Buyer's guide
GRC tools: a buyer's guide to governance, risk and compliance for AI
A vendor-neutral guide to what GRC tools do, the categories, how AI changes the requirement, what to check when buying and what a GRC tool cannot see.
A GRC tool holds an organisation's policies, risks, controls, evidence and audits in one place, so governance, risk and compliance work can be repeated and shown to an auditor. AI adds new records to track, such as models, agents and data flows, and evidence that a GRC tool cannot produce by itself: what the system did at runtime. This guide names no vendors. Swfte is not a GRC suite.
Last verified 2026-10-07. Sources are listed at the end of the page.
What is GRC, and what does a GRC tool do?
OCEG defines GRC as the integrated collection of capabilities that let an organisation reach "Principled Performance", meaning the reliable achievement of objectives while addressing uncertainty and acting with integrity. Its GRC Capability Model (version 3.5, the Red Book) integrates governance, strategy, risk, audit, compliance, ethics and culture, and IT.
A GRC tool is software that supports that work. It is not the capability itself. A tool can store a policy but cannot decide your risk appetite, and it can track a control but cannot make the control operate. Judge a tool by how much trustworthy evidence it holds and how little manual re-keying it needs.
What are the core functions of a GRC tool?
The rows below are this page's own grouping of common modules, not an OCEG list. Products name and bundle them differently.
| Function | What it holds | The AI-era question to ask |
|---|---|---|
| Policy library | Policies, standards and procedures, with owners, versions and attestations. | Can it hold an AI acceptable use policy and link it to the systems it governs? See company AI policy. |
| Risk register | Risks, ratings, owners and treatments. | Can a risk attach to a model, an agent or a data flow, as well as to a business process? |
| Control mapping | One control mapped to several frameworks. | Does it carry mappings for the NIST AI RMF, the EU AI Act and ISO/IEC 42001, and can you edit them? |
| Evidence collection | Screenshots, exports, tickets and attestations, with dates. | Can evidence arrive from a system through an interface, or only by upload? |
| Audit management | Audit plans, findings and remediation tracking. | Can an auditor sample runtime records for an AI system, or only read a narrative? |
| Third-party risk | Supplier inventory, questionnaires and reviews. | Does it record which model providers each AI system calls, and which data goes to each? |
Which categories of GRC tool exist?
Vendors blend categories, so treat these as a way to ask questions. Check each vendor's own product page for what it states.
| Category | Typically built for | Question for AI use |
|---|---|---|
| Enterprise GRC suites | Broad risk, audit and policy work across a large organisation, with workflow and reporting. | Does it support AI-specific record types, or must you model them as generic assets? |
| Compliance automation | Collecting evidence for named frameworks from connected systems, often for security audits. | Which AI frameworks does it carry, and which connectors reach your AI stack? |
| Privacy and third-party risk tools | Data mapping, assessments, supplier reviews and questionnaires. | Can it run an impact assessment for an AI use case and link it to the system record? |
| AI governance platforms | Inventory, risk tiering, assessments and framework mappings specific to AI. | Is evidence taken from runtime, or entered by people after the fact? |
How does AI change what you need from a GRC tool?
An AI inventory
NIST AI RMF subcategory GOVERN 1.6 reads "Mechanisms are in place to inventory AI systems", resourced according to risk priorities. It is voluntary. Whatever tool you buy needs a record per model, agent and tool server. See AI inventory management.
Risk tiers for models and agents
An agent that can send email or change records carries different risk from a summariser. The tool should let you tier by what a system can reach and do, and review the tier when that changes.
Framework mappings you can inspect
Ask for the mapping text as well as a logo. The NIST AI RMF is voluntary, the EU AI Act is binding law with dated duties (see what changed), and ISO/IEC 42001 is a management system standard. The European Commission says its goals and definitions are not aligned with the quality management system the AI Act requires, so a mapping is a convenience, not a proof.
Runtime evidence
The AI Act requires high-risk systems to allow automatic recording of events over their lifetime (Article 12) and asks deployers to keep logs for at least six months (Article 26). Whether those articles apply to you depends on your role and use case. Either way, a tool that can ingest event records is more useful than one that stores screenshots.
Change records
Models, prompts and tool permissions change weekly. The tool should link a change to the system record and the review it triggers.
What should you check before you buy a GRC tool?
Ask each vendor to show these in a demonstration with your data, not slides.
- Can you create a custom record type for a model, an agent and a tool server, with your own fields?
