How to Choose a GRC Platform: An Honest Buyer’s Checklist
We sell one of these, so read this with that in mind. What follows is the list of questions we would want asked of us — including the ones where our answer is “no”. A checklist that only flatters the vendor who wrote it is worth nothing.
GRC platforms demo extremely well. They are dashboards, and dashboards are designed to look convincing in thirty minutes. The difference between a good purchase and an expensive filing cabinet shows up in month four, and almost all of it is predictable from questions you can ask before signing.
First, decide what you are actually buying
Three different products get sold under the same name, and buying the wrong category is the most expensive mistake available:
| Category | Built for | Wrong if |
|---|---|---|
| Compliance automation | Getting and keeping certifications. Evidence collection, control mapping, audit readiness. | You need enterprise risk quantification, policy lifecycle across 5,000 staff, or regulatory change management. |
| Enterprise GRC | Large regulated organisations. Deep risk taxonomy, workflow engines, heavy configuration. | You are under 300 people. Implementation alone will outlast your patience and your budget. |
| Point tools | One job — vendor risk, or policy management, or questionnaires. | You will need three of them, and they will not share a control set. |
The pricing questions
Ask all of these in writing, before the demo if you can. The answers move total cost more than the headline figure does.
- Is pricing per framework? Model the cost of the framework you need now plus the one a customer will ask for next year. This is where the real money is, and where first-year quotes mislead most.
- What counts as a seat? Some platforms charge full price for auditors and read-only reviewers who will never edit anything.
- Are integrations included or an add-on? Automated evidence collection is most of the value. Priced separately, the maths changes entirely.
- What is the renewal uplift? Ask for the cap in writing. Uncapped renewals after a cheap first year are a standard play in this market.
- Is there an implementation or onboarding fee, and is it mandatory?
- Is the price published anywhere? A vendor who will not put pricing on their website is telling you the number depends on what they think you will pay.
The integration questions
Every vendor claims automated evidence collection. The claims differ enormously in substance. Push past the logo wall:
- Which of MY tools, specifically? Name your cloud, identity provider, endpoint agent, scanner, code host and HR system. A long logo grid is not an answer.
- What does each integration actually check? "AWS integration" can mean thirty real configuration checks or one API call that confirms the account exists.
- How often does it refresh, and what happens when a check fails — does it open something a human must act on, or silently record a red tile?
- Can I see a real evidence artefact from a live tenant during the demo? Not a screenshot in a slide.
- What happens to evidence that cannot be automated? There will be plenty — board minutes, training records, physical security. How does it get in and stay current?
The questions vendors hope you skip
Ask every vendor to state plainly what they are not certified for. A surprising number of compliance platforms are less certified than the customers they sell to, and a few describe themselves as “ISO 27001 aligned” in a way designed to be misread as certified. Ask for the certificate number and the accreditation body. If the answer is “in progress”, that is fine — but it should be said without prompting.
- How do I get my data out, in what format, and how long does it take? Test this before you need it. Evidence libraries are the definition of lock-in.
- Where is Customer Data stored, and where is it processed? Those are different questions and the second one has the longer answer.
- Who are your sub-processors, and is the list published? If you have to email to get it, that tells you something.
- What is your actual support commitment — response targets in hours, and are they business hours or round the clock? Get this from the SLA, not the sales deck.
- Is single sign-on included on the plan I am buying, or is it on a higher tier? SSO is very commonly gated. Find out before it becomes a security-review problem.
- What breaks if I want to add a framework you do not yet support?
The trial that tells you something
A guided demo tells you the product exists. If you want to know whether it works for you, do this instead: connect one real system and take one real control end to end.
Pick access review — the most-sampled control in most audits. Connect your actual identity provider. See what the platform pulls, how the review is presented, what an auditor would receive at the end, and how much of it you had to type. Half an hour of that is worth four demos.
If a vendor will not let you connect a real system during evaluation, that is itself the answer.
Signals that a platform will not survive month four
- The demo tenant is always the same fictional company with perfect data. Ask to see one mid-implementation and watch the reaction.
