Skip to content
    July 24, 2026| Top Floor Team| 9 min read

    Is a GRC Platform Enough, or Do You Need People Too?

    No, a GRC platform is not enough on its own, and yes, you still need people. Not necessarily employees (fractional help covers most companies under a few hundred headcount), but a human who owns the judgment calls the software cannot make. A platform can tell you a policy document was uploaded on March 4th. It cannot tell you the policy contradicts how your team actually offboards contractors, and it will not be in the room when the auditor asks why three terminated contractors still had repository access in month seven of your audit period. The real question is not platform or people. It is which parts of the program each one should own.

    We wrote a tool-level companion to this article covering Vanta, Drata, and whether you still need a consultant. This piece zooms out to the program level: what does the work of compliance consist of, and how much of it can software absorb?

    Key takeaways

    • A GRC platform is not enough on its own, and you still need people, though not necessarily employees.
    • Platforms genuinely win at evidence collection, continuous monitoring of technical controls, and orchestration. Buy one; anyone telling you to run compliance out of a shared drive is selling consulting hours.
    • A green check means evidence was collected. The auditor asks a different question: does this evidence demonstrate the control operated effectively, for the whole period, as designed?
    • Six things stay human: the risk assessment, scoping, the system description, exception handling and negotiation, the auditor interface, and the judgment calls that arrive weekly.
    • The test: if the platform went dark tomorrow, could someone in your company explain what your controls are, why they are scoped that way, and what happened when one failed? If not, you have a subscription with a dashboard.

    What platforms genuinely do well

    Let's concede the strengths honestly, because they're real and we recommend a platform to nearly every client we work with.

    Evidence collection is the big one. A platform with API integrations into AWS, GitHub, Okta, and your MDM pulls configuration evidence continuously instead of forcing someone to take 200 screenshots the week before fieldwork. That alone eliminates the single most miserable part of a first audit. Continuous monitoring of technical controls is the second win: if someone disables MFA enforcement or spins up an unencrypted database, you find out from an alert in hours rather than from your auditor in month eleven.

    Platforms are also good at orchestration. Task assignments, policy acknowledgment tracking, vendor questionnaire workflows, a single place where the auditor can pull evidence without forty email threads. Compared to running SOC 2 out of a shared drive and a spreadsheet, the difference is dramatic, and anyone who tells you otherwise is selling consulting hours.

    So the platform earns its subscription. The problem starts when the dashboard becomes the definition of done.

    Tracking controls is not the same as being compliant

    Here is the distinction that the sales demo glosses over. A platform shows a green check when evidence was collected. Your auditor asks a different question: does this evidence demonstrate the control operated effectively, for the whole period, as designed?

    Take quarterly access reviews, a control every framework requires in some form. The platform's view: a review task was completed each quarter and a spreadsheet was attached. Green check, four for four. The auditor's view: who performed the review, and did that person have the authority and context to judge whether access was appropriate? Were any findings acted on? Where are the revocation tickets?

    We've seen the failure mode more than once. A company terminates a dozen-plus people in a year, uploads four access review spreadsheets showing zero revocations, and considers the control satisfied. To an auditor, that evidence doesn't demonstrate the control worked. It documents that the control didn't operate, in writing, with timestamps. The platform faithfully collected proof of the deficiency.

    The compliance firm 360 Advanced puts it well: "A GRC platform can show that controls exist, that evidence has been uploaded, and that tasks are complete. What it cannot do is determine whether those controls will stand up under audit." The platform measures whether artifacts exist. Compliance is whether your organization actually behaves the way those artifacts claim, and no integration can measure that.

    The work that stays human

    When we map a compliance program, there's a residue of work that no platform performs, and it happens to be the work that determines whether your audit goes smoothly. As of August 2026, with all the AI features the platforms have shipped, this list has barely shrunk.

    Risk assessment

    Every platform ships a risk register template, and importing it wholesale is one of the most common pieces of auditor pushback we see. SOC 2's CC3 criteria expect a risk assessment grounded in your actual business: your architecture, your customer commitments, your threat model. Deciding that vendor concentration in a single cloud region matters more to you than laptop theft is a judgment about your company. Software has no opinion.

    Scoping

    Which systems, products, and entities are in scope? Get this wrong in either direction and you pay. Scope too broadly and you're collecting evidence for systems that don't touch customer data. Scope too narrowly and the auditor expands it mid-engagement, or worse, a customer's security team notices the product they buy isn't in your report. Scoping is a negotiation between what's defensible and what's achievable, and it happens before the platform is even configured.

