Book an Appointment

GRC as a Service: Compliance as an Operating Model

How managed GRC models organise the ongoing operation of ISMS, risk management and compliance evidence – from the service components and meaningful metrics to the limits of transferring responsibility.

Certifications under ISO/IEC 27001 and regulations such as NIS2 or DORA do not call for one-off project deliverables but for management processes that work on a permanent basis: risks must be reassessed regularly, measures tracked, audits performed and evidence kept up to date. Many organisations – especially small and mid-sized ones – lack the staff for this: according to Bitkom, around 109,000 IT positions in Germany were unfilled in 2025. GRC as a Service (also known as managed GRC) shifts the ongoing operation of these governance, risk and compliance processes to an external provider that works with fixed responsibilities, deadlines and metrics. This article puts the concept into perspective: service components, benefits and limits, meaningful metrics and the tool landscape.

The Essentials at a Glance

01

Continuous compliance instead of a one-off project

Traditionally, an ISMS is built as a project and, in organisational terms, ends with the certificate – yet the real work only begins afterwards. ISO/IEC 27001:2022 explicitly requires the management system to be maintained and continually improved; the certificate is valid within a three-year cycle with at least annual surveillance audits (ISO/IEC 17021-1). NIS2, too, is designed as a permanent obligation: risk management measures must be implemented, monitored and reviewed for effectiveness – binding in Germany since the German NIS2 implementation act (NIS-2-Umsetzungsgesetz) entered into force in December 2025. Managed GRC means running these recurring tasks not as ad-hoc engagements but as an ongoing service with a defined scope, cadence and reporting.

02

Typical service components of a managed GRC model

At the core is ISMS operation: document control, tracking of measures, preparation of the management review and maintenance of evidence. Added to this are ongoing risk management (risk register, periodic reassessments, risk treatment plans), an internal audit programme in line with clause 9.2 of ISO/IEC 27001, plus metrics and reporting to the management level. The provider frequently also operates the GRC platform, including data maintenance and framework updates; external officer roles (such as information security officer or data protection officer) and audit support are offered on top. The exact scope varies considerably – the scope of services, the cadence and the client's duties to cooperate should be precisely defined in the contract.

03

Why SMEs benefit in particular

According to Bitkom's study on the IT labour market, around 109,000 IT positions in Germany were unfilled in 2025; 85 percent of the companies surveyed report a shortage of IT professionals, and 79 percent expect the situation to worsen further. For small and medium-sized enterprises, a dedicated full-time GRC role is often neither economically viable nor fillable on the market – especially since the required knowledge spans several specialist areas, from interpreting standards and regulation to audit practice and tool expertise. A managed service pools these competencies in shared capacity, brings deputisation arrangements and experience from many audit cycles, and reduces the internal effort to a defined interface role. Decisions, resource approvals and the involvement of the business units remain internal, however – no model works entirely without in-house capacity.

04

Distinction: traditional consulting vs. operational responsibility

Traditional consulting is limited in time and delivers recommendations, concepts and documents – implementation and upkeep remain with the client. In the managed model, by contrast, the provider assumes responsibility for the outcomes of defined operational processes: audits take place, risk assessments are up to date, reports are delivered. Two limits are essential: first, overall accountability cannot be delegated – under Art. 20 of the NIS2 Directive, management bodies must “approve” the risk management measures and “oversee their implementation”, and they can be held liable for infringements; likewise, an ISO 27001 certificate is issued to the organisation, not to the provider. Second, ISO/IEC 27001 requires objective and impartial internal audits – if the same provider operates the ISMS, this calls for a separation at the personnel or organisational level.

05

Meaningful metrics for GRC operations

The obligation to measure is anchored in the standards: clause 9.1 of ISO/IEC 27001 requires monitoring and evaluation of security performance and ISMS effectiveness, and Art. 21(2)(f) of NIS2 demands policies and procedures to assess the effectiveness of risk management measures. Proven operational metrics include the implementation rate of measures from the risk treatment plan, overdue measures and audit findings including time to remediation, the age of risk assessments, the currency of controlled documents, training and awareness rates, and detection and remediation times for security incidents. Methodological guidance is provided by ISO/IEC 27004:2016 (a revision is currently available only as a draft) and NIST SP 800-55 (2024). What matters is selection rather than volume: a small number of decision-relevant metrics with a defined data source, target value and report recipient.

06

The GRC tool landscape at a glance

Broadly, three categories can be distinguished: integrated GRC platforms that combine several disciplines such as risk, compliance, internal audit and policy management in a single data model; specialised ISMS tools with prebuilt framework catalogues and measure tracking; and compliance automation solutions that collect evidence automatically via interfaces to cloud, identity and endpoint systems. Alongside these, office-based in-house solutions remain widespread but hit their limits when it comes to versioning, traceability and multi-user operation. In the managed model, tool operation is part of the service scope – for instance catalogue updates for new versions of standards, mapping several frameworks onto each other and ongoing data maintenance. A tool does not replace an operating model, however: without defined processes and owners it merely depicts the standstill more clearly; in addition, the exportability of the data should be contractually secured for a later change of provider.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Amtsblatt der EU / EUR-Lex · 2022

Richtlinie (EU) 2022/2555 (NIS2)

Art. 20 anchors the approval, oversight and accountability of management bodies; Art. 21(2) lists the minimum measures, including the assessment of effectiveness (point (f)).

ISO/IEC · 2022

ISO/IEC 27001:2022 (inkl. Amd 1:2024)

Requirements for information security management systems; clause 9 requires monitoring and measurement, internal audits and management review; Annex A comprises 93 controls.

ISO/IEC · 2016

ISO/IEC 27004:2016 – Monitoring, measurement, analysis and evaluation

Guidance on measuring the performance and effectiveness of an ISMS in accordance with ISO/IEC 27001 clause 9.1; a revision is currently available only as a DIS draft.

NIST · 2024

NIST SP 800-55 Vol. 1 & 2: Measurement Guide for Information Security

Two-volume guide to selecting security metrics and building a measurement programme; supersedes Revision 1 from 2008.

Bitkom e. V. · 2025

Der Arbeitsmarkt für IT-Fachkräfte

Representative survey of 855 companies: around 109,000 unfilled IT positions in Germany, 85 percent report a shortage of skilled professionals, 79 percent expect it to worsen.

ISO/IEC · 2015

ISO/IEC 17021-1:2015

Requirements for bodies providing audit and certification of management systems; defines the three-year certification cycle with at least annual surveillance audits.

Build GRC operations in-house or outsource them?

In a no-obligation initial consultation, we will jointly assess which operating model fits your organisation – from selective support to a fully managed service.