The State of Governance, Risk, and Compliance: Innovations and Industry Shifts in Q3 2024

Governance, Risk, and Compliance (GRC) technology has rapidly transitioned from a back-office administrative function to a strategic enterprise imperative. As regulatory landscapes become increasingly complex—driven by the explosion of generative AI, heightened cybersecurity threats, and global supply chain volatility—the market for GRC software is experiencing an unprecedented surge. Recent industry data suggests the global GRC platform market is expected to grow at a compound annual growth rate (CAGR) of over 13% through 2028, as organizations seek to automate audit trails, manage third-party exposure, and navigate the fragmented regulatory frameworks governing data privacy and artificial intelligence.
The current wave of innovation, highlighted by a flurry of product launches and strategic personnel appointments, signals a move toward "agentic" GRC—systems that do not merely store data but actively perform tasks, make decisions, and enforce policies in real-time.
The Rise of Agentic AI in Risk Management
The most significant trend currently reshaping the GRC landscape is the shift toward autonomous, agentic artificial intelligence. Unlike passive AI models that require constant human prompting, these new agentic solutions are designed to operate within specific workflows, such as vendor onboarding or code deployment, to provide continuous oversight.
Drata, a leader in the trust management space, recently unveiled a standalone agentic AI solution specifically engineered for third-party risk management (TPRM). Traditionally, TPRM has been a labor-intensive, manual process involving lengthy questionnaires and static document reviews. Drata’s new platform automates the end-to-end review process, potentially reducing the time required for vendor risk assessments by weeks. This automation is critical, as many enterprises now work with thousands of vendors, making human-led assessment cycles unsustainable.
Similarly, Workiva has expanded its AI portfolio with the launch of "Agent Studio." This no-code environment allows teams in finance, accounting, and compliance to build and deploy custom AI agents. By empowering non-technical staff to create their own automated guardrails, Workiva is addressing a major bottleneck in GRC: the gap between technical developers and the compliance officers who actually understand the regulatory requirements.
Securing the AI Frontier: Archer and Monitaur
As organizations integrate generative AI into their products, they face mounting pressure from regulators to implement "AI Governance." Archer has responded to this challenge with the release of Archer Evolv AI Compliance. Designed to be deployed directly within an organization’s Amazon Web Services (AWS) environment, the tool utilizes Amazon Bedrock Guardrails. It acts as an interceptor, enforcing AI policies before a model generates a response to an employee or end-user. This effectively bridges the gap between high-level corporate AI policies and the technical execution of those policies, ensuring that every AI interaction is traceable to specific regulatory or internal obligations.
Complementing this, Monitaur has transitioned its "FlightSim" product to standalone availability. FlightSim serves as an assurance testing platform, allowing organizations to stress-test their AI systems in a sandbox environment before they are deployed to production. This "pre-flight" testing is becoming a gold standard for companies looking to avoid the reputational and financial risks associated with "hallucinating" AI or models that exhibit bias.
Supply Chain Traceability and Operational Resilience
Beyond digital risks, the physical and operational supply chain remains a primary focus for GRC providers. Achilles has introduced "Achilles Action Plans," a module that goes beyond mere risk identification to provide actionable remediation steps. By helping procurement teams pinpoint specific supplier weaknesses and prescribing corrective workflows, Achilles is shifting the paradigm from "risk monitoring" to "risk mitigation."
Similarly, TrustTrace has rolled out a new platform that enhances the accessibility of supplier data. In an era where Scope 3 emissions reporting and human rights due diligence are increasingly mandated by law—such as the EU’s Corporate Sustainability Due Diligence Directive (CSDDD)—the ability to turn disparate supplier data into decision-ready insights is a significant competitive advantage. Ecolumix, focusing on the environmental, health, and safety (EHS) vertical, has launched "IN-Site" facility risk reports, which consolidate hazardous waste, air quality, and worker safety metrics into standardized profiles. This standardization is vital for multinational corporations that must reconcile data from facilities in different jurisdictions with varying reporting requirements.
Infrastructure, DevOps, and Compliance Integration
A notable development in the integration of DevOps and GRC is the new version of the GuardRails platform from Dyna Software. By bringing native source control management into ServiceNow, the platform provides Git-like controls—such as peer reviews, automated approvals, and audit trails—directly within the enterprise service management ecosystem. This integration effectively turns the software development lifecycle (SDLC) into an auditable compliance asset.
Redgate Software has also entered the AI-augmented management space with the launch of Redgate Assistant. As organizations struggle to maintain compliance across massive, distributed database environments, the assistant leverages AI to manage, monitor, and document database development workflows, ensuring that changes to production environments do not inadvertently violate data protection standards.
Strategic Talent Shifts and Leadership
The evolution of GRC is not merely a technological challenge but a leadership one. The recent round of high-level personnel changes reflects the industry’s need for professionals who can navigate both the boardroom and the technical backend of modern software.
Casepoint, a provider of communications compliance solutions, has appointed Varun Bisht as Vice President of Governance and Compliance. This appointment underscores the growing importance of "eDiscovery" and communication monitoring in preventing internal fraud and data leaks. Simultaneously, the Association of Certified Anti-Money Laundering Specialists (ACAMS) has added Jen Calvery, the group head of financial crime risk and compliance at HSBC, to its board of directors. Her inclusion signals a strengthening of the link between global financial institutions and the regulatory standard-setting bodies.
In the legal and regulatory sphere, the return of David Dahlquist to Winston Taylor as a litigation partner and co-chair of the antitrust and competition practice highlights the increasing regulatory scrutiny on market concentration. As antitrust agencies globally increase their focus on tech giants and platform ecosystems, having specialized legal expertise at the intersection of compliance and litigation is becoming a prerequisite for large-cap firms. Finally, Eventus has tapped Jay Biondo as Head of Product and Regulatory Affairs, a role that bridges the gap between product development and the rapidly evolving requirements of global trade surveillance.
Broader Implications for the Enterprise
The rapid adoption of these tools represents a shift in corporate culture. Compliance is no longer seen as a "check-the-box" activity; it is being integrated into the flow of work. Whether it is through Copla’s new third-party risk management software, which brings procurement and legal into a unified workflow, or Zing365’s specialized learning platforms for insurance competence, the industry is moving toward a model of "continuous compliance."
However, this reliance on AI-driven and automated GRC tools brings its own set of risks. The "black box" nature of some AI governance tools remains a point of concern for regulators, who are increasingly demanding explainability in automated decision-making. Organizations will need to ensure that as they automate their risk management, they maintain a "human-in-the-loop" approach for high-stakes decisions.
As we look toward the remainder of the year, the focus will likely remain on scalability and interoperability. The companies that succeed will be those that can successfully integrate their GRC platforms into the existing "tech stack" of the enterprise, reducing friction for employees while simultaneously providing the high-fidelity audit trails required by an increasingly vigilant regulatory community. The trajectory is clear: GRC is evolving into a data-centric, AI-powered discipline that sits at the very heart of corporate operational excellence.







