When AI Can Do the Risk Work, What Is a GRC Platform Actually For?
AI is making some of the most visible work in governance, risk and compliance remarkably easy to reproduce. But that does not necessarily mean GRC platforms themselves are becoming commodities.
I started thinking about this after encountering what felt like a sudden proliferation of relatively inexpensive GRC platforms.
The demos were surprisingly capable.
Policies could be generated. Regulations mapped to controls. Evidence analysed. Questionnaires answered. Risks summarised. Increasingly, AI agents were not simply assisting users; they were being positioned to perform parts of the work themselves.
These were capabilities that, not very long ago, helped distinguish sophisticated enterprise GRC platforms.
Then I met another GRC vendor with a rather different proposition.
Instead of presenting GRC primarily as a repository for controls, assessments and findings, the conversation centred on creating something closer to a Risk Operations Centre.
That changed the question.
Perhaps the interesting story is not simply that AI is making GRC cheaper.
Perhaps AI is forcing us to reconsider what a GRC platform is actually for.
The commoditisation question
There is an obvious hypothesis.
If generative and agentic AI can create policies, map requirements, review evidence, conduct assessments, complete questionnaires and coordinate remediation, then a significant amount of functionality that once required substantial product development — and substantial human effort — becomes easier to reproduce.
There is evidence of exactly this capability convergence.
Sprinto now combines continuous monitoring across hundreds of integrations, automated evidence collection, AI-powered vendor assessments, questionnaire automation, evidence-gap analysis and custom AI agents.
LogicGate makes an even more useful distinction between AI that assists and agents that actually perform GRC work. Its current GRC Agents can execute workflow steps and, for example, run an assessment rather than merely recommend one.
Drata's September 2026 third-party-risk release similarly combines vendor intake, risk tiering, evidence collection, criteria-based assessment, residual-risk evaluation and decision tracking in an agentic workflow. Importantly, the human reviewer still retains responsibility for the final vendor decision.
Whistic goes further in its language, explicitly calling itself an Agentic Risk Operations Platform. Its agents gather evidence, analyse it and produce findings while humans retain consequential decisions and approvals.
The pattern is difficult to ignore.
But there is an important distinction:
Feature convergence is not the same thing as economic commoditisation.
Forrester's 2026 GRC assessment describes many platforms as still requiring too much manual data entry, providing basic workflow automation, and being complex or expensive relative to the value they deliver. It also reports limited customer enthusiasm for today's AI functionality. But none of that proves that enterprise GRC prices themselves are systematically collapsing.
The evidence therefore supports a narrower proposition:
Parts of GRC functionality are commoditising faster than we can yet demonstrate that enterprise GRC economics are commoditising.
And a capability does not have to become free before it stops being strategically differentiating.
It merely has to become ordinary.

AI did not invent continuous risk
This is where the story gets more interesting.
The idea that risk and controls should be monitored continuously is much older than generative AI.
In September 2011, NIST published SP 800-137, describing continuous monitoring as a way to maintain visibility into assets, threats, vulnerabilities and the effectiveness of controls — and to provide information quickly enough for organisations to respond to changing risk.
That was fifteen years ago.
Yet much enterprise GRC remained periodic: quarterly assessments, annual control testing, scheduled attestations, audit evidence assembled when required, and risk registers refreshed through workshops and questionnaires.
Even in 2026, Forrester describes continuous controls monitoring as the weakest capability area across the GRC platforms it evaluated. Much of what is currently called continuous monitoring remains oriented toward gathering audit evidence rather than continuously measuring control effectiveness and triggering remediation.
That fifteen-year gap deserves more attention than another discussion about AI-generated policies.
Because enterprises have never lacked signals.
Identity systems know when access changes.
Cloud platforms know when configuration changes.
Security tools know when vulnerabilities emerge.
ERP systems know when authorities, transactions and business processes change.
Third-party intelligence services know when suppliers change.
The harder problem is translating all those changes into governance.
- What changed?
- Which risk did it affect?
- Which control is involved?
- Is the change material?
- Who owns the decision?
- What should happen next?
- Can that decision be defended later?
Continuous monitoring generates data.
It does not automatically create continuous risk management.
The expensive part may have been interpretation
A great deal of GRC work consists of translation.
- Regulations into obligations.
- Obligations into controls.
- Controls into evidence.
- Evidence into findings.
- Findings into risks.
- Risks into decisions.
- Decisions into remediation.
- And remediation back into evidence.
Historically, humans supplied much of that connective tissue.
Humans are very good at judgement, ambiguity and accountability.
They are rather less scalable when the work involves repeatedly reading documents, collecting evidence, comparing artefacts, chasing responses, mapping requirements and preparing routine assessments.
Agentic AI attacks precisely that layer.
Which gives us a more consequential hypothesis:
AI's most important contribution to GRC may not be better intelligence. It may be reducing the human interpretation and coordination cost that has prevented continuous risk management from becoming operationally practical.
That is a much larger change than generating policies faster.
From system of record to system of action
Current analyst research is beginning to describe the market in similar terms.
Forrester expects GRC platforms to evolve from systems that principally record the outputs of risk, compliance and audit processes into systems of action that orchestrate specialist data sources, technologies and workflows. But it simultaneously cautions that much of today's AI capability remains incremental rather than transformational.
Gartner is more cautious still.
At its September 2026 Enterprise Risk, Audit & Compliance Conference, Gartner placed anomaly detection, automated risk scoring, workflow assistance, continuous control monitoring, automated evidence collection and document review among the more mature AI use cases available to assurance teams today.
Autonomous third-party risk management and “self-driving GRC orchestration”, by contrast, were characterised as longer-term opportunities — closer to moonshots than immediate priorities.
That tension is useful.
The Risk Operations future should not be presented as if it has already arrived.
A better interpretation is:
The architecture is emerging before the operating model is mature.
The market increasingly knows what it wants to build.
Whether enterprises are ready to trust it is another question.

Sense → Decide → Act → Prove
Looking across established GRC platforms, compliance-automation vendors and newer agentic entrants, I find one model particularly useful for separating cosmetic AI from something closer to operational risk management.

Sense
Can the platform continuously consume changes from the actual systems where risk emerges — identity, cloud, security, ERP, HR, third parties and other operational sources — rather than waiting for somebody to complete an assessment?
Decide
Can it translate those signals into business, control and risk context? A changed configuration is not yet a risk decision. Something has to understand why it matters.
Act
Can the system initiate an assessment, escalate an exception, create remediation, enforce a policy or otherwise change the workflow without waiting for a human to manually connect every step?
Prove
Can it preserve the evidence, reasoning, authority, approvals and outcomes well enough that the resulting decision remains defensible? The first three describe increasingly autonomous Risk Operations. The fourth becomes increasingly important because machines are beginning to do the first three.
The moat probably isn't the AI
Nearly every serious GRC vendor can add an LLM.
That makes “we have AI” a rapidly depreciating product claim.
The harder challenge is giving the AI authoritative context.
IBM's OpenPages 9.2 provides an interesting example. Its MCP interface allows external AI agents to access OpenPages objects, relationships and actions through governed interfaces, while the platform retains policy-aware and auditable interactions. Its subsequent 9.2.1 release added APIs specifically capable of exposing an object's broader relationship hierarchy to AI agents.
SAP is heading in a similar direction. Its current GRC proposition combines real-time irregularity detection, automated evidence collection and AI agents with the wider business-process and identity context available inside SAP environments. SAP describes its Governance Assistant as correlating risk and control signals across systems to move organisations from periodic oversight toward continuous risk and compliance monitoring.
This suggests that the emerging moat may not simply be better AI.
- It may be trusted context:
- this regulation creates this obligation;
- this obligation maps to this control;
- this control applies to this business service;
- this evidence demonstrates — or fails to demonstrate — its operation;
- this issue changes this risk;
- this person has authority to accept that risk;
- and this decision was made under these conditions.
An LLM without those relationships may produce an excellent paragraph.
An agent with trustworthy relationships may be able to participate in an enterprise decision.
Those are very different propositions.
But the GCC complicates the commoditisation story
This is where the global argument encounters an important regional reality.
Many of the vendors demonstrating the most aggressive AI-native GRC models today have relatively limited presence in Qatar and the wider GCC.
