People sitting around a desk

adesso Blog

Chief Information Security Officers (CISOs), Artificial Intelligence (AI) Officers and Data Protection Officers are increasingly facing the same challenge: they must identify, assess and interpret a growing number of internal and external requirements, and embed them effectively within the organisation.

Internally, expectations from management, business units and staff are rising. Externally, legal and regulatory requirements continue to increase. The AI Act, the Cyber Resilience Act (CRA), the second version of the Network and Information Security Directive (NIS2) and the European General Data Protection Regulation (GDPR) are prime examples of how closely compliance, security, data protection and governance requirements now overlap. These requirements are not only becoming more numerous, but also more complex, dynamic and closely intertwined.

This article deliberately does not focus primarily on efficiency in the sense of speed or cost-effectiveness. Rather, the central argument is this: without a suitable Governance, Risk & Compliance (GRC) tool, modern management systems can no longer be managed effectively. In this context, ‘effectively’ means that the defined objectives of a management system are actually achieved, monitored in a traceable manner and continuously improved.

Management systems face a structural problem

CISOs, AI officers and Data Protection Officers (DPOs) essentially have a comparable role within their respective disciplines. They must identify requirements, translate these into objectives, controls and measures, and align the organisation in such a way that these objectives are achieved. Regardless of whether the focus is on information security, data protection, business continuity or AI governance, all disciplines essentially operate within two overarching control frameworks: requirements management and risk management.

Requirement management clarifies which external and internal requirements are relevant to the organisation. Risk management assesses the resulting risks and opportunities, determines which measures are necessary, and establishes how their effectiveness can be demonstrated.

The central thesis: without a GRC tool, effective control is lacking

My thesis is: without a GRC tool, modern management systems can only achieve their objectives to a limited extent. Organisations can, to a certain extent, ‘bend’ their organisational structure and accommodate additional requirements manually. However, once a certain level of complexity is reached, Excel spreadsheets, SharePoint folders, Jira tickets and manual coordination are no longer sufficient to manage management systems effectively.

The crucial point is not that a GRC tool alone solves all problems. A tool is no substitute for a sound technical concept, a governance structure or clear lines of responsibility. Nor is it an end in itself. The desired end state should be an integrated management system in which requirements, risks, controls, measures, responsibilities and evidence are consistently linked across disciplines.

In practice, however, it is clear that such an integrated management system can hardly be operated sustainably without suitable tool support. This is because, as soon as multiple roles, departments, locations, regulatory frameworks and documentation requirements come together, a level of complexity arises that can only be managed manually at great expense and with considerable quality risks.

A good GRC tool is therefore not simply a digital repository. It is a control platform for management systems.

The AI Act: the last straw

This development is particularly evident in the example of the AI Act. The AI Act was published in 2024 and has been coming into force gradually ever since. Its overarching aim is to ensure that AI systems within the European Economic Area are developed, deployed and used under transparent, secure and trustworthy conditions. In doing so, the AI Act addresses different roles along the value chain.

A particular challenge lies in the fact that ‘trustworthiness’ is not a single, easily verifiable criterion. Trustworthy AI comprises several dimensions. Guidance is provided here by frameworks such as the NIST AI Risk Management Framework or ISO/IEC 42001, amongst others. Depending on the perspective, these include criteria such as transparency, traceability, validatability, security, data protection, robustness, resilience and human oversight. This makes it clear that AI governance is not an isolated discipline. Anyone wishing to implement the AI Act must inevitably establish interfaces with other management systems.

The AI Act is therefore not simply another set of regulations that can be implemented ‘in addition’. It acts as an amplifier for an already existing structural problem: requirements no longer arise in a clearly separate manner according to discipline, but cut across the organisation.

What needs to be done in every management system

Although management systems differ in content, they often follow a similar logic. Organisations must understand the context, analyse stakeholders and their expectations, identify requirements, assess risks and opportunities, define objectives, plan measures, assign responsibilities, allocate resources, monitor effectiveness and derive improvements.

In practice, this gives rise to recurring processes and artefacts. These include, for example, risk registers, policies, training records, incident management processes, audit programmes, management reviews and continuous improvement measures. These elements are often functionally comparable across different management systems. They pursue similar objectives but differ in terms of content, level of detail and regulatory context. An ISB, a DPO and an AI officer therefore often work on the same core processes, albeit from different specialist perspectives.

