PLATFORM OVERVIEW

One Platform. The Entire GRC Stack.

From raw regulatory text to board-ready evidence. GRAC delivers the complete journey, on a single architecture.

Two-Tier IdentityCCAConcurrentEight ModesPractice Instance
THE FOUR DEFINING PRINCIPLES

Four architectural principles.

Four architectural principles separate GRAC from conventional GRC tools. They explain why GRAC scales where others fragment, and why governance teams trust it as their operating fabric.

01

Principle 1 — Identity is Two-Tiered

GRAC serves two distinct audiences with two distinct identity planes. Our content team curates the global library; your team operates your governance. Authentication, audit logs, and data are isolated end to end. Your data is never visible to anyone outside your organization.

02

Principle 2 — Assurance is Concurrent Audit. Not the Sole Source of Truth.

The Assurance Engine performs continuous, automated concurrent audit on every operationalized Practice Instance. The signals it produces feed two independent disciplines — Risk Management and Internal Audit. The platform supports their judgement; it never replaces it. We respect the Three Lines of Defense. Most platforms flatten it.

03

Principle 3 — One Engine. Every Audit Mode.

Concurrent audit. Compliance audit. Risk-based internal audit. Branch inspection. Vigilance investigation. Forensic audit. Thematic audit. Operational audit. GRAC supports all eight on one engine, fed by one signal fabric, with type-specific behaviors layered on top.

04

Principle 4 — Practices are Templates. Instances are Atomic.

A Practice in GRAC is a normalized template — the executable concept of a regulatory requirement. Practices do not run. Their Instances do. Each organization creates one or more Practice Instances per Practice, instantiated with full operational context — owner, evidence, dependencies, frequencies, assurance mode. This is what lets GRAC handle the messy reality of large organizations: the same Practice running across branches, environments, business units, or product lines — each Instance with its own context.

THE FIVE PARTS OF THE PLATFORM

The stack. Ground up.

PART 0

Platform Services

The foundation. Two-tier identity, workflow engine, task engine, notifications, integration framework, reporting engine, multi-entity hierarchy, customer theming, and a tamper-resistant audit log.

PART 1

Knowledge Repository

The curated library. Every authority. Every artifact. Every release. Every Source Statement extracted, classified, positioned in its source structure, and mapped to normalized Practices through the Common Control Architecture. Framework agnostic. Domain agnostic. Industry agnostic.

PART 2

Operationalization

Where standards meet your organization. Subscribe to releases. Import Practices. Create Practice Instances per your operational context. Configure ownership, frequency, and evidence. Map dependencies. Operationalize. Run the Assurance Engine.

PART 3

Intelligence

Three governance disciplines on one signal fabric. Compliance Management. Risk Management. Multi-modal Audit Management. With CXO and board reporting, organizational knowledge search, and an optional AI intelligence layer.

PART 4

Extended GRC

Adjacent capabilities — third-party risk, VAPT, gap analysis (including cross-framework), dependencies, documents, evidence vault, training, exception, incident, maturity, regulatory reporting — all integrated, all sharing the same Practice Instances, signals, and workflows.

READY?

See the Architecture Diagram.

We'll walk through the five parts and four principles on a live tenant.