That matters because enterprises here do not buy GRC capability in an abstract feature market.
- They also buy deployment assurance.
- Data residency.
- Regulatory fit.
- Implementation capacity.
- Local support.
- Established relationships.
- Integration with existing enterprise platforms.
And confidence that the vendor and its partner ecosystem will still be present when a regulator, internal auditor or board committee asks difficult questions several years later.
This creates a significant distinction:
Feature commoditisation may be global. Vendor commoditisation is not.
Installed enterprise gravity is real
Consider Qatar.
In 2020, KAHRAMAA publicly tendered for implementation of RSA Archer to build an enterprise GRC programme across its IT department. Four years later, another public tender sought three years of licence renewal and support for the existing Archer environment.
That is important because enterprise GRC is not merely software.
Once an organisation has embedded risk taxonomies, control libraries, workflows, organisational structures, reporting relationships, integrations, historical findings and years of evidence inside a platform, replacing it becomes an architectural decision.
Not a feature comparison.
MetricStream's published Middle East banking cases illustrate similar characteristics: tightly integrated risk and control taxonomies, regulatory mappings, organisational structures and integrations with security operations such as SIEM, DLP and identity systems. The company also maintains implementation relationships in Saudi Arabia through regional cybersecurity partners.
Corporater provides another regional signal. It established a Riyadh office and Saudi SaaS capability in 2024, followed by Qatar SaaS availability in 2025.
Archer itself operates a UAE SaaS data centre intended to address Middle Eastern performance and data-residency requirements.
Diligent, meanwhile, is actively increasing its Middle Eastern presence through a regional organisation, partners and GCC-facing activities.
These aren't glamorous AI features.
They are market infrastructure.
And in the GCC, that infrastructure may protect incumbent platforms far longer than a pure technology comparison would suggest.
The regional AI story is nevertheless already beginning
Installed gravity does not mean the operating model will remain static.
One of the most interesting examples in the research comes from the UAE.
In January 2026, e& and IBM announced an enterprise-grade agentic-AI initiative focused initially on policy, risk and compliance. A joint proof of concept developed with Gulf Business Machines integrated IBM watsonx Orchestrate with the OpenPages environment and demonstrated agents reasoning across regulatory and compliance information while keeping responses traceable and operating within enterprise governance controls.
There is a subtle but important lesson here.
The regional path to agentic GRC may not necessarily involve throwing out the incumbent GRC platform and replacing it with an AI-native startup.
It may involve putting an agentic execution layer on top of the trusted enterprise system already in place.
That strengthens one of our counter-hypotheses:
AI may actually increase the value of some incumbent GRC platforms if their existing data models, relationships and controls become the trusted context upon which agents operate.
In other words, the old system of record may become the foundation for the new system of action.
That would be much more threatening to weak incumbents than to strong ones.
Why lower-cost platforms still matter
None of this makes the AI-native challengers irrelevant to the GCC.
Quite the opposite.
Their significance may initially be less about replacing Archer, MetricStream, OpenPages, ServiceNow or SAP inside the largest regulated enterprises.
Their significance may be that they expose how much functionality can now be delivered with much less product complexity.
- A smaller vendor can increasingly demonstrate:
- policy generation;
- control mapping;
- continuous evidence;
- vendor assessment;
- questionnaire automation;
- AI agents;
- risk recommendations;
- and workflow automation.
That changes the buyer's frame of reference even if the buyer ultimately chooses an incumbent.
The question becomes:
If much smaller platforms can now perform these functions, what exactly justifies the enterprise premium?
The incumbent then needs a better answer than “we have more features”.
A two-speed GRC market?
This leads to a hypothesis that deserves further testing.
AI may not commoditise the GCC GRC market evenly.
At the mid-market, greenfield and narrower-compliance end, lighter AI-native platforms may increasingly provide enough capability without the cost and complexity of a large GRC programme.
At the large regulated-enterprise end, incumbents may retain significant advantage because their value is increasingly tied to installed context, data residency, regulatory confidence, complex operating models and integration into enterprise systems.
If that happens, the market does not simply commoditise.
It bifurcates.
And the most vulnerable segment may be the middle: platforms charging enterprise-style premiums while offering little that cannot increasingly be reproduced elsewhere.
