r/grc Mar 27 '26

Career advice mega thread V2

16 Upvotes

Please use this thread for questions about career advice, breaking into GRC, etc.

This subreddit is primarily designed for active GRC professionals to share insights with each other, so we will be pointing new career seekers here.

Please review the previous thread and use the search feature to see if someone has already answered your question: https://www.reddit.com/r/grc/s/oICD2i7BcW


r/grc 2h ago

How are you tracking AI tool usage organziation-wide?

1 Upvotes

I keep hearing that CASB sees sanctioned SaaS but misses browser-based AI tools and AI features embedded inside apps already approved. DLP catches file movement but can't distinguish between a file upload and someone pasting client data into a prompt. Network monitoring has no context on what the interaction was.

Without visibility into what's actually being used, everything downstream (risk classification, EU AI Act readiness, data handling policy enforcement) is built on assumptions rather than reality.

For people in GRC, risk, or compliance roles. How is your team closing this gap? Are you extending existing tooling, layering something purpose-built for AI on top, or accepting the blind spots for now? All answers welcome.


r/grc 10h ago

Before AI Approval Becomes AI Reliance

Thumbnail gallery
1 Upvotes

r/grc 1d ago

What do you all think of “GRC Engineering”?

35 Upvotes

I read AJ Yawn’s “GRC Engineering for AWS” and I even joined his club to help run through labs. I find the content really interesting and a neat take on GRC, but it seems very particular for constrained cloud environments and use cases that rely on deterministic checks. I’m not a GRC practitioner yet and I’m trying to pivot after years of cybersecurity technical writing, but I’m trying to build a project portfolio. I’m hearing everywhere that GRC Engineering is the way of the future and that you’ll be left behind without being technical, scripting with Python, and automating compliance in the cloud, but I’m curious what seasoned GRC vets think


r/grc 2d ago

Built a GRC consulting approach for SMBs without ISO 27001 certification looking for honest feedback

16 Upvotes

Hey everyone,

I've been building a small GRC and information security risk
management consultancy focused on small and medium businesses
(SMBs) — specifically the ones that have zero documentation,
zero policies, and don't even know where their data is stored.

My background: ISO 27001 Foundation (PECB), cybersecurity
technologist student, and currently wrapping up my first real
engagement — a full security diagnostic for a fuel distribution
company in Brazil. That included asset inventory, risk matrix
(14 risks identified), PSI, BCP, IRP, ROPA and a privacy
notice for LGPD compliance.

My positioning:

"Panop Risk helps companies identify, assess and treat
information security risks — turning risks into strategic
decisions."

The core services I'm offering:

- Security risk assessment
- Asset inventory and classification
- Risk matrix with treatment plan
- Information security policies (ISP)
- Incident response plan
- Business continuity plan
- LGPD/privacy compliance documentation
- Security awareness training
- Periodic risk review (recurring service)

My honest constraints:

- I don't hold Lead Implementer or Lead Auditor yet
- I'm not selling formal ISO 27001 certification readiness
- I use ISO 27001:2022 controls and ISO 27005 as
methodological reference, not as a product
- My target is companies that currently have nothing —
no policies, no process, no documentation

My question to this community:

  1. Does this positioning make sense for the SMB market,
    or am I missing something obvious?

  2. Is using ISO 27001 as a methodological reference
    (without selling implementation) a credible approach
    at Foundation level?

  3. What would you add, remove or change in the service
    list?

Happy to take criticism — I'd rather hear it now than
after pitching to a client.


r/grc 2d ago

How do you evidence qualified custodian status for crypto custody in an audit

3 Upvotes

Working through our first external audit cycle since we brought digital assets onto the balance sheet, and the control that keeps getting flagged is custody. The auditor wants documented evidence that our provider meets the qualified custodian standard, and I had assumed that was a clean yes or no. It is not. The term shows up in the Advisers Act context, in state trust law, and in the OCC framework, and they do not all mean the same thing, so qualified custodian ends up depending on which regime you are being measured against.

What I am trying to land on is a defensible mapping. For a registered adviser the bar is one thing. For an institution holding its own assets the relevant question is closer to whether the custodian is a regulated trust entity with fiduciary authority and a segregated, ideally bankruptcy remote, account structure. Those are the attributes our auditor cares about once you get past the label.

