HOW GRAC WORKS

Authority to Assurance. In One Continuous Flow.

Trace any board-level report back to the original regulatory clause that mandated it. GRAC makes that traceability the default — not a quarterly project.

AuthorityPracticeInstanceAssuranceReport
THE END-TO-END FLOW

Nine steps. One continuous flow.

Step 1
01

Curate the Authority

GRAC's content team maintains the global library. Every authority artifact — ISO 27001, RBI Master Direction on IT, NABH 6, SOC 2 — is ingested. Every requirement within each release is extracted as a Source Statement, positioned in the source structure, tagged with classification, and mapped to one or more reusable Practices. The same Practice may be mapped to Source Statements across multiple authorities — that is the Common Control Architecture at work.

Step 2
02

Subscribe and Import

Your organization subscribes to the releases that apply. Source Statements and their mapped Practices flow into your tenant. Internal policies — yours alone — flow into the same pipeline, with internal Source Statements authored and mapped to Practices alongside subscribed releases.

Step 3
03

Create Practice Instances

You decide how each Practice operationalizes in your reality. A single Practice — say, 'Enforce role-based access control' — may instantiate as one Instance in a small organization, or as five Instances in a large one (one per environment, one per business unit, one per geography). Each Instance is an atomic operational unit with its own context.

Step 4
04

Configure Each Instance

For each Practice Instance, set the execution frequency, assurance frequency, evidence type, retention period, and criticality. Assign primary, secondary, and escalation owners. Map to department and business function.

Step 5
05

Operationalize Each Instance

Define exactly where the evidence lives — the system, the path, the locator. Map every dependency the Instance relies on — people, processes, tools, vendors, third parties. Process dependencies bind to live workflows. Choose the assurance mode — automated via API, connector, or agent, or manual via assurance ticket.

Step 6
06

Continuous Assurance

The engine runs continuously against every operationalized Practice Instance. Automated Instances pull evidence directly from source systems on schedule. Manual Instances generate tickets assigned to owners with deadlines and escalation. Every check is logged. Every exception is tracked. Every piece of evidence is dated and traceable.

Step 7
07

Inform the Disciplines

Compliance Management
sees real-time posture across every release, leveraging the Common Control Architecture to show cross-framework coverage.
Risk Management
interprets failure signals into registered risks with assessment, treatment, and monitoring.
Audit Management
plans, executes, and forms opinions across eight audit modes — using the assurance signal as their pre-engagement intelligence pack.
Step 8
08

Report to the Board

CXO and board reporting draws from the same signal fabric. One-page governance summaries. Top risks. Audit findings. Compliance scores. All evidence-backed. All traceable to specific Practice Instances and the original Source Statements.

Step 9
09

Benchmark, Identify Gaps, Improve

Practices are benchmarked against the organization's own internal standards and against subscribed releases. Gaps surface automatically. Each gap becomes a task — assigned to an owner. Closure happens through creating new Practice Instances, reconfiguring existing ones, or modifying dependencies. The Assurance Engine begins running against the new Instance immediately. The improvement loop closes. Then opens again, at a higher baseline. This is Plan-Do-Check-Act, operationalized.

THE TRACE
Every action — from a subscribed release update down to an individual evidence submission — is logged, version-controlled, and auditable. Years later. By any auditor. For any regulator. And every action ultimately traces back to specific Source Statements across all linked authorities.
READY?

Walk Through It Live.

We'll take you from Source Statement to assured evidence on a real tenant.