AI, Policy and Risk

AI governance, built in

ISO/IEC 42001, NIST AI RMF, and the EU AI Act ship as first-class frameworks with curated crosswalks to your ISMS, so AI governance becomes a delta on work you've already done, not a rebuild. An org-scoped AI-system registry tracks each system's EU AI Act risk tier, owner, model provider, and linked controls. GRCFlow governs AI the same way it uses it: the agentic layer can draft an AI-audit finding, with executive summary and root cause, but every AI-drafted finding lands gated “Human Review Required” and the compliance verdict stays policy-evaluated, never AI-decided.

A GRCFlow AI audit finding with executive summary and root-cause detail, carrying a Human Review Required banner before it can be accepted.

Policy versioning and attestations

Every policy create, update, and approval pins an immutable version snapshot with a live SHA-256 integrity check. Attestation campaigns assign policies to users or roles and record who attested to exactly which version, when, as signed entries in the audit chain.

The GRCFlow policy library listing policies with version number, active status, review date and last-reviewed date.

Risk: Residual and FAIR

Map controls to risk-register entries and residual risk is computed from real assessment pass rates, untested controls earn no credit, and a manual override always wins and is always labeled. Open FAIR Monte Carlo quantification (ALE, VaR, loss exceedance) runs server-side and persists every analysis.

Proof behind every verdict

Tamper-evident audit trail

Every control-verdict change, evidence action, policy edit, and user change is written to a SHA-256 hash chain, one entry per verdict, no exceptions. Verdicts a person records or approves are additionally signed with that person's Ed25519 key; machine-generated verdicts are chained but unsigned, because no human authored them. You can re-verify the entire chain from the Audit Log page any time, with per-entry signature verification available through the audit API. An auditor doesn't have to trust your dashboard; they can check the math.

The GRCFlow audit log: a tamper-evident activity table with per-entry timestamp, action, entity type and SHA-256 checksum, above a Verify Chain Integrity control.

Honest state, never a fake green

A control the engine cannot verify is an honest error or gap, never a fabricated verdict. Assessments only report “completed” when controls received real verdicts; coverage percentages are computed, never hardcoded; deterministic Rego rules only fire on live cloud evidence; and anything not implemented says so instead of pretending it ran.

The GRCFlow findings list showing genuine pass and fail verdicts per control, each with severity, review state and its source framework reference.

True between audits

Continuous controls monitoring (CCM)

Seven scheduled jobs run out of the box on a Postgres-backed scheduler. Six run daily:

  • Evidence-source health and drift checks
  • Control-test sweeps that trigger and execute due assessments
  • Policy-review-due sweeps
  • Reminders for open PBC (prepared-by-client) evidence requests
  • Reminders for stale needs-review findings
  • Security-awareness training reminders

The seventh, an A2A notification-delivery sweep, runs every 60 seconds. All of it is on by default, and if the scheduler ever fails to start, the log shouts it instead of hiding it.

GRCFlow risk monitoring: key risk indicators such as control failure rate and mean time to remediate, each with current value, amber and red thresholds and a tolerance status.

Automated assessments

Agentic control evaluation: LangGraph agents draft findings and gather evidence with live Steampipe cloud queries, while the compliance verdict is minted by deterministic OPA/Rego over live infrastructure rows, not by the model, across all 20 frameworks (2,082 controls). Bring your own LLM (NVIDIA NIM, Anthropic Claude, Google Gemini, DeepSeek, OpenAI, Azure OpenAI, Cloudflare Workers AI, or any OpenAI-compatible server), configurable from the admin panel, including pointing at a local or air-gapped Ollama/vLLM endpoint, with a Test Connection check. Cloud queries use the optional Steampipe sidecar. Controls with no reachable cloud collector are evaluated against your in-force policy documents, clearly labeled as documentation review, not live verification.

The GRCFlow assessments list showing compliance assessments per framework with status, progress and creation date.