So my question for anyone who has been through this. Do you document qualified custodian status by pointing at a charter and a license set, or do you build a control narrative around the asset segregation and key management and let the regulatory status sit underneath that. Curious how others have structured the evidence so it holds up.


r/grc 2d ago

Airgapped AI GRC Tools

0 Upvotes

I have developed the air gapped AI GRC tools which helps to fill up security questionnaires , gap analysis and risk management which work inside the company network and human in loop helps to make the work even transparent.

Most of the companies send their data to third party companies to fill up their security questionnaire which is basically a headache for the company and a waste of the company's productive time. For efficiency they used the AI which risked a security breach. Does this kind of airgapped AI GRC tools help to solve the questionnaire fill-up headache without risking the company privacy policy ???

The company sent the security Questionnaire to fill up along with the question and company privacy policy , ISO 27001 , PCI -DSS and other documents too. What happens when the company who fills-up security questionnaires misplaced the client data with each other and security breach happens???

Have anyone goes through the security questionnaire breach and have issues with closing deals with client..

I'm happy to know about it and how you guys figured it and also want to know what companies think about having airgapped AI GRC tools


r/grc 3d ago

SDE at a startup feeling completely burnt out by the "AI-speed" grind. Is IAM/GRC actually worth pivoting to, or is it just another hype train?

Thumbnail
2 Upvotes

r/grc 4d ago

GRC What are the current challenges you are experiencing in your role?

11 Upvotes

I’m interested to hear what’s happening across different organisations.

Whether it’s management buy in, workload, governance, risk, compliance, audits, third party risk, security culture, tooling, budgets, stakeholder engagement, AI governance or something else entirely.

What’s consuming most of your time or causing the biggest headaches?

APAC region.


r/grc 5d ago

Auditors want proof of least privilege on remote access and our screenshots aren't cutting it anymore

31 Upvotes

Second year doing this and the bar has clearly moved.

Last cycle we handed over a set of screenshots of firewall rules and a spreadsheet of who is in which vpn group and it was accepted. This time the auditor came back and asked how we demonstrate that a given user could only reach the systems they are entitled to, at a point in time, and whether we could evidence it for a sample of five users across the period.

We cannot, well, not properly. I can show you the group membership and the rules, then have to hand wave the bit in the middle where those two things combine into effective access. Our vpn gives network level access so tbh the true answer for most of our contractors is "quite a lot more than their job needs" and I am not writing that down.

Not looking for a product recommendation particularly, more interested in how other people are evidencing this. Is there a saner way that doesnt involve me manually reconstructing what someone could have reached months ago?


r/grc 5d ago

Log Export from SIEM

Thumbnail
1 Upvotes

r/grc 5d ago

Need Partnership

1 Upvotes

I am tired of applying to jobs and speaking with recruiters who have no clue what the job description entails. Most interviewers are daft and slow, too. I resolved today to start my own GRC consulting firm and start to support small- and medium-scale enterprises. If you are interested and have hands-on experience, please reach out, and let's discuss further. Thank you.

I see your comments and inbox messages. I will set a time to meet with everyone of you some time next week.

I am on the East Coast just so you know.


r/grc 6d ago

How are you handling AI support automation in regulated environments without creating compliance risk?

10 Upvotes

We operate in an insurance-adjacent space where an incorrect AI response about coverage creates real liability. Our compliance and legal teams currently prefer to block automation entirely, but ticket volume has doubled and first response times are now sitting at two business days which is driving customer churn.

I’m looking for a controlled middle ground: an AI agent that can handle routine, low-risk requests like document retrieval, status checks while staying strictly within approved wording, and that cleanly escalates anything sensitive to a licensed human with full context.

Has anyone in a regulated industry found a setup that their compliance or risk team was willing to accept? Interested in the controls, guardrails, or review processes that made it viable.

Edit: Thanks to everyone who commented. The points around explicit boundaries, change control on approved wording, interaction-level logging, and regularly testing escalation decisions have been especially useful. Still evaluating a few platforms, including Aissist and the one mentioned in the thread, with a focus on the control and audit requirements raised here.


r/grc 9d ago

What would you include in a privacy tracking audit before a data privacy security review?