- Is there an interface for sending evidence in, such as events, tickets and exports, and what are its limits?
- Can you read and edit each framework mapping, and see its version and date?
- Does it record the model providers and data locations behind each AI system for third-party risk?
- Who can see risk ratings and findings, and is access logged?
- Can you export everything in an open format if you leave?
- What does the vendor's own documentation say it does not do? Read that page first.
- How is pricing set, and is it published? If the vendor states "contact sales", write that down rather than guessing.
What can a GRC tool not see?
A GRC tool sees what people or connected systems tell it. It does not see what an AI agent did between audits. Which tools did it call, with what arguments? Did a person approve the action, and did the approval cover that exact call? Which policy decision let it through? Those facts live in the runtime, in gateway logs, agent platforms and approval systems.
That gap matters because an attestation says a control exists, while a runtime record shows it operating. The practical answer is to treat the GRC tool as the system of record for decisions and ownership, and to feed it records from the runtime. Sampling a few events per quarter is better than a screenshot, and a continuous feed is better still, where the tool can take one.
Two limits remain. A runtime record shows what happened and not whether the outcome was acceptable, and no tool replaces the person who decides. See AI agent governance and the AI audit trail.
Where Swfte fits
Swfte is not a GRC suite. It has no policy library, audit workflow or risk register that replaces one. What it can produce is runtime evidence a GRC system can take in: audit events, approvals and policy decisions from the gateway and the governed agent runtime. The policy engine applies only to runs that have a policy attached, and the run ledger has read and verify endpoints. No export format for a specific GRC product is claimed here.
The Trust Profile is the design for one record per AI system holding owner, risk level, approved models and controls. It is design intent: those controls exist as separate parts today and are not yet joined into one record. See AI governance for the platform view.
You do not need Swfte if your AI use is small enough to track in your current GRC tool, or if you do not run agents. Swfte provides the technical controls, governance mechanisms and evidence you need to deploy AI within your applicable regulatory, security and policy requirements. The exact posture depends on your use case, jurisdiction, deployment and configuration.
Sources and last verified
Every dated or technical fact on this page was read from the pages below on 2026-10-07. Anything that could not be confirmed is left out or marked as not verified.
- OCEG: GRC Capability Model 3.5 (Red Book). The definition of GRC, Principled Performance, the version and the disciplines the model integrates.
- NIST AI 100-1: AI Risk Management Framework (AI RMF 1.0). GOVERN 1.6 on inventorying AI systems and the voluntary status of the framework.
- European Commission: understanding standardisation under the AI Act (FAQ). The statement that ISO/IEC 42001 goals and definitions are not aligned with the AI Act quality management system. Dated 10 March 2026.
- AI Act Service Desk: Article 12, record-keeping. Automatic recording of events over the lifetime of a high-risk system.
- AI Act Service Desk: Article 26, deployer obligations. Log retention of at least six months for deployers of high-risk systems.
Frequently asked questions
What does GRC stand for?
GRC stands for governance, risk and compliance. OCEG defines it as the integrated collection of capabilities that let an organisation reach Principled Performance, the reliable achievement of objectives while addressing uncertainty and acting with integrity. A GRC tool is software that supports those capabilities.
Do I need a separate GRC tool for AI?
Not always. If your current GRC tool can hold custom record types and take evidence from other systems, you can add AI records to it. A separate AI governance platform makes sense when you need an AI inventory, model and agent risk tiers, or framework mappings your current tool lacks.
Can a GRC tool meet our EU AI Act duties for us?
No tool can. The Act sets duties for providers and deployers according to role and risk class. A GRC tool can hold your inventory, assessments and evidence, and track owners and deadlines, but classification and legal judgement stay with you and your counsel.
What is runtime evidence?
Runtime evidence is a record produced by the system while it operates, such as an audit event, an approval decision or a policy outcome, with a time and an identity. It differs from an attestation, which is a person stating a control exists. Auditors can sample runtime evidence directly.
Is Swfte a GRC tool?
No. Swfte is a Sovereign Intelligence Platform. It can supply runtime evidence such as audit events and approvals to a GRC system, and the Trust Profile is a design for one record per AI system. It does not replace a policy library, a risk register or an audit workflow.
How should I compare GRC vendors without trusting marketing pages?
Use the vendor's own documentation, ask for a demonstration with your data, and write down what the documentation says the product does not do. Compare published limits and published prices only. If a vendor does not publish a price, record "sales-led" and the date you asked.