The mechanism

Three layers turn “what we should do” into “what we did today.”

Requirements say what's expected. Practices say what you actually do about it. Scheduled activities make those practices happen — on cadence, with evidence as a byproduct. That's the whole engine.

See the loop
Requirement
ISO 27001 · A.9
RBI CSF
GRAC logo
Practice
core
Practice
Scheduled Activity
ACT-2148Due in 3 days
Monthly access review
AMSynced to JiraIn progress
Evidence captured
94%posture
How it runs

Four moves, one continuous engine.

Each layer hands off to the next — and the whole thing repeats. Below: how requirements become practices, practices become scheduled work, work becomes evidence, and evidence becomes the posture you see today.

Step 1 · Map

Map what you're accountable for

Bring every framework you carry — RBI, NABH, SOC 2, ISO 27001, PCI DSS, contractual and internal requirements — into one structured library. Requirements are mapped to the assets, teams and standards they govern, so you start from clarity instead of a pile of PDFs.

1
Framework library
versioned
ISO 27001
RBI CSF
NABH
PCI DSS
SOC 2
GDPR
DPDP
SEBI

Pre-built, queryable, kept current.

2
Step 2 · The wedge

Turn controls into activities that get done.

GRAC connects high-level controls to concrete, low-level practices and schedules them as recurring work — routed into the tools your teams already use: Jira, ServiceNow, Freshservice, ManageEngine. One practice (say, a quarterly access review) can satisfy several frameworks at once, so the same control is never re-done per standard.

Practice mapping
Quarterly access review
RAQuarterly
ISO 27001 · A.9
RBI
PCI DSS · 8
SOC 2 · CC6
DPDP

One practice → five frameworks.

Satisfies
RBI
PCI DSS
ISO 27001
DPDP
SOC 2
ACT-2148Due in 3 days
Monthly access review
AMSynced to JiraIn progress
Step 3 · Evidence

Capture evidence as you operate

Every scheduled activity produces evidence automatically — versioned, approved and retained as the work happens. When an auditor or regulator asks 'show me this is working,' the answer already exists. No pre-audit scramble, no reconstructing the binder.

3
firewall-config-Q2.pdf
Approvedv5Retained 7y
Captured automatically · 1 day ago
patch-status-Jun.csv
Approvedv2Retained 7y
Captured automatically · 3 days ago
access-review-Q2.pdf
Approvedv3Retained 7y
Captured automatically · 2 days ago
Compliance posture
All frameworks
Live
94%Compliant today
Frameworks6
Overdue0
Open risks3
ISO 27001
Operating
SOC 2
Operating
RBI
Operating
PCI DSS
Operating
Updated just now
4
Step 4 · Posture

See your posture in real time

Live compliance scoring, open gaps, overdue activities and rising risks roll up into a single real-time view — by framework, by business unit, for the board. Posture is a number you can see today, not a verdict you wait for at the next audit.

Always on

The loop never stops.

Map → operate → evidence → posture — and back. Drift surfaces as risk, risk reopens activities, activities produce evidence, evidence updates posture. Every day, by itself.

Requirement
Practice
Scheduled Activity
Evidence
Risk
Posture
Repeats — every day
The whole engine

Map → operate → evidence → posture. Continuously.

It's not a new place to store controls. It's the engine that makes them run.