adesso Blog

CISOs, AI officers and data protection officers are increasingly facing the same challenge: they must identify, assess and translate a growing number of internal and external requirements, and effectively embed them within the organisation.

Internally, the expectations of management, business units and the workforce are rising. Externally, legal and regulatory requirements continue to increase. The AI Act, the Cyber Resilience Act, NIS2 and the GDPR are prime examples of how closely compliance, security, data protection and governance requirements now overlap. These requirements are not only becoming more numerous, but also more complex, dynamic and increasingly intertwined.

This blog post deliberately does not focus primarily on efficiency in terms of speed or cost-effectiveness. Rather, the central argument is this: without a suitable GRC (Governance, Risk & Compliance) tool, modern management systems can no longer be managed effectively. In this context, ‘effectively’ means that the defined objectives of a management system are actually achieved, monitored in a traceable manner and continuously improved.

Management systems face a structural problem

CISOs, AI officers and DSBs essentially have a comparable role within their respective disciplines. They must identify requirements, translate these into objectives, controls and measures, and align the organisation so that these objectives are achieved. Regardless of whether the focus is on information security, data protection, business continuity or AI governance, all disciplines essentially operate within two overarching control frameworks: requirements management and risk management.

Requirements management clarifies which legal, regulatory, contractual, normative and internal requirements are relevant to the organisation. Risk management assesses the resulting risks and opportunities, determines which measures are necessary, and establishes how their effectiveness can be demonstrated.

In practice, of course, this distinction is not always clear-cut. Requirements influence risks; risks lead to measures; measures generate obligations to provide evidence; and this evidence, in turn, feeds into audits, management reviews and improvement measures. This is precisely where the problem begins: modern management systems are no longer static collections of documents. They are dynamic control systems based on up-to-date information, clear responsibilities and robust evidence.

The central thesis: without a GRC tool, effective control is lacking

My thesis is this: without a GRC tool, modern management systems can only achieve their objectives to a limited extent. Organisations can, to a certain extent, ‘adapt’ their structures and manually accommodate additional requirements. However, once a certain level of complexity is reached, Excel spreadsheets, SharePoint repositories, Jira tickets and manual reconciliations are no longer sufficient to effectively manage management systems.

The crucial point is not that a GRC tool alone solves all problems. A tool is no substitute for a sound conceptual framework, a governance structure or clear lines of responsibility. Nor is it an end in itself. The actual target state is an integrated management system in which requirements, risks, controls, measures, responsibilities and evidence are consistently linked.

In practice, however, it is clear that such an integrated management system can hardly be operated sustainably without suitable tool support. This is because as soon as multiple roles, departments, locations, regulatory frameworks and evidence requirements come together, a level of complexity arises that can only be managed manually at great expense and with significant quality risks.

A good GRC tool is therefore not simply a digital repository. It is a control platform for management systems. It helps to structure requirements, assign responsibilities, assess risks, track measures, collect evidence and report on status in a manner tailored to the relevant stakeholders.

The AI Act: the last straw

This development is particularly evident in the example of the AI Act. The AI Act was published in 2024 and has been coming into force in stages ever since. Its overarching aim is to ensure that AI systems within the European Economic Area are developed, deployed and used under transparent, secure and trustworthy conditions.

In doing so, the AI Act addresses different roles along the value chain, such as providers, operators, importers, distributors and product manufacturers. For organisations, this means they must first understand which AI systems they actually use or develop, what regulatory role they play and what obligations arise from this.

A particular challenge lies in the fact that ‘trustworthiness’ is not a single, easily verifiable criterion. Trustworthy AI comprises several dimensions. Guidance is provided here by frameworks such as the NIST AI Risk Management Framework or ISO/IEC 42001. Depending on the perspective, these include criteria such as transparency, traceability, validatability, security, data protection, robustness, resilience and human oversight.

This makes it clear that AI governance is not an isolated discipline. Anyone wishing to implement the AI Act must inevitably establish interfaces with other management systems. Data protection requirements relate to the Data Protection Management System (DSMS). Security requirements relate to the Information Security Management System (ISMS). Requirements for reliability and continuity relate to the Business Continuity Management System (BCMS). Requirements concerning suppliers, documentation and evidence, in turn, relate to overarching compliance and risk management.

The AI Act is therefore not simply another set of regulations that can be implemented ‘in addition’ to existing frameworks. It acts as an amplifier for an already existing structural problem: requirements no longer arise neatly separated by discipline, but cut across the organisation. This is precisely why it is not enough to maintain a separate AI register in Excel. Organisations need integrated structures in which AI systems, risks, controls, data protection implications, security measures, supplier information and evidence are all linked together.

What needs to be done in every management system

Although management systems differ in terms of content, they often follow a similar logic. Organisations must understand the context, analyse stakeholders and their expectations, identify requirements, assess risks and opportunities, define objectives, plan measures, assign responsibilities, allocate resources, monitor effectiveness and derive improvements.

In practice, this gives rise to recurring processes and artefacts. These include, for example, risk registers, control catalogues, action plans, guidelines, training records, incident management processes, audit programmes, management reviews and continuous improvement measures.

