Risk • Compliance • Audit • Third-Party Risk • Business Continuity • AI Governance • ESG & Sustainability
Disclaimer: Features, functionality, and specifications described in this presentation are subject to change without notice. This material is provided for informational purposes only and does not constitute a contractual commitment. GRCxAI reserves the right to modify, enhance, or discontinue any feature at any time. Actual capabilities may vary depending on subscription tier, configuration, and deployment. No guarantee is made regarding the availability, performance, or suitability of any feature for a specific use case.
GRCxAI consolidates governance, risk, compliance, vendor management, business continuity, AI governance, and ESG & sustainability into a single AI-powered platform — eliminating tool sprawl and data silos.
Risk Register with 9-tab detail • 5x5 heatmaps • AI risk analysis • Risk assessments with templates • Treatments with budget tracking • Principal risks with board oversight • Top 10 ranking • 3 dashboard types • AI report streaming
ISO-aligned controls with evidence • Objectives with KPI tracking • 8 audit types with guided wizard • AI finding generation • Incidents with RCA (6 methods) • Corrective actions • Non-conformances • Change Management: ITIL 4 types, risk-proportional approvals, freeze windows, CI/CD ingestion — trail = ISO 27001 A.8.32 / SOC 2 CC8.1 evidence
AI Portfolio dashboard • Use case triage (Fund/Fix/Freeze) • Model registry with drift detection • ISO 42001 maturity (5-level) • ICO risk toolkit (32 items) • EU AI Act: 6-step wizard, 84 obligations, 37 Annex III categories
Vendor register with contracts, SLA & assessments • TPRM premium add-on: continuous outside-in due diligence — registries, sanctions/PEP, insolvency, ownership graphs, live attack-surface scans • Vendor response portal with AI answer & document validation • Evidence graded & hash-chained
Business functions with BIA (RTO/RPO/MTPD) • 13 threat scenarios • Recovery strategies • BC plans • Exercises • Crisis teams • Communication plans • Live activations with actual vs planned comparison • BC Readiness Score
ESG Dashboard with E/S/G scoring • Carbon accounting (Scope 1/2/3) with emission factors • 7 ESG frameworks (GRI, CSRD, TCFD, CDP, ISSB, SASB, SDGs) • Double materiality matrix • Goals & targets with trajectory • Supply chain ESG • AI-generated ESG reports (7 templates)
AI document generation across 26 standards/frameworks • 50+ templates per standard • 764+ controls • Real-time SSE streaming with auto-save • DOCX export with branding • 26 completion guides • 19 interactive training courses (200+ modules) • Auto-generated certificates
Dashboard with 28 module cards • Calendar with 10 event types, saved filters, multi-day events • Unified task aggregation from all modules • Document library with versioning, preview (PDF/Word), classification (4 levels), folder hierarchy
User management with RBAC • Company hierarchy (parent-subsidiary) • 6-type dept permissions • SAML SSO (Okta, Azure AD, Google, OneLogin) • TOTP 2FA • Audit log (30+ tables, field-level diffs) • AI chatbot (20+ standards) • Super Admin
The most comprehensive multi-standard coverage available. Every standard includes controls, AI document generation, a completion guide, and a dedicated training course.
Information Security Management
AI Management System
Cloud Security Controls
Cloud Privacy & PII Protection
Privacy Information Management
Risk Management Guidelines
Anti-Bribery Management
Compliance Management Systems
Business Continuity Management
Occupational Health & Safety
EU Data Protection Regulation
Service Organisation Controls
Payment Card Industry Security
NIST Cybersecurity Framework
UK NCSC Certification (v3.3)
UK NCSC Enhanced Certification (v3.1)
UK SME Cyber Security Standard
UK MOD Defence Cyber Certification
Managed Service Provider Certification
Every risk is enriched by linked data from across the platform. Controls, treatments, threats, vulnerabilities, and evidence all feed into a composite assurance score — which rolls up to board-level reporting.