    The system description

    Section 3 of a SOC 2 report is a multi-page narrative describing your infrastructure, data flows, and control environment. It's the part customers actually read. Platforms generate a skeleton at best. Someone who understands both your architecture and what assertions an auditor will test has to write it, because every sentence in it becomes something you're attesting to.

    Exception handling and negotiation

    A control will fail during your period. It happens in most first audits we see, and plenty of later ones. What happens next is pure judgment: remediate and document a management response, argue for a compensating control, or accept a qualified opinion. Whether an exception becomes a footnote or a deal-killer depends on how it's framed and negotiated, and auditors negotiate with people, not dashboards. We covered how much room there is to maneuver in can you fail a SOC 2 audit.

    Auditor interface

    Fielding follow-up requests, explaining an architectural decision from two years ago, pushing back when an evidence request overreaches the scope. An experienced hand on your side of the table shortens fieldwork by weeks. It's also worth choosing the other side of the table carefully; we wrote up the questions to ask a SOC 2 auditor for exactly that reason.

    Ongoing judgment calls

    Is this vendor's questionnaire response acceptable? Was that S3 misconfiguration a reportable incident or a near miss? Does the new EU customer change your data residency commitments? These decisions arrive weekly, and someone accountable has to make them. That's the accountability question we dug into in who owns compliance.

    The timeline nobody quotes you

    The demo implies you'll be audit-ready in weeks, and the vendors say so directly: ZenGRC advertises getting you "up and running within weeks, not months or years". For the integration setup, that's roughly true. For the program, it isn't. In our experience with mid-market companies the program takes months even with a platform doing the evidence collection, and we are deliberately not attaching a market-wide figure to that, because the published deployment timelines all measure onboarding rather than the program.

    Neither number is wrong. Connecting APIs takes days. What takes months is everything the connections can't do: agreeing on scope, writing policies people will actually follow, running controls long enough to generate a period of evidence, and fixing the gaps that monitoring surfaces. The bottleneck was never data collection. It's decisions, and decisions have owners, and owners are people.

    What the split looks like in practice

    The ratio of tooling to people shifts with company stage, but the shape is consistent.

    A company under about 50 people pursuing one framework can usually run on a platform plus a few hours a week of experienced oversight, either an internal owner who has been through audits before or a fractional resource. During the first audit cycle, expect the human side to spike: scoping, policy authoring, the system description, and auditor management all land in a few months.

    Growth-stage companies juggling SOC 2 plus ISO 27001 or HIPAA typically need a standing fractional arrangement. This is the gap compliance as a service exists to fill: the platform stays, and the judgment work gets a consistent owner without a full-time hire. When security strategy beyond compliance enters the picture (board reporting, security roadmap, customer-facing security posture), that's vCISO territory.

    Past a few hundred employees or three-plus frameworks, you want dedicated internal staff, and the platform becomes their force multiplier rather than their replacement.

    A caveat against our own interest: if you have a strong internal owner, a stable scope, and a second-year audit, you may not need us or anyone like us. Renewal-year audits with no material changes are the platform's best case, and paying consulting rates to babysit green checkmarks is a waste of your money.

    The test we'd apply

    Ask one question of your program: if the platform went dark tomorrow, could someone in your company explain to an auditor what your controls are, why they're scoped the way they are, and what happened when one of them failed? If yes, the platform is doing its proper job, amplifying a program that people own. If no, you don't have a compliance program. You have a subscription with a dashboard, and the gap between those two things is exactly what an auditor is paid to find.

    Frequently asked questions

    Do platform-only success stories exist?

    Yes, and they're worth examining closely. The companies that get through a SOC 2 examination with no outside help almost always have a founder or senior engineer who has been through audits at a previous company. The platform replaced project management and screenshot collection, not judgment; the judgment was already in the building. If nobody on your team has sat across from an auditor before, you're not in that reference class, and your first exception negotiation is a bad time to discover it.

    What ratio of tooling to people actually works?

    There's no universal number, but steady state for a single-framework company under 200 people usually means a platform subscription plus a few hours per week of experienced human time, weighted heavily toward people in the first audit year and shifting toward tooling in renewal years. The red flag is a budget where the people line is zero. If everything is allocated to software, the plan assumes the software makes judgment calls, and it doesn't.

    Can I start with just a platform and add people later?

    You can, and many companies do, but front-load the human input at two points: scoping and risk assessment. Those decisions shape everything downstream, and redoing them after six months of evidence collection means throwing away much of that evidence. A few advisory hours at kickoff is the cheapest insurance in compliance.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.