That is still a hypothesis.
But it is now one worth watching.
Risk Operations may be emerging before the category has a name
“Risk Operations Centre” is not yet a stable industry category.
Different vendors mean different things when they use similar terminology.
Whistic defines Agentic Risk Operations around connected third-party-risk, monitoring, compliance and evidence workflows.
LogicGate talks instead about agents performing high-volume GRC work while retaining human review and permissioned actions.
IBM talks about AI moving into the execution layer of GRC.
SAP describes agents correlating risk and control signals while moving oversight from periodic to continuous.
The terminology differs.
The architecture increasingly does not.
This is why I am reluctant to declare “Risk Operations” a new product category.
It may be something more interesting:
an operating model emerging across multiple categories before the software market has agreed what to call it.
Humans may retreat toward the accountability boundary
Another pattern deserves attention.
The agents are increasingly being given the work.
The humans are retaining the consequential decision.
Drata keeps reviewers responsible for evaluating findings and making final vendor decisions.
Whistic says explicitly that agents perform repeatable work while people retain decisions, approvals and overrides.
LogicGate's formulation is even simpler:
agents act; users supervise.
This suggests a possible redesign of the GRC profession itself.
The traditional model:
human gathers → maps → assesses → chases → documents → reports → decides
may increasingly become:
machine gathers → correlates → analyses → prepares → coordinates → executes routine work
while:
human challenges → judges → authorises → accepts accountability
That boundary may prove more durable than any particular GRC feature.
Because somebody still needs to own the risk.
AI may automate risk work long before enterprises are willing to automate risk accountability.
“I accepted the risk because the agent said so” is unlikely to become a reassuring sentence at an audit committee meeting.
What changes for the enterprise buyer?
If this thesis is directionally correct, the traditional GRC feature matrix starts losing usefulness.
Policy management will not disappear.
Neither will control libraries, assessments, questionnaires, workflows, dashboards or risk registers.
They simply become poorer proxies for strategic differentiation.
A stronger GRC evaluation begins asking different questions.
- What can the platform observe continuously?
- Which operational systems provide authoritative signals?
- How does it connect an event to a control, a business service and a risk?
- What can an agent actually do rather than merely recommend?
- Who authorises those actions?
- Which decisions require human intervention?
- Can the system explain why a conclusion was reached?
- Can the supporting evidence be reproduced later?
- What happens automatically when the evidence changes?
- Where does machine authority end and human accountability begin?
And in markets such as Qatar and the wider GCC, I would add:
- Where does the data reside?
- Can the architecture satisfy local deployment and sovereignty requirements?
- Who implements and supports it locally?
- How deeply is the platform already embedded in the organisation's enterprise architecture?
Those questions test something very different from whether the vendor can demonstrate another AI copilot.
They test whether the platform can become part of the organisation's risk operating architecture.
So, is GRC becoming commoditised?
Parts of it probably are.
The evidence increasingly supports feature commoditisation, particularly around knowledge-heavy and administratively intensive work.
It does not yet justify a confident claim that enterprise GRC pricing itself is collapsing.
And it certainly does not mean every vendor becomes interchangeable.
The GCC makes that particularly clear.
Enterprise incumbency, deployment architecture, local support, data sovereignty, integration and institutional trust remain powerful differentiators.
But something subtler appears to be happening.
The bottom of the GRC value stack is becoming easier to reproduce.
At the same time, the top of the stack is becoming more ambitious.
- Documentation becomes generation.
- Assessment becomes continuous sensing.
- Workflow becomes agentic execution.
- Reporting becomes decision support.
- Evidence becomes provenance.
- Governance becomes an operating capability.
The irony is that the aspiration itself is not new.
We have been talking about continuous monitoring for at least fifteen years.
What may finally be changing is the cost of turning all those signals into decisions and action.
Which brings me back to the question that started this research:
When AI can do the risk work, what is a GRC platform actually for?
My provisional answer is:
Not to produce more GRC.
It is to establish the trusted context within which risk can be sensed, decisions can be made, actions can be taken — and somebody can still prove afterwards why any of it was justified.
If that is where the category is going, the future of GRC may look considerably less like a compliance application.
And considerably more like an enterprise operating layer.