Traditionally, an ISMS is built as a project and, in organisational terms, ends with the certificate – yet the real work only begins afterwards. ISO/IEC 27001:2022 explicitly requires the management system to be maintained and continually improved; the certificate is valid within a three-year cycle with at least annual surveillance audits (ISO/IEC 17021-1). NIS2, too, is designed as a permanent obligation: risk management measures must be implemented, monitored and reviewed for effectiveness – binding in Germany since the German NIS2 implementation act (NIS-2-Umsetzungsgesetz) entered into force in December 2025. Managed GRC means running these recurring tasks not as ad-hoc engagements but as an ongoing service with a defined scope, cadence and reporting.
GRC as a Service: Compliance as an Operating Model
How managed GRC models organise the ongoing operation of ISMS, risk management and compliance evidence – from the service components and meaningful metrics to the limits of transferring responsibility.
Certifications under ISO/IEC 27001 and regulations such as NIS2 or DORA do not call for one-off project deliverables but for management processes that work on a permanent basis: risks must be reassessed regularly, measures tracked, audits performed and evidence kept up to date. Many organisations – especially small and mid-sized ones – lack the staff for this: according to Bitkom, around 109,000 IT positions in Germany were unfilled in 2025. GRC as a Service (also known as managed GRC) shifts the ongoing operation of these governance, risk and compliance processes to an external provider that works with fixed responsibilities, deadlines and metrics. This article puts the concept into perspective: service components, benefits and limits, meaningful metrics and the tool landscape.
The Essentials at a Glance
Six topic blocks — tap to expand.
Service components of a managed GRC model
From the ISMS core to platform operation — tap a component. The exact scope varies considerably.
- Document control, tracking of measures, preparation of the management review and maintenance of evidence form the core of the service.
- The provider maintains the risk register, organises periodic reassessments and keeps the risk treatment plans on track.
- An internal audit programme in line with clause 9.2 of ISO/IEC 27001 is part of the model, as are metrics and reporting to the management level.
- The provider frequently also operates the GRC platform, including data maintenance and framework updates.
- External officer roles — such as information security officer or data protection officer — and audit support are offered on top.
- The scope of services, the cadence and the client's duties to cooperate should be precisely defined in the contract.
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
Richtlinie (EU) 2022/2555 (NIS2)
Art. 20 anchors the approval, oversight and accountability of management bodies; Art. 21(2) lists the minimum measures, including the assessment of effectiveness (point (f)).
ISO/IEC 27001:2022 (inkl. Amd 1:2024)
Requirements for information security management systems; clause 9 requires monitoring and measurement, internal audits and management review; Annex A comprises 93 controls.
ISO/IEC 27004:2016 – Monitoring, measurement, analysis and evaluation
Guidance on measuring the performance and effectiveness of an ISMS in accordance with ISO/IEC 27001 clause 9.1; a revision is currently available only as a DIS draft.
NIST SP 800-55 Vol. 1 & 2: Measurement Guide for Information Security
Two-volume guide to selecting security metrics and building a measurement programme; supersedes Revision 1 from 2008.
Der Arbeitsmarkt für IT-Fachkräfte
Representative survey of 855 companies: around 109,000 unfilled IT positions in Germany, 85 percent report a shortage of skilled professionals, 79 percent expect it to worsen.
ISO/IEC 17021-1:2015
Requirements for bodies providing audit and certification of management systems; defines the three-year certification cycle with at least annual surveillance audits.
Related Services
Build GRC operations in-house or outsource them?
In a no-obligation initial consultation, we will jointly assess which operating model fits your organisation – from selective support to a fully managed service.