These elements are often functionally comparable across different management systems. They pursue similar objectives but differ in terms of content, level of detail and regulatory context. An ISB, a DPO and an AI Officer therefore frequently work on the same core processes, albeit from different specialist perspectives.

This naturally raises the question: why should these processes be established, documented and managed separately from one another?

If risks, measures, responsibilities and evidence are interconnected anyway, they should also be managed in an integrated manner. A GRC tool can provide the common foundation here. It enables different roles to work on the same objects without the need to maintain information multiple times, transfer it manually or document it inconsistently.

How it is still often done in practice

In many organisations, management systems continue to be managed and documented in a decentralised manner. Information is stored in various Excel files, SharePoint folders, ticketing systems, email threads, audit documents or presentations. Departmental teams provide information manually. Those responsible then transfer this information into central registers or reports.

This works for a while. But it doesn’t scale well.

As the number of requirements, roles and supporting documentation increases, typical problems arise: duplicate data, outdated information, inconsistencies between different media, unclear responsibilities and contradictory statements. The situation becomes particularly critical when the same information is assessed differently in different contexts. An AI system, for example, may be relevant from the perspectives of data protection, information security and AI governance. If these assessments are carried out separately, the overall picture is lost.

The result is often a management system that exists in theory but lacks sufficient operational control. Documents, registers and processes are in place, but ascertaining the organisation’s actual status requires considerable effort. It is precisely here that effectiveness becomes a problem. After all, a management system achieves its objectives not simply through the existence of documents, but by identifying risks, implementing measures and making decisions based on reliable information.

GRC tools as enablers of integrated management systems

GRC tools cannot automatically solve these challenges, but they can provide the necessary structure. It is crucial that a GRC tool is not merely viewed as a filing system or ticketing tool, but as an enabler of an integrated management system.

A suitable GRC tool makes it possible to record requirements centrally and link them to risks, controls, measures and evidence. Information can be collected directly from specialist departments and stakeholders. Responsibilities can be clearly assigned. Measures can be tracked, deadlines monitored and escalations made visible. At the same time, a consistent database is created for management reports, audits and regulatory compliance.

A GRC tool becomes particularly valuable when it does not view different management systems in isolation, but can map their interfaces. This reveals which requirements affect the same processes in multiple ways, which controls address several regulatory requirements simultaneously, and where genuine gaps exist.

An example: a technical measure for access control may be relevant to information security, data protection and AI governance at the same time. Without an integrated view, this measure may be documented multiple times, assessed differently and tracked separately. With a GRC tool, the same measure can be assigned to multiple requirements and risks. This not only leads to greater efficiency, but above all to greater effectiveness and consistency.

This is precisely where the difference lies: efficiency means getting things done faster. Effectiveness means managing the right things in a transparent and effective manner. A good GRC tool supports both, but its true value lies in the effective management of complex management systems.

Conclusion: Excel and Jira are gradually becoming obsolete

Modern governance, risk and compliance requirements can no longer be meaningfully considered in functional silos. The AI Act, the Cyber Resilience Act, NIS2 and the GDPR demonstrate that regulatory requirements are becoming increasingly intertwined. Organisations must therefore think and work within integrated management systems.

A GRC tool is not a panacea and does not replace the need for a subject-matter-specific examination of requirements, risks and responsibilities. However, it is increasingly becoming the necessary foundation for effectively managing this complexity. Without a centralised database, clear links, traceable responsibilities and robust reports, a management system quickly becomes a documented statement of intent rather than an effective control instrument.

The choice of the right tool depends heavily on the organisation’s requirements, size, maturity and target architecture. The market offers numerous solutions, ranging from lean entry-level products to comprehensive enterprise platforms. The price range accordingly extends from a few thousand euros to six-figure sums.

This is precisely why organisations should engage with GRC tools at an early stage and in a structured manner. Not because every company needs a large platform straight away, but because Excel, SharePoint and Jira reach their limits in the long term when it comes to integrated management systems. At first glance, they appear flexible and cost-effective. In the long run, however, they become costly when inconsistencies, manual maintenance efforts, a lack of transparency and unclear responsibilities jeopardise the effectiveness of the management system.

The crucial question is therefore no longer whether a GRC tool delivers efficiency gains. The crucial question is: Can your organisation even manage its management systems effectively without a suitable GRC tool?


IT Security & Cyber Security

A competitive advantage rather than a target

Our goal: to position your organisation so that it can withstand attacks, recover quickly from disruptions and, at the same time, reliably meet regulatory requirements.

Learn more


Picture Kaan Güllü

Author Kaan Güllü

Kaan Güllü is deeply involved in IT risk management, information security and IT compliance, including data protection and the regulatory requirements of the AI Act. His core responsibilities include setting up and operating information security, data protection and AI management systems (ISMS, DSMS, AIMS). He has extensive experience in dealing with international standards such as ISO 27001, ISO 42001, BSI IT-Grundschutz, the EU General Data Protection Regulation (EU GDPR) and the German Federal Data Protection Act (BDSG). This combination enables him to take a holistic approach to security and compliance issues in modern IT environments.