From individual risk tracking with 9-tab detail views and heatmap scoring, through to board-level principal risk aggregation with weighted categories and oversight tracking.
Full risk inventory with inherent/residual scoring, risk owners, status tracking, and colour-coded severity.
Comprehensive view: details, controls, treatments, threats, vulnerabilities, evidence, assessments, and AI analysis.
Board-level risks grouped by 12 categories with priority ordering and weighted assurance scores.
Linked risks, Three Lines of Defence oversight, board review tracking, and assurance score breakdown.
Every risk gets a 0-100% assurance score calculated from 8 measurable inputs. This gives stakeholders a single, defensible number for how well each risk is understood and controlled — not just a red/amber/green guess.
Click to enlarge — Risk Assurance tab showing all 8 components with scores, weights, and ratings
Principal Risks aggregate individual risks with weighted scoring, track board oversight, and generate AI-streamed annual reports meeting Provision 29 disclosure requirements.
Principal Risk, Uncertainty, Emerging Risk — each with independent sections and priority ordering
Link risks with 0-100% weights. Auto-calculate inherent/residual scores. View effective/partial/ineffective control breakdown.
Board review tracking (last/next), overdue alerts, annual report inclusion flag, executive sponsor + co-owners
Strategic, Financial, Operational, Regulatory, Compliance, Cyber, ESG, Geopolitical + 4 more. Priority reorder within each.
End-to-end compliance lifecycle from ISO-aligned controls through guided audits with AI finding generation, incident management with root cause analysis, and non-conformance tracking.
ISO catalogue + custom controls with 5 evidence types, affirmation workflow, and 0-100% effectiveness tracking.
Hierarchical objectives with KPI tracking (metric, target, current), progress visualisation, budget vs actual, and auto-status calculation.
8 audit types, Guided Wizard with AI finding generation from Q&A, timeline tracking, and AI report streaming to DOCX.
7 types, RCA (Five Why, Fishbone, +4 methods), corrective actions with verification, NCR raising, anonymous reporting.
Major/Minor/Observation types, 6-step workflow (Open to Closed), ISO clause references, RCA integration, linked from incidents.
From use case triage (Fund/Fix/Freeze) through model registry, ISO 42001 maturity assessment, ICO risk toolkit, to full EU AI Act classification and compliance.
Aggregate view: use case counts, model risk distribution, maturity score, Fund/Fix/Freeze matrix
6 types, 5-factor triage scoring, portfolio decisions, EU AI Act + ISO 42001 flags, budget & ROI
7 model types, 4 sources, drift detection, vendor supply chain linking, cost tracking
ISO 42001-aligned 5-level framework (Initial to Optimising), 5 domains, NIST AI RMF mapping, evidence guidance, priority improvements
ICO AI & Data Protection Risk Toolkit: 32 items across 5 lifecycle stages, inherent vs residual scoring, control tracking, DPIA linking
The most comprehensive EU AI Act module available — 6-step classification wizard, 84 obligations, 37 Annex III high-risk categories, and full conformity assessment.
84 obligations dynamically filtered by risk category, role, and GPAI status. Per-obligation evidence, review workflow, real-time compliance score.
Internal or third-party assessment with 10 required documents (Technical Docs, Risk Mgmt, Data Governance, Human Oversight, QMS, FRIA).
Feb 2025: Prohibited. Aug 2025: GPAI. Aug 2026: High-Risk. Aug 2027: Product Safety. Aug 2030: Public Authority.
Full vendor lifecycle with contacts, contracts (SLA/auto-renewal), documents, and issues. Inherent vs residual risk scoring, criticality tiers, and supply chain linking.
Risk scoring (1-25), criticality tiers, contract expiry monitoring
5 types, 3 scoring methods, vendor self-assessment, evidence
Click to enlarge
RTO/RPO/MTPD tracking, dependency mapping
13 threat types, hot/warm/cold standby, cost estimation
Tabletop/simulation/full interruption with NCR integration
Real-time crisis tracking, actual vs planned RTO
Click to enlarge
The Corvus intelligence engine continuously gathers evidence on your third parties — registries, sanctions & watchlists, financial signals, live attack-surface scans — and grades every finding for reliability.
