Screenata

Beyond SOC 2

What is GRC?

August 18, 20263 min read

What is GRC?

GRC stands for Governance, Risk, and Compliance: three disciplines managed as one rather than in separate silos. Governance sets direction, accountability, and policy. Risk management identifies, assesses, and treats what could go wrong. Compliance meets obligations imposed from outside. The term describes both an operating approach and a software category, and treating those as the same thing is the most common mistake when evaluating tools.

The three letters

LetterAnswersTypical artifact
GovernanceWho decides, and on what authority?Policies, roles, board reporting, delegation of authority
RiskWhat could go wrong, and what are we doing about it?Risk register with owners, scores, and treatments
ComplianceWhat are we obliged to do, and can we prove it?Control matrix, evidence, audit reports, certificates

The argument for managing them together is that they share inputs. A risk assessment drives which controls you implement, controls produce compliance evidence, and governance decides who owns the result. Run separately, the same work gets done three times and the answers disagree.

GRC the practice, and GRC the software category

These are different things sold to different buyers.

Enterprise GRC platforms (Archer, MetricStream, ServiceNow GRC, LogicGate, Riskonnect) manage enterprise risk registers, policy lifecycle, audit workflow, and regulatory change across large organisations with a staffed risk function. Implementation is a project measured in months.

Compliance automation platforms (Vanta, Drata, Secureframe, Sprinto, Scrut) connect to your cloud and identity systems, monitor controls against a framework like SOC 2, and surface what needs evidence. The buyer is a company pursuing a certification.

Agent-first tools (Screenata) perform the work rather than tracking it: generating policies from attested operations, running the tests, chasing attestations, filing evidence.

A 20-person SaaS company that needs SOC 2 to close a deal has a narrow problem. Buying an enterprise GRC suite for it is the expensive version of the mistake, and buying nothing and doing it in a spreadsheet is the cheap version.

The GRC Capability Model

The most-cited structural model is OCEG's, which describes four components: Learn, Align, Perform, Review. It is a cycle rather than a sequence, and the loop back from Review to Learn is what stops a program rediscovering the same gaps each year. See what are the 4 components of GRC.

Where most programs actually fail

Not in governance, which is usually documented. In Perform and Review: controls that exist on paper and never operated, and findings that never fed back. An auditor can only test evidence, so a control with no artifact behind it is an assertion regardless of how well the governance around it is written.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.