Collect once, map everywhere

The cross-framework delta engine shows how much of your existing ISO 27001 or SOC 2 work already covers a new framework, GLBA, ISO 42001, and more, with full/partial/none coverage per control and an honest reuse percentage. Deterministic crosswalk mappings first; AI suggestions are always labeled “AI-suggested, verify” and never block or fake a result.

Evidence, incidents and the audit copilot

Board packs and auditor evidence

An executive board-pack report rolls up posture, per-framework readiness, top residual risks, and open gaps. External auditors on a grant view evidence inline only, watermarked images, no download links, every view and every denied download audit-logged. Deterrence and auditability, not DRM: a browser view still delivers bytes.

The GRCFlow reports screen offering detailed findings, gap analysis and executive summary reports as generated PDF downloads.

Integrations, honestly labelled

One connector collects control evidence today: AWS. It backs 70 controls across SOC 2, ISO 27001 and CMMC Level 2, with 82 live Steampipe queries, every one of them against an aws_* table. Nine further connection types, Azure, GitHub, Okta, Kubernetes, SSH, WinRM, LDAP, PostgreSQL and MySQL, can be configured, credential-tested and health-checked, but none of them feeds the assessment engine yet. Azure (26 queries) and Okta (6) control libraries are written and schema-verified, but nothing calls them. Jira sync is real: outbound create, close and comment against the Jira Cloud REST API v3, with inbound comments and status changes arriving over the HMAC-signed generic webhook, which also drives any other tracker. ServiceNow returns an honest “not yet supported” instead of pretending; no GCP connector is claimed because none exists yet.

The GRCFlow data sources screen showing the supported connector grid: AWS, Azure, GitHub, Okta, Kubernetes, SSH, WinRM, LDAP, PostgreSQL and MySQL.

Incidents, vendors and evidence

NIST 800-61 incident workflow with SLA tracking and breach-notification support; Agent-to-Agent vendor attestation with signed responses; versioned, hash-verified evidence storage. Evidence needs your own S3-compatible object storage (R2, S3, or the bundled MinIO). Object Lock retention is GOVERNANCE mode (365-day default), which holders of the bypass permission can override, and presigned browser uploads stamp no per-object retention, so WORM semantics require you to enable Object Lock and a default retention rule on the bucket yourself.

The GRCFlow incident management screen with counts of open, critical, breach and SLA-tracked incidents above a prioritised incident list.

Audit copilot

The audit copilot is GRCFlow's agentic layer at the operator's side: guided audit prep grounded in real framework content and your organization's own findings, “new to this” and “seasoned” modes, resumable sessions, and agentic actions that pull real verdicts, save AI remediation drafts onto findings for human review, or run the reuse delta. Progress is recomputed from real findings on every resume, never stored, so it can't go stale or be faked. ISO 27001 today; offline template drafts are labeled and never auto-saved.

All 20 frameworks, with their control counts

Every one ships with the 30-day trial and with every paid tier. Seat count is the only difference between plans, never the framework list.

NIST SP 800-53 Rev. 51,014 controls
CMMC Level 2110 controls
NIST SP 800-171 Rev. 2110 controls
CCPA/CPRA107 controls
NIST CSF 2.0106 controls
ISO/IEC 27001:202293 controls
TISAX (VDA ISA)80 controls
DORA64 controls
PCI DSS v4.0.163 controls
NIS2 Directive63 controls
SOC 2 Type II61 controls
ISO/IEC 42001:202338 controls
GDPR30 controls
HIPAA Security Rule25 controls
NYDFS Part 50025 controls
CMMC Level 324 controls
NIST AI RMF 1.019 categories
EU AI Act19 obligations
GLBA Safeguards (FTC)16 controls
CMMC Level 115 controls
  • Self-hosted
  • A2A attestation
  • Air-gap ready
  • No telemetry

All 20 frameworks and 2,082 controls ship with the 30-day trial. Nothing renews on its own, and the install is one command.