Companies House, GLEIF LEI & SEC EDGAR verification. PSC ownership chains walked nightly — sanctions screened down the chain, offshore opacity flagged.
UK, OFAC & EU lists with weighted entity matching — every near-miss carries a written, defensible rationale. Modern-slavery registry & debarment feeds included.
Insolvency & Gazette watch (CRN-confirmed = hard stop), credit checks (bring your own key), VAT validity, distress signals — surfaced in hours, not at renewal.
15 passive probes per domain — DNS/DNSSEC, TLS, email posture, subdomains, typosquats, cloud exposure. Threat campaigns mapped to your portfolio.
Every finding graded on the NATO Admiralty scale (A1–F), 7 honest evidence states, append-only hash-chained register — built for auditors and regulators.
Score swings, new hits & decision changes alert instantly (email + webhooks). Request → approve → auto-scan onboarding with two-tier approval.
Corvus watches official registries, watchlists and live infrastructure continuously — resolving news to the actual entities in your portfolio and walking ownership trees nightly. Every datum carries a NATO Admiralty rating, so your Confidence score is earned, not asserted.
Send secure magic-link questionnaires when you need them. But unlike every questionnaire tool, AI cross-validates each answer against the live evidence pool — and reads every uploaded document to verdict whether it actually proves the claim.
Secure tokenised links, resumable responses, expiry & reminders, colleague delegation, evidence upload with cryptographic receipts, return-for-revisions loop.
Every answer checked against the Corvus evidence pool. A vendor claiming ISO 27001 with no certificate on record gets flagged — with the verdict, rationale and score impact shown per answer.
Reads every uploaded file — pen tests, certificates, policies — and verdicts it: supports / partial / insufficient / wrong document. Catches the 2019 pen test and the lunch menu attached as a certificate.
75% external posture + 25% assessment lane, with published docks per contradiction or bad document. The formula ships in the payload — no black-box score.
Vendor-submitted certificates are AI-read, independently re-validated, provenance-marked, and slotted into an expiry-sorted chain — an old upload can never displace a newer cert.
Change is where risk enters an organisation — and where most audit findings are born. Enterprise change governance for every kind of change: IT, application, security, policy, organisational, vendor, facility and data. The trail doubles as audit evidence for ISO 27001 A.8.32 and SOC 2 CC8.1.
Standard changes run from pre-approved templates and auto-approve. Normal changes get a risk-proportional approval chain. Emergency changes are expedited with a mandatory post-implementation review.
Scored likelihood × impact on the same 1–25 bands as the risk module; your policy matrix decides the tiers (Owner / Change Manager / Management CAB). Material edits after approval automatically invalidate the chain.
Declare change freezes; scheduling respects them. Change windows appear on the organisation's shared calendar, with conflict detection.
GitHub Actions, GitLab CI and any HTTP-capable pipeline log deployments as change records automatically — governance without slowing delivery down.
Raise a risk from a change, an incident from a failed change, an emergency change from an incident. Link controls, assets, continuity plans and vendors; tasks surface in the unified Tasks view.
From carbon accounting and double materiality assessments through 7 ESG framework compliance to AI-generated sustainability reports — everything organisations need for CSRD, GRI, TCFD, and beyond.
E/S/G pillar scores with trend sparklines, Scope 1/2/3 emissions totals, framework compliance progress, active goals tracker, and ESG incident feed
Scope 1 (Direct), Scope 2 (Indirect-Energy), Scope 3 (Value Chain) tracking with emission factor picker, auto-calculation, and data quality tagging
Impact-based & financial-based scoring with matrix visualisation, 4 materiality classifications, and GRI topic mapping
Net-zero, renewable energy, diversity targets with baseline→target trajectory modelling, milestone tracking, and SBTi commitment linking
7 report templates (CDP, CSRD, GRI, ISSB, SASB, TCFD, SDGs). AI-powered markdown generation with real-time streaming, DOCX export, version tracking
Vendor ESG assessments with E/S/G pillar scoring, risk tier classification (Low→Critical), and colour-coded score cards
40+ metrics across E/S/G pillars, framework-aligned (GRI, SASB, TCFD), baseline→target tracking, 5 data quality levels, 5 verification types
Generate compliance documents with real-time AI streaming across all 26 standards & frameworks, 50+ templates each and 764+ mapped controls. Export to DOCX with company branding.