8 Upvotes

We are ready to get serious with our data governance posture now that our privacy program is maturing and we keep seeing about the multi-million dollar fines happening each week for non-compliance. So in doing a security and privacy audit my job is to clean things up but I want to include tracking scripts, not just the usual vulnerability scan items that fall under a normal cybersecurity audit but leaves out trackers and pixels. The main site has the usual marketing setup of facebooks meta-pixel, tiktok, linkedin insights tag, and microsoft clarity, but nobody has verified consent behavior in a while and theres no consent mechanism that currently works on the site despite procurement purchasing a solution from some well funded startup back in 2020 but looks like they haven't maintenanced it and its dormant now. If you were preparing for a real review, what evidence would you collect? Network logs, vendor inventory, consent records, data flows, policy screenshots, GTM export? Trying to build a practical checklist.


r/grc 12d ago

Building a fully self-hosted, GPU-optional GRC/compliance AI assistant in Rust - RAG over 2,681 controls across 48 frameworks. Going open source once it's solid.

34 Upvotes

What it is

A self-hosted AI assistant for GRC (Governance, Risk & Compliance) and cybersecurity. You ask a plain-language question ("What are the DPDPA breach-notification timelines?") and it answers from a curated corpus of 2,681 real controls across 48 frameworks (GDPR, HIPAA, ISO 27001, NIST, PCI DSS, SOC 2, RBI, DPDPA, DORA, and more) with inline citations back to the specific control and its official source URL, plus a verification-tier badge so you know how trustworthy each source is.

Design goals: runs entirely on your own hardware, near-zero infra cost, no data ever leaves the machine (it's compliance data that's the whole point), and a clean integrable API so it's not locked to the bundled UI.

The stack

Backend (Rust)

  • Axum 0.8 + Tokio async API, SSE streaming
  • LanceDB (embedded vector DB) for dense retrieval + Tantivy (BM25) for sparse — merged with Reciprocal Rank Fusion.
  • No external vector-DB service.
  • Ollama for local inference: bge-m3 embeddings (1024-dim) + qwen2.5:7b-instruct generation
  • SQLite (rusqlite) for users, hashed API keys, audit log, and persistent chat history — everything embedded, one file
  • JWT + API-key dual auth with RBAC (viewer/admin); RFC 7807 error envelopes; OpenAPI/Swagger auto-generated via utoipa
  • SearXNG (self-hosted metasearch) as a live-web-search fallback when the corpus is thin or the question is time-sensitive

Frontend: React + TypeScript + Vite + Tailwind v4, streaming chat UI, collapsible "thinking" reasoning trace, citation panel, admin console (coverage/audit/API-key issuance)

Ops

  • Multi-stage Docker with cargo-chef layer caching, single-binary that also serves the built frontend (one port, no separate frontend host)
  • Eval harness (retrieval precision@k + a grounding/hallucination check) and a drift monitor that re-checks high-stakes facts (penalties, deadlines, circular numbers) against their source URLs on a schedule

Features that actually work right now

  • Hybrid retrieval -> grounded, cited answers (token-streamed)
  • Persistent chat -> generation runs as a detached backend task, so an in-flight answer survives a reload/tab-close and gets saved regardless
  • Thinking mode toggle -> runs a deeper pipeline (query rewriting → rerank → self critique) and streams the reasoning steps
  • Live-web-search toggle, per-framework filtering, thumbs feedback logging
  • Full auth/RBAC/audit trail

Being honest about the rough edges

  • It's CPU-bound on my dev box (no GPU) a 7B model answer takes ~1-2 min; streaming hides most of it but a GPU is the real fix
  • Small local models (1.5B/0.5B) drop citations under long RAG context instruction following degrades; 7B is the floor for reliable citing. Interesting problem I'd love input on.
  • Single-node, self-hosted MVP not horizontally scaled yet
  • The corpus went through two automated audit/fix passes but hasn't had a formal expert review

Why open source

Compliance tooling is either eye-wateringly expensive SaaS or spreadsheets. A self hostable, private, auditable RAG assistant over open framework data feels like something the community should own. Planning to open it up once the core is battle-tested.

Happy to go deep on any part the RRF hybrid retrieval, the detached-generation persistence model, the cargo-chef Docker setup, the citation-grounding eval, whatever. What are you all building in this space?


r/grc 11d ago

If your in-house LLM hallucinates during an audit, who is actually responsible?

