§ 05.1
Governance
Who owns which obligation, which policy answers it, who signed off. In legacy suites this is a workflow you configure for months. Here it is the register itself: every line has an owner, a policy mapping and a stamped history.
GRC software is the system a company uses to run governance, risk and compliance: the risk register, the control library, the policies, the audit trail. The legacy suites do this with six-figure licences and consultant-built workflows. Complianceofficer is GRC software rebuilt AI-first around the part the suites never solved: watching the regulations themselves.
Pick your sector below. The scan returns the obligation register a GRC program is supposed to sit on, with the last 12 months of regulatory movement and sources linked. No signup, nothing stored.
§ Live · Compliance scan
No signup. Nothing you pick is stored.
Sample register · fintech, US · what a scan returns
§ 05.1
Who owns which obligation, which policy answers it, who signed off. In legacy suites this is a workflow you configure for months. Here it is the register itself: every line has an owner, a policy mapping and a stamped history.
§ 05.2
The biggest compliance risk is the change you did not see. Governance risk and compliance software that waits for you to enter the risk has it backwards; the watching comes first, and the register updates you.
§ 05.3
Policies checked against the current text of the rule, gaps flagged with the reason, evidence filed as it happens. The audit becomes an export, not a project.
One caveat on the middle column, because it is where GRC buyers most often get the wrong tool. The risk a GRC suite handles well is compliance risk: a control stops meeting a rule. That is narrower than enterprise risk, which also has to carry strategic, financial, operational and reputational lines, a stated risk appetite, and key risk indicators that roll up to a board committee. If the question your board is actually asking is what our top ten risks are and whether any is getting worse, read enterprise risk management software first and treat GRC as the layer underneath it.
| ServiceNow GRC / RSA Archer | Complianceofficer planned | |
|---|---|---|
| Cost picture | Six figures plus implementation | $149 to $1,499 per month, published |
| Time to running | Months of configuration, usually consultants | Tell it your industry and frameworks; the register builds itself |
| Regulatory change | Content feeds bolted on, mapping is your project | The core loop: watch, explain, map, draft |
| Who can run it | A GRC team | The compliance owner you already have |
The suites are real platforms with capabilities we do not claim, workflow breadth above all; the comparison is about what a mid-market compliance team actually needs and can run. Our column is the launch plan, marked planned because it is.
GRC begins as one painful regime, not a platform decision. Teams usually arrive here for GDPR compliance software, SOC 2 before a first audit, or AML monitoring after a regulator letter. The register grows from there; the four-step loop stays the same.
Run the compliance scanGRC software is one system holding governance, risk and compliance together: the policies and decision rights that make up governance, the register of risks with owners and treatment plans, and the obligations with the controls that satisfy them. The value is not any one of those three. It is the joins between them, so that a risk points to the control that mitigates it and the control points to the rule that requires it.
That definition rules out several tools that market themselves in the category. An audit readiness platform that collects evidence for SOC 2 is compliance automation, not GRC, because it has no risk register and no governance layer. A spreadsheet of risks scored high, medium and low is a risk register, not GRC, because nothing connects it to a control. Both are useful. Neither answers the question a board asks, which is whether the risks we accepted are still covered by the controls we said would cover them.
| Category | What it holds | Bought by | What it cannot answer |
|---|---|---|---|
| GRC platform | Policies, risks, obligations, controls, audits, vendors | CRO, CCO, head of internal audit | Usually not: what changed in the regulation this week |
| Compliance automation | Framework controls and collected evidence | CISO, security engineer | Anything outside the certified framework |
| ERM tool | Risk register, appetite, KRIs, board reporting | CRO, CFO | Which control satisfies which obligation |
| Policy management | Documents, versions, attestations | Compliance manager, HR | Why a policy exists and when its rule moved |
| Regulatory change | Source monitoring, impact assessment, tasks | Compliance, legal | The state of your controls today |
Most organizations end up owning two or three of these rows. The overlap is real, and it is worth deciding deliberately which system is the record for controls before you buy the second one. We cover the individual categories on compliance automation software, enterprise risk management software, policy compliance software and audit management software.
GRC stands for governance, risk and compliance. Governance is how decisions get made and who is accountable. Risk is the identification, assessment and treatment of things that could stop you meeting objectives. Compliance is meeting the external obligations that apply to you. The term describes an integrated way of running all three, and only secondarily a category of software.
ERM is the risk half of GRC done thoroughly, across the whole enterprise and usually reported to the board. GRC is broader, adding the governance layer and the compliance obligation register alongside risk. In practice a company with an ERM program and no compliance mapping has half a GRC capability, and the missing half is the one regulators examine.
Recorded purchase data puts enterprise GRC suites at medians around $45,000 to $54,000 a year, with observed contracts ranging from roughly $12,000 to $136,000 depending on modules and headcount. Lighter compliance automation platforms sit nearer $15,000 to $25,000. Full figures by vendor are on compliance software pricing.
Chief risk officers, chief compliance officers and heads of internal audit are the usual owners, with security and legal as heavy users. In regulated industries the buyer is often driven by an examination finding rather than by a planned project, which is why so many implementations start with one register rather than the full platform. Banks and credit unions have their own requirements, covered on bank compliance software.
Below roughly 50 people with one framework in scope, usually not. A spreadsheet plus a compliance automation tool covers it. GRC becomes worth the overhead when you have more than one regime, more than one team owning controls, or a regulator who will ask you to trace an obligation to a control and back. That is the point at which the joins stop fitting in anyone's head.
It should tell you which of your obligations moved, which policies and controls are affected, and what the gap is, without you having read the regulator's publication first. Most platforms manage the workflow after a human notices the change. That gap is what this product is built to close, and it is described step by step on how it works.
§ 99 · Final entry
Leave your work email, confirm the 6-digit code, and we will email you when your spot opens. Nothing is charged before launch.