Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI in GRC: what the visibility and accountability gap means


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12324
Topic starter  

TL;DR: AI adoption in GRC is outpacing governance models: Drata’s survey of 300 U.S. IT and security professionals found 43% say AI made their jobs harder, 90% report at least some AI investments fell short of expectations, and 71% say an AI tool used for GRC caused a failed audit or lapsed standard. The real issue is not AI breadth, but governed scope, visibility, and accountable outcomes.

NHIMG editorial — based on content published by Drata: The State of GRC in the Age of AI

By the numbers:

Questions worth separating out

Q: How should security teams govern AI-enabled workflows that can act on their own?

A: Treat them as identity-governed execution paths, not just software features.

Q: Why do traditional GRC tools fall short for AI governance?

A: Traditional GRC tools are strong at documentation and evidence collection, but AI risk now shows up during execution.

Q: What do organisations get wrong about AI observability?

A: They often confuse technical telemetry with governance evidence.

Practitioner guidance

  • Build a live AI tool inventory Track every AI tool used in GRC and adjacent workflows, including data access, human owner, approval path, and review cadence.
  • Assign outcome owners for AI-assisted workflows Name one accountable business owner for each AI-enabled compliance or review workflow so audit failures, exception handling, and control drift have a clear escalation path.
  • Tie AI controls to evidence and review cycles Require current evidence for each AI tool, including security posture, vendor assurances, and review status.

What's in the full report

Drata's full report covers the operational detail this post intentionally leaves for the source:

  • The full subgroup breakdown by company size and revenue, useful for benchmarking where AI friction is most pronounced.
  • The detailed question wording behind the 300-person survey, which matters if you are validating how the findings map to your own programme.
  • The report's deeper cut on trust-centre adoption and how practitioners are using continuous assurance to support vendor reviews.
  • The vendor's month-ahead series outline, which shows how the broader expectations gap will be unpacked in follow-up analysis.

👉 Read Drata's report on AI in GRC governance gaps and audit risk →

AI in GRC: what the visibility and accountability gap means?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 2 months ago
Posts: 11878
 

AI governance debt is now an operating risk, not a future concern. The report shows that adoption is outrunning the controls needed to make AI defensible in GRC workflows. When 83% of organisations say they are not fully prepared for the coming wave of AI integration, the problem is not experimentation but accumulated governance debt across visibility, ownership, and evidence. Practitioners should treat AI control design as part of core identity and assurance architecture.

A question worth separating out:

Q: Who is accountable when an AI-assisted GRC workflow fails an audit?

A: The organisation is accountable, not the tool. Practically, that means the business owner of the workflow, the security or compliance leader overseeing controls, and procurement or vendor risk teams all share responsibility for ensuring the AI’s use is documented and defensible.

👉 Read our full editorial: AI in GRC is widening the visibility and accountability gap



   
ReplyQuote
Share: