modern auditing

Glossary

Agent-native GRC

Also known as: agent-native governance, risk and compliance

Governance, risk and compliance software designed from the data model up so that software agents can do the work, with human approval built into the record rather than bolted on afterwards.

The distinction that matters is between agent-native and agent-added. Nearly every established GRC platform has now added a chat panel. That panel can summarise a page and draft text, because those are things a language model can do to a document. What it cannot do is execute a control test, because the underlying data model was built to store documents for humans, not to expose structured work to a machine.

Agent-native means the opposite starting point: controls, tests, populations, exceptions and approvals exist as structured records with stable identifiers, so an agent can be handed “perform this test” rather than “write about this test”. It also means the permission model treats an agent as a first-class actor with a scope, so its actions can be constrained and logged the way a person’s are.

The practical test is simple, and it survives any demo. Ask whether an agent can complete a unit of work end-to-end and leave a record an auditor would accept — the control it tested, the population it pulled, the exceptions it found, the human who approved the conclusion. If the answer is “it can help you write that up”, the product is agent-added.


Related


Part of the Modern Auditing glossary. See also the maturity model and theartifact library.