July 28, 2026
AI in GRC
A rather short thought piece. Or I should get a journal.

By Tsitsi Flora
2 min read
TL;DR
In my personal life i am n AI skeptic, that is clear to all the people around me. At least I think. With everything I see online my first thought is always "Is that AI?". We have all seen the articles of people using AI for emotional comfort and advice. If that is you (I know that is me on some days) you need to stop. We all need to stop. In my professional life though, I think AI is a massive win. Not in the same way it has been taking over software engineering though, i think it is moving much slower in GRC.
AI in security Engineering
In my previous role i was doing security engineering. This role was technically heavy. One of my responsibilities was carrying out threat modelling for new features and helping developers implement controls after those sessions. My manager in this role who was very AI forward and savvy worked on developing an AI based threat modeller, then heavily encouraged us to use it. It was not that good, it made a lot of broad generalisations and it lacked important context about system components. All this to say, I could see how fast AI was moving in this field. Now you can even find AI penetration testers and manual code reviews are probably a thing of the past at this point.
What about in GRC?
GRC being a more document heavy part of information security, I did not se the same speedy adoption of AI. I'm pretty sure most people were just wondering where exactly it would fit in. It mostly seemed like a thing that can only be beneficial only in technical sectors. But I have. Few ways that i have been using AI now that i have moved into a GRC role.
- Policy templating
If there is one thing that is just annoying to do, it is coming up with a standard policy template when building an ISMS. This is very important because ISO 27001 requires a set of foundational policies and it just makes sense that they all follow the same format.
- Control mapping
If you are dealing with a product that is being sold in various regions i.e., in the EU as well as in North America, it is vital to know where the different standards overlap. SOC2 is popular in America whereas ISO 27001 is more common in the EU, although it is becoming more international. AI really helps in discovering where these 2 standards overlap, and where there are gaps.
- Automations
Now automations do not necessarily have to rely on AI, but it just makes them easier. Things that used to require manual labor, such as following up on audit issues, keeping track of risks, document review cycles etc., can be done so much more smoothly with AI. This is such a game changer because much of GRC work is collaborations with people and engaging different teams to implement controls and processes. AI makes all that easier.
Anyways these are the main ways i have been using AI so far. If i discover any more, I will come back and update here.
Till next time