Book an Appointment

GRC as a Service: Compliance as an Operating Model

How managed GRC models organise the ongoing operation of ISMS, risk management and compliance evidence – from the service components and meaningful metrics to the limits of transferring responsibility.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

~109,000unfilled IT positions in Germany in 2025 — according to Bitkom
85%of companies surveyed report a shortage of IT professionals
3 yearscertification cycle with at least annual surveillance audits
3 categoriesin the GRC tool landscape — broadly distinguished

Certifications under ISO/IEC 27001 and regulations such as NIS2 or DORA do not call for one-off project deliverables but for management processes that work on a permanent basis: risks must be reassessed regularly, measures tracked, audits performed and evidence kept up to date. Many organisations – especially small and mid-sized ones – lack the staff for this: according to Bitkom, around 109,000 IT positions in Germany were unfilled in 2025. GRC as a Service (also known as managed GRC) shifts the ongoing operation of these governance, risk and compliance processes to an external provider that works with fixed responsibilities, deadlines and metrics. This article puts the concept into perspective: service components, benefits and limits, meaningful metrics and the tool landscape.

The Essentials at a Glance

Six topic blocks — tap to expand.

Service components of a managed GRC model

From the ISMS core to platform operation — tap a component. The exact scope varies considerably.

Core
  • Document control, tracking of measures, preparation of the management review and maintenance of evidence form the core of the service.
Document controlTracking of measuresManagement reviewEvidence

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Amtsblatt der EU / EUR-Lex · 2022

Richtlinie (EU) 2022/2555 (NIS2)

Art. 20 anchors the approval, oversight and accountability of management bodies; Art. 21(2) lists the minimum measures, including the assessment of effectiveness (point (f)).

ISO/IEC · 2022

ISO/IEC 27001:2022 (inkl. Amd 1:2024)

Requirements for information security management systems; clause 9 requires monitoring and measurement, internal audits and management review; Annex A comprises 93 controls.

ISO/IEC · 2016

ISO/IEC 27004:2016 – Monitoring, measurement, analysis and evaluation

Guidance on measuring the performance and effectiveness of an ISMS in accordance with ISO/IEC 27001 clause 9.1; a revision is currently available only as a DIS draft.

NIST · 2024

NIST SP 800-55 Vol. 1 & 2: Measurement Guide for Information Security

Two-volume guide to selecting security metrics and building a measurement programme; supersedes Revision 1 from 2008.

Bitkom e. V. · 2025

Der Arbeitsmarkt für IT-Fachkräfte

Representative survey of 855 companies: around 109,000 unfilled IT positions in Germany, 85 percent report a shortage of skilled professionals, 79 percent expect it to worsen.

ISO/IEC · 2015

ISO/IEC 17021-1:2015

Requirements for bodies providing audit and certification of management systems; defines the three-year certification cycle with at least annual surveillance audits.

Build GRC operations in-house or outsource them?

In a no-obligation initial consultation, we will jointly assess which operating model fits your organisation – from selective support to a fully managed service.