THE PRACTICE INSTANCE MODEL

Same Practice. Many contexts. One coherent model.

GRAC's data model handles the operational reality that no conventional GRC tool has handled before: the same control running across multiple environments, locations, or business units — each with its own owner, evidence, and assurance mode.

Talk to a Solution Engineer
PracticeInstanceOwnerEvidenceCadence
THE CONVENTIONAL PROBLEM

Real organizations don't fit one control per requirement.

Conventional GRC tools model one control per framework requirement. But that's not how real organizations operate. A single requirement — 'enforce role-based access control' — exists in many places: in the cloud, on-premise, across HR systems, across branch banking systems, across SaaS applications. Each place has different owners. Different evidence locations. Different assurance modes. Different criticality.

Force-fitting all of that into one control loses operational truth. Splitting it into five controls loses regulatory traceability.

THE GRAC MODEL

A Practice is the concept. A Practice Instance is the operation.

In GRAC, a Practice is a normalized template — the framework-agnostic concept of what the requirement means. A Practice Instance is the operational reality of how that Practice runs in a specific context.

A Practice does not run. A Practice Instance runs.
THREE EXAMPLES

The same model. Three industries. Twelve Instances.

Example 1Multi-environment Access Control

SOURCE STATEMENT
ISO 27001 A.5.15
(and parallel statements in NIST CSF, RBI, PCI DSS, SOC 2)
PRACTICE
Enforce role-based access control

In a typical enterprise, this Practice instantiates as multiple Instances:

INSTANCE 1
RBAC on production AWS
Automated via AWS IAM API
Cloud Security Team
INSTANCE 2
RBAC on on-premise Active Directory
Automated via agent
Identity Team
INSTANCE 3
RBAC on HRMS
Manual quarterly review
HR Director
INSTANCE 4
RBAC on branch banking system
Manual monthly review
Branch Manager

Same Source Statement. Same Practice. Four Instances. Four owners. Four assurance regimes. One coherent compliance picture.

Example 2Multi-ward Hand Hygiene Compliance

SOURCE STATEMENT
NABH Standards on Infection Control
PRACTICE
Healthcare worker hand hygiene compliance verification

In a hospital, this Practice instantiates as:

INSTANCE 1
ICU ward hand hygiene
Manual daily observation
ICU Head Nurse
INSTANCE 2
General ward hand hygiene
Manual weekly observation
Nursing Supervisor
INSTANCE 3
Operating theatre hand hygiene
Manual per-procedure attestation
OT Coordinator
INSTANCE 4
Dispenser refill verification
Automated IoT sensor integration
Facility Manager

One Source Statement. One Practice. Four atomic Instances, each accountable, each assured at its appropriate cadence.

Example 3Multi-plant Machine Guard Inspection

SOURCE STATEMENT
ISO 45001
(with parallel statements in ISO 9001, ISO 14001, Factories Act)
PRACTICE
Machine guard inspection before startup

In a manufacturing group:

INSTANCE 1
Plant Chennai, Line A
Per-shift inspection, photo evidence via mobile app
Shift Supervisor
INSTANCE 2
Plant Chennai, Line B
Per-shift inspection
different Shift Supervisor
INSTANCE 3
Plant Pune, Line A
Per-startup inspection
IoT sensor + manual attestation
INSTANCE 4
Plant Baddi, Line A
Per-shift inspection
Paper log migrated monthly to digital

Same ISO Practice. Four Instances across three plants. Corporate quality gets comparative analytics: which line, which shift, which plant has better guard-inspection completion?

WHY THIS MATTERS

Six architectural side effects. Each measurable.

Real ownership clarity
each Instance has exactly one accountable owner. No diffuse responsibility.
Mixed-mode assurance
some Instances of the same Practice can be automated, others manual. No artificial splits.
Accurate rollups
Instance-level signals aggregate to Practice posture, Practice posture aggregates to Release posture, with mathematical defensibility.
Continuous improvement at the right granularity
when one Instance fails, only that Instance is remediated, not the entire Practice.
Multi-context audit
auditors can scope to specific Instances, or audit all Instances under a Practice, or all Practices in a Release.
Comparative analytics
same Practice across multiple contexts becomes a data question, not an opinion question.
READY?

See the Model in Action.

We'll walk through the Practice Instance Model with examples from your industry.