19 courses covering every standard with interactive lessons, quizzes, progress tracking, and auto-generated certificates with verification codes.
All 19 standards covered with interactive lessons and quizzes
4 question types, per-module completion %, time tracking
Verification codes, PDF download, audit-ready proof of competence
Learners see all 19 courses with real-time progress bars, module completion percentages, and time spent. Managers can track team-wide compliance readiness at a glance.
On course completion, certificates are generated automatically with unique verification codes, final scores, and issue dates — downloadable as PDF for audit evidence.
Every standard and framework on the platform has a dedicated, comprehensive completion guide — walking teams from initial risk assessment through controls, documentation, assessment, audit, and training.
An AI-powered chatbot trained across all 26 standards and frameworks, providing instant expert guidance on clauses, implementation steps, common questions, and best practices — no waiting for consultants.
Browse all supported frameworks from a single Help & Guidance panel. Each standard has its own tile with dedicated guidance — from ISO 27001 to IASME MSP. Staff can self-serve compliance questions instantly.
Each standard surfaces common questions grouped by topic, key clause areas, and suggested prompts. Shown here: ISO 42001 with AI Management System categories — helping teams know exactly what to ask.
The chatbot delivers detailed, structured answers with implementation steps, example scope statements, timelines, and common pitfalls. Conversation history is saved and searchable — building an organisational knowledge base over time.
Complete platform administration with multi-tenancy, RBAC, SAML SSO, comprehensive field-level audit logging, and AI-powered compliance chatbot.
User CRUD, company hierarchy, dept permissions (6 types), ISO framework config
Field-level diffs across 30+ tables, UUID resolution, record timeline, CSV export
Okta, Azure AD, Google Workspace, OneLogin with auto-provisioning
Authority hierarchy, score-based triggers, company-scoped role assignments
Cross-tenant management, bulk ownership transfer, AI compliance chatbot, and a full knowledge base for self-service support.
AI assistant supporting 26 standards with multi-conversation context
Cross-tenant orgs, users, domain whitelisting, support tickets
Bulk ownership transfer across 8 entity types and 12 role types
Knowledge base with articles, FAQs, quick-start guides, Ctrl+K search
User Reassignment Wizard
Risk Escalation Levels
Risk Sign-Off Roles
SAML SSO Configuration
Built on enterprise-grade infrastructure with security at every layer.
App Router, TypeScript
High-performance, memory-safe API
Dedicated infrastructure, 208+ tables
8+ integrations, SSE
Global delivery & DDoS protection
JWT, SAML, TOTP, AES
Email/Password (12+ chars) • Google OAuth 2.0 • Microsoft OAuth 2.0 • SAML 2.0 SSO • TOTP 2FA with backup codes • AES-256-GCM encryption
DOCX with company logos & cover pages • Excel with formatting • CSV raw data
Risk analysis • 13 report types (6 risk + 7 ESG) • ISO docs (26 standards) • Audit findings • Compliance chatbot (26 standards) • ESG reports • BIA/BC plan generation • Multi-language
Compliance-automation tools have grown fast — this table is honest about it. What none of them have: ESG & CSRD, UK board reporting, BCP activation, evidence-graded TPRM intelligence, change governance, or unlimited users at a transparent per-company price. Capabilities per public positioning, July 2026.