- Framework coverage is advertised as a count with no way to see the list. Ask which version of each standard, and when it was last updated.
- Everything is "AI-powered" but nobody will say what the AI does, or what happens when it is wrong.
- The reference customers are all much larger or much smaller than you.
- Pricing requires a call. For a product sold to companies of 30 to 250 people, that is a choice, not a necessity.
A proof-of-concept script you can reuse
Run the same exercise with every shortlisted vendor, in the same order, and score it. Two hours per vendor, and it eliminates the demo-quality bias almost entirely.
| Step | What you are measuring |
|---|---|
| 1. Connect your identity provider yourself | How long it takes, how much hand-holding it needs, and whether it works without a support ticket. |
| 2. Open the access-review workflow | Does it show real users and real entitlements, or a summary count? Can you see who has privileged access right now? |
| 3. Complete one review and export the evidence | Would an auditor accept the artefact? Does it record who reviewed, when, and what they decided? |
| 4. Add a framework you do not yet hold | Does existing evidence map across automatically, or does the control set start empty? |
| 5. Break something deliberately | Remove MFA from a test account. Does the platform notice, when, and does it raise something actionable? |
| 6. Export everything | Ask for your data back. Format, completeness, and how long it took to arrive. |
Step five is the one that separates products. A platform that tells you a control has drifted, promptly and with enough context to act, is doing the job. One that renders a red tile you notice next quarter is a dashboard.
Contract terms worth negotiating
Most buyers negotiate price and sign everything else. The terms below cost nothing to ask for at signature and are effectively impossible to get later.
- A renewal uplift cap. Name a percentage. Uncapped renewal after a discounted first year is the most common way this category gets expensive.
- A data-export right on termination, with a format and a deadline. "Reasonable assistance" is not a commitment.
- Price protection when you add seats mid-term, so growth does not reset your rate.
- A service credit or exit right if a promised integration does not ship. Roadmap promises made in a sales cycle should appear in the contract or be treated as decoration.
- Notice of sub-processor changes, with a right to object. You are buying a system that holds your audit evidence.
- Clarity on what happens to your evidence after termination — retention period, deletion confirmation, and whether backups are covered.
Reference calls that produce information
Vendor-supplied references are selected, so do not ask them whether they are happy. Ask questions whose answers cannot be pre-briefed:
- "What took longest during implementation, and was that the vendor or you?"
- "Which integration disappointed you?" — every deployment has one. A reference who names none is not being candid.
- "What do you still do in a spreadsheet?"
- "How did your auditor react to the evidence exports?" This is the question that matters most and is almost never asked.
- "What did renewal look like?"
- "If you were starting again, would you buy the same tier?"
Better still, find a customer the vendor did not introduce you to. A post on LinkedIn asking who uses the platform will usually surface two, and they will tell you things the reference list will not.
If you are switching from an incumbent
Migration is where this category hides its real cost, and the work is mostly yours rather than the new vendor’s.
Export your existing evidence before you give notice, not after — access to historical evidence sometimes ends with the subscription, and an auditor asking for last year’s access reviews will not accept “we changed platforms”. Keep the old evidence in your own storage regardless of what the new platform imports.
Expect an overlap period of one to three months and budget for both subscriptions during it. Migrate before an audit window rather than during one, and keep your control identifiers stable across the move if you can — remapping control references mid-cycle is how evidence gets orphaned.
Where we land on our own checklist
In fairness, our answers: all 71 frameworks are included on every plan and the prices are published on the site. Evidence collects from 23 integrations. Data is stored in the European Union by default, with some processing outside it — every sub-processor, its region and its transfer mechanism is listed in our DPA. Our support targets are business-hours, not round the clock, and the SLA says so. Single sign-on is on Scale and Enterprise, not on the entry plan. We are not ISO 27001 certified — our controls are aligned to it and we are targeting certification in Q3 2027.
Every vendor you evaluate should be willing to write a paragraph like that one. Ask them to.
Compare us against the checklist
Pricing is on the site. The framework list is on the site. So is the sub-processor list and the SLA. Nothing here needs a call first.
See the Comparison