This naturally raises the question: why should these processes be established, documented and managed separately from one another?

If risks, measures, responsibilities and evidence are interconnected anyway, they should also be managed in an integrated manner. A GRC tool can provide the common foundation here. It enables different roles to work on the same objects without information having to be maintained multiple times, transferred manually or documented inconsistently.

How it is often still done in practice

In many organisations, management systems continue to be managed and documented in a decentralised manner. Information is stored in various Excel files, SharePoint folders, ticketing systems or email threads. Departmental teams submit information manually. Those responsible then transfer this information into central registers or reports. This works for a while. But it does not scale well.

As the number of requirements, roles and supporting evidence increases, typical problems arise: duplicate data storage, outdated information, inconsistencies in data formats, unclear responsibilities and contradictory statements. The situation becomes particularly critical when the same information is assessed differently in different contexts.

The result is often a management system that exists in theory but lacks sufficient operational control. Documents, registers and processes are in place, but the organisation’s actual status can only be ascertained at considerable expense. This is precisely where effectiveness becomes a problem. After all, a management system achieves its objectives not simply through the existence of documents, but by identifying risks, implementing measures and making decisions based on reliable information.

GRC tools as enablers of integrated management systems

GRC tools cannot automatically solve these challenges, but they provide the necessary structure to tackle them in a transparent manner. It is crucial that a GRC tool is not merely viewed as a filing system or ticketing tool, but as an enabler of an integrated management system.

A suitable GRC tool – such as the one from OneTrust – enables requirements to be recorded centrally and linked to risks, controls, actions and evidence. Information is collected directly from business units and stakeholders. Responsibilities can be clearly assigned. Actions are tracked, deadlines monitored and escalations made visible. At the same time, a consistent database is created for management reports, audits and regulatory evidence.

A GRC tool becomes particularly valuable when it does not view different management systems in isolation, but rather maps their interfaces. This reveals which requirements affect the same processes multiple times, which controls address several regulatory requirements simultaneously, and where genuine gaps exist.

With a modern GRC tool, the same measure can be assigned to multiple requirements and risks. This not only leads to greater efficiency but, above all, to greater effectiveness and consistency.

This is precisely where the difference lies: efficiency means getting things done faster. Effectiveness means managing the right things in a traceable and effective manner. A good GRC tool supports both – yet its true value lies in the effective management of complex management systems.

Conclusion: Excel and Jira are slowly reaching their limits.

Modern governance, risk and compliance requirements can no longer be meaningfully viewed in functional silos. Organisations must therefore think and work within integrated management systems.

A GRC tool is not a panacea and does not replace the need for in-depth engagement with requirements, risks and responsibilities. However, it is increasingly becoming the necessary foundation for effectively managing this complexity.

The choice of the right tool depends heavily on the organisation’s requirements, size, maturity and target architecture. The market offers numerous solutions ranging in price from a few thousand euros up to six-figure sums, from lean entry-level products to comprehensive enterprise platforms such as OneTrust.

This is precisely why organisations should engage with GRC tools at an early stage and in a structured manner. Not because every company needs a large platform straight away, but because Excel, SharePoint and Jira reach their limits in the long term when it comes to integrated management systems. At first glance, they appear flexible and cost-effective. In the long run, however, they become costly when inconsistencies, manual maintenance, a lack of transparency and unclear responsibilities jeopardise the effectiveness of the management system.

The crucial question is therefore no longer whether a GRC tool delivers efficiency gains. Rather, the crucial question is: Can your organisation even manage its management systems effectively without a suitable GRC tool?

Picture Rajeev Panesar

Author Rajeev Panesar

Rajeev works in the ITMC business unit at adesso SE. He is an experienced consultant in information security, IT incident management and IT service management.

His work focuses on the implementation and further development of management systems (ISMS) within the context of information security regulations. These include, amongst others, NIS2, DORA, the Minimum Requirements for Risk Management (MaRisk), the ISO 2700x series and the BSI IT-Grundschutz, for example BSI 200-x.



Our blog posts at a glance

Our tech blog invites you to dive deep into the exciting dimensions of technology. Here we offer you insights not only into our vision and expertise, but also into the latest trends, developments and ideas shaping the tech world.

Our blog is your platform for inspiring stories, informative articles and practical insights. Whether you are a tech lover, an entrepreneur looking for innovative solutions or just curious - we have something for everyone.

To the blog posts