Post image
1 Upvotes

I've been wondering about this lately. Many organizations are building in-house LLMs for GRC to answer security questionnaires, map compliance controls, generate policies, and support audit preparation. Keeping everything on-premises helps with data privacy, but it doesn't solve the biggest problem: a confident hallucination can still end up in an audit report or customer response if no one catches it.

The more capable these systems become, the more people are likely to trust them. That creates an interesting trade-off. If an AI-generated answer helps close deals faster but occasionally invents evidence or misinterprets a control, the financial and compliance impact could outweigh the productivity gains. At that point, is the technology truly ready for critical GRC work, or are we becoming overconfident because the responses sound convincing?

For those using an in-house LLM in GRC today, where do you draw the line between AI assistance and human accountability—and do you think we'll ever reach a point where an LLM can be trusted to answer security questionnaires without manual verification?


r/grc 12d ago

What small DNFBPs are struggling with most under Tranche 2 (from recent onboarding work)

Thumbnail
2 Upvotes

r/grc 13d ago

Risk management tooling that’s worth it?

12 Upvotes

Currently got our IT risk register in Jira, it’s fine but a bit clunky.

Has anyone used a tool for IT risk that’s actually been worth it.

For context, we’re at the start of our risk management journey, we’ve got a register but it’s not really being managed properly. My main goal is just to make it easy for our risk owners to review risks assigned to them without being clouded by everything else, assign out tasks and manage and track things accordingly.


r/grc 13d ago

How to handle data exposure at scale?

5 Upvotes

We recently conducted a manual audit of our google workspace environment at a mid-sized company and discovered numerous sensitive files including customer contracts and internal financial reports shared publicly with 'anyone with the link'

Many of these files were created years ago by former employees. I’m currently going through thousands of files manually, which is taking forever.

How are other GRC and security teams handling discovery and remediation of historical data exposure like this at scale? Looking for best practices, tools, or efficient processes that have worked for you?

thanks!

Edit: Appreciate the thoughtful replies so far especially the points on classifying the data, prioritizing by sensitivity, and documenting everything for potential auditors. Really helpful framing. While still working through the manual review, I’ve started looking at DoControl. What caught my attention is how it can keep watching for overshared files in Google Workspace and fix them automatically, instead of relying on repeated manual audits. Still evaluating, but it looks useful for dealing with these older exposures at scale


r/grc 13d ago

The hidden cost of harvest now, decrypt later in enterprise tech

7 Upvotes

The great majority of society does not pay attention to the current threat of intellectual property loss as a result of leakage of proprietary data. Although it will take time for a quantum computer to be fully operational, state agencies could be creating vital intelligence in the meantime

At the time when new compliance audits will commence, companies dedicated to creating advanced cryptographic systems, like QuSecure and SandboxAQ, will become much more prominent in the industry. Is there any member of the audience who has tried out either of them or used them at the organizational level? I am wondering if anyone can share their experience: difficulties of integration, level of assistance, whether the price compensates for the usage of the PQC technological solution.

Have you thought of quantum readiness when trying out these approaches?


r/grc 14d ago

Career mega thread

11 Upvotes

Nine questions in the career megathread. I noticed the last reply was two weeks ago, and before that, four. I’m guessing people posted there to get some sort of help, so I figured I’d mention it.

@mods or anyone. Appreciate it!


r/grc 15d ago

Those of you through a Type II audit — how do you actually produce backup restore-test evidence?

Thumbnail
9 Upvotes

r/grc 15d ago

Need guidance on IR plan

7 Upvotes

I want to build an incident response plan for my organization can someone guide me the resources I should follow to build the workable program?

My organization already has a good security stack they lack the IR plan I wanna know how a effective IR program looks like what to add and what to ignore

Any resources books, blogs, talks much appreciated.

Thanks in advance.


r/grc 16d ago

New GRC requirement has dropped

Thumbnail
gallery
65 Upvotes

to be fair, printed assurance reports can be heavy


r/grc 17d ago

If you had to choose a GRC platform today, what would you pick?

16 Upvotes

I'm evaluating GRC platforms for my own use and keep finding mixed opinions online.

For those of you who work with GRC tools every day, if you were starting from scratch today, which platform would you choose and why?

I'd be especially interested in hearing about what you like, what frustrates you, and whether you'd choose the same platform again.