| Capability | GRCxAI | Vanta | Drata | Enzai | Kertos |
|---|---|---|---|---|---|
| ISO 27001 (InfoSec) | |||||
| ISO 42001 — full AI management system | |||||
| EU AI Act module (classification wizard, 84 obligations) | |||||
| ISO 22301 Business Continuity | |||||
| BCP live activation — actual-vs-planned RTO | |||||
| Enterprise risk register & heatmaps beyond compliance scope | |||||
| Objective 0–100% composite assurance score (vs RAG bands) | |||||
| AI document generation across 26 standards | |||||
| Internal audit execution — findings, corrective actions, NCRs | |||||
| Incident RCA (6 methods) + anonymous reporting | |||||
| Interactive training — 19 courses, quizzes, auto-certificates | |||||
| Change management — ITIL 4 lifecycle, CI/CD deploy ingestion | |||||
| ESG & Sustainability (8 modules) + CSRD/ESRS | |||||
| UK Provision 29 board reporting | |||||
| Native TPRM intelligence — sanctions/PEP, ownership graphs, insolvency | |||||
| NATO Admiralty evidence grading on findings | |||||
| One platform — from £2,000/mo per company, unlimited users |
Enterprise suites are powerful — and priced, licensed and implemented like it. Capabilities per public positioning, July 2026. † = requires a separately-licensed add-on product or partner data integrations.
| Capability | GRCxAI | ServiceNow IRM | IBM OpenPages | Corporater | SAP GRC |
|---|---|---|---|---|---|
| ISO 27001 pre-mapped | |||||
| ISO 42001 — govern your AI (not just theirs) | † | ||||
| EU AI Act module | † | ||||
| Generative document authoring (not just summaries) | |||||
| UK Provision 29 principal-risk reporting | |||||
| ESG + CSRD/ESRS in the same suite | † | † | |||
| Interactive compliance training + auto-certificates | † | ||||
| Internal audit execution | |||||
| Incident RCA (6 methods) + anonymous reporting in GRC | † | ||||
| Objective 0–100% composite assurance score (vs RAG bands) | |||||
| BCP live activation — actual-vs-planned RTO | |||||
| GRC-native change management (trail = ISO 27001 A.8.32 / SOC 2 CC8.1 evidence) | † | † | |||
| Native TPRM intelligence — sanctions/PEP, registry & ownership, insolvency, attack surface | † | † | † | ||
| NATO Admiralty evidence grading on findings | |||||
| 26 standards pre-mapped out-of-box + 26 completion guides | † | † | |||
| Setup in days, self-serve (not months of consulting) | |||||
| Transparent pricing — flat per company, unlimited users, no per-seat licensing | |||||
| AI-native, complete, ready today — from £2,000/mo per company |
Security-ratings tools grade a vendor's cyber hygiene. GRCxAI also answers the question they can't: may you legally and prudently trade with them? Competitor capabilities reflect their public product positioning, July 2026.
| Capability | GRCxAI | Panorays | Security Scorecard | RiskRecon | UpGuard | Risk Ledger |
|---|---|---|---|---|---|---|
| Continuous outside-in attack-surface monitoring | ||||||
| Security questionnaires & vendor response portal | ||||||
| Answers AI-verified against independent evidence — verdict shown per answer | ||||||
| AI reads & verdicts every uploaded evidence document | ||||||
| Combined rating with a published, explainable formula | ||||||
| Sanctions, PEP & debarment screening | ||||||
| Financial due diligence — insolvency, credit, VAT | ||||||
| Registry identity & beneficial-ownership graph — sanctions down the chain | ||||||
| Modern-slavery registry screening | ||||||
| Every finding graded for reliability (NATO Admiralty scale) | ||||||
| Hash-chained, append-only forensic audit trail | ||||||
| Full GRC platform included (risk, compliance, BCP, ESG, AI governance) | ||||||
| Due diligence beyond cyber — £2,000/mo, unlimited monitored vendors |
ISO 42001 + ISO 27001 + ISO 27701 + EU AI Act + ESG/CSRD — 26 standards natively integrated. Plus continuous, evidence-based Third-Party Risk Management. No second tool needed. No data silos. No integration headaches.
Book a Demo