to improve data quality so that AI can deliver the best possible and most comprehensible results based on that data.
Explainability XAI
https://www.youtube.com/watch?v=SJllbx2SZVA...
August 24, 2025 - AI Engineer World's Fair 2025

Building a platform for Agentic AI

Not directly related to GRC, but still an interesting architectural topic: This presentation is about the development of Agentic AI within Box, a cloud-based content management platform. Ben Kus, CTO of Box, reports on the stages from simple LLM usage to an architecture for Agentic AI.
Agentic AI
https://www.youtube.com/watch?v=12v5S1n1eOY...
August 21, 2025 - VerifyWise Blog

VerifyWise 1.2 released

Version 1.2 of the open source solution for AI governance is now available. The application from the Canadian startup based in Toronto currently supports ISO 42001 for AI management systems and the EU AI Act, with further standards in preparation.
VerifyWise:Open Source AI Governance; Located in Toronto (Canada), founded 2024
AI Governance AI Management System EU AI Act ISO/IEC 42001 Open Source
https://verifywise.ai/verifywise-1-2-a-new-way-to-...
August 18, 2025 - New in Vanta, August 2025 Vanta

New AI feature in Vanta VRM: Vendors can use AI suggestions when answering questionnaires

In its August product news, Vanta describes a new AI use case in vendor risk management (VRM): Based on uploaded documents, the application makes suggestions for answering questionnaires.
AI Third-Party Management TPRM VRM
https://www.vanta.com/resources/new-in-vanta-augus...
Description in the help
https://help.vanta.com/en/articles/11662022-vendor...
August 18, 2025 - Workiva Release Notes: August 9 – August 15 , 2025

Upgrade to ChatGPT-4.1

Workiva supports various LLMs. ChatGPT from OpenAI has been updated from version ChatGPT-4o to ChatGPT-4.1. Knowledge cutoff date: June 2024.
GenAI LLM OpenAI
https://support.workiva.com/hc/en-us/articles/4036...
August 14, 2025 - NIST

Concept paper on control overlays for securing AI systems - seeking feedback

The National Institute of Standards and Technology (NIST) is developing guidelines on how organizations can operate AI systems securely. This will take the form of overlays to SP 800-53, the SP 800-53 Control Overlays for Securing AI Systems (COAiS). NIST is requesting feedback on this.
AI Security
https://csrc.nist.gov/projects/cosais
August 6, 2025 - CoreStream GRC

AI strategy paper for CoreStream GRC

CoreStream GRC outlines in this paper how it integrates Artificial Intelligence (AI) into its GRC platform. The approach is not to embed AI rigidly into the core platform but to provide AI in a flexible, secure, and optional way through integrable services. The strategy is based on market feedback, client requirements, and CoreStream’s philosophy of acting as the 'GRC backbone.' No fixed commitment to specific AI models or providers, integrations instead of in-house developments, and a focus on core competencies. The goal: more time for strategic GRC work instead of manual processes.
CoreStream GRC:GRC plattform; London (HQ), New York; founded 2004; approx. 50 employees
Rich Eddolls:Co-Founder and CPO of CoreStream GRC
AI Strategy
https://145493126.fs1.hubspotusercontent-eu1.net/h...
 

GRC News July 2025

July 28, 2025 - GRC 20/20 Research

GRC in Transition: A Strategic Outlook on the Age of Agentic AI

In this article, Michael Rasmussen presents a strategic outlook on what he calls GRC 7.0: a new era of Governance, Risk & Compliance in which agentic AI acts as an autonomous force to identify risks, support decision-making, and orchestrate GRC processes. The piece combines trend analysis with conceptual framing and illustrates how GRC is evolving from static controls to dynamic, intelligent, and proactive systems.
Agentic AI
July 1, 2025 - GRC Uncensored

Interview with Complyance founder Richa Kaul

This interesting interview focuses on the positioning of GRC tools, particularly in the US market, as well as various aspects of AI use both in the GRC sector and in general. Richa Kaul is the founder and CEO of Securely Technology, the provider of the AI-oriented GRC tool 'Complyance', based in New York and London.
Complyance:GRC platform; New York, London; approx. 20 employees
Richa Kaul:Founder and CEO of Complyance
AI
https://www.youtube.com/watch?v=4NjtOa_OqLY...
 

GRC News June 2025

June 2025 - Massachusetts Institute of Technology (MIT)

The GenAI Divide: Study on the State of AI in the Economy

95% of organizations do not generate a return on their AI investments. This MIT study reveals possible reasons why.
AI
https://mlq.ai/media/quarterly_decks/v0.1_State_of...
June 09, 2025 - Vanta Blog

Vanta: MCP Server in Public Preview

A more technical or architectural topic: Vanta has implemented its first MCP server. The Model Context Protocol (MCP) is an open standard that defines how AI models communicate with external tools, data sources, and applications. It ensures that a model can exchange information in a structured way without having to build separate integrations for each system. The article demonstrates access to Vanta data using the example of Claude and Cursor.
Vanta:GRC-Plattform; San Francisco (HQ); founded 2018; approx. 1000 employees
AI LLM MCP
https://www.vanta.com/resources/meet-the-vanta-mcp...
https://github.com/VantaInc/vanta-mcp-server...
 

GRC News April 2025

April 28, 2025 - Vanta Blog

Vanta: Experience with ISO 42001 certification

In this blog article, Vanta's Information Security & Compliance Manager describes four insights gained from their ISO 42001 certification for AI management systems.
Vanta:GRC-Plattform; San Francisco (HQ); founded 2018; approx. 1000 employees
AI AI Governance AI Management System Certification Compliance ISO/IEC 42001
https://www.vanta.com/resources/4-lessons-learned-...
https://www.vanta.com/resources/vanta-earns-iso-42...
 

GRC News January 2025