Subscribe & import
Pull Source Statements and their mapped Practices from any subscribed release into your tenant.
Same Practice. Many contexts. One coherent model.
Conventional GRC tools model one control per framework requirement. But that's not how real organizations operate. A single requirement — 'enforce role-based access control' — exists across cloud infrastructure, on-prem systems, HR systems, branch banking systems, SaaS applications. Different owners. Different evidence locations. Different assurance modes. Different criticality.
Force-fitting all of that into one control loses operational truth. Splitting it into five controls loses regulatory traceability.
A Practice in GRAC is a normalized template — the framework-agnostic concept of what the requirement means.
A Practice Instance is the operational reality of how that Practice runs in a specific context.
Your organization creates as many Practice Instances per Practice as your reality requires — one per environment, one per business unit, one per geography, one per branch — each with its own owner, evidence, dependencies, and assurance mode.
A Practice does not run. A Practice Instance runs.
Pull Source Statements and their mapped Practices from any subscribed release into your tenant.
Author internal Source Statements alongside subscribed releases, mapped to Practices, flowing through the same operationalization pipeline.
Decide how many Instances of each Practice your organization needs (zero, one, or many). Capture rationale for non-applicability. Bulk-create Instances for Practices that operationalize identically across many contexts.
Primary, secondary and escalation owner; department; business function; criticality; execution frequency; assurance frequency; evidence type; retention period.
Evidence location and locator; full dependency map (people, processes, tools, vendors, third parties); assurance mode (automated via API / connector / agent, or manual via assurance ticket).
At every stage — applicability, configuration, operationalization.
For incomplete or inactive dependencies, before they cause a failure.
ISO 27001 A.5.15 — with parallel statements in NIST CSF, RBI, PCI DSS, SOC 2.
Enforce role-based access control
In a typical enterprise, this Practice instantiates as multiple Instances:
Automated via AWS IAM API
Owned by Cloud Security Team
Automated via agent
Owned by Identity Team
Manual quarterly review
Owned by HR Director
Manual monthly review
Owned by Branch Manager
Same Source Statement. Same Practice. Four Instances. Four owners. Four assurance regimes. One coherent compliance picture.
Every control has a named, accountable owner — zero ambiguity.
The same Practice can have some Instances automated and others manual — no artificial splits.
Multi-context audit becomes possible — scope to specific Instances, all Instances under a Practice, or all Practices in a Release.
Multi-branch banks, multi-ward hospitals, multi-plant manufacturers, multi-product SaaS teams — all finally have a data model that matches their reality.
| MODERN COMPLIANCE TOOLS | LEGACY GRC | GRAC | |
|---|---|---|---|
| Control model | One control per requirement | Static control library | Practice template → many Instances |
| Multi-context handling | Loses operational variation | Tribal knowledge in notes | Atomic Instances per context |
| Mixed-mode assurance | All-or-nothing | All-or-nothing | Per-Instance choice |
| Owner clarity | Diffuse | Often ambiguous | One named owner per Instance |
We'll walk you through the Practice Instance Model with examples from your industry.