GRC engineering is more than automation
Writing a script is one part of the work. Getting a process adopted across an organization is another.
Adapted from my original LinkedIn post.
Automating evidence collection is useful. But writing the script does not finish the job.
The work also involves managing risk, navigating governance, and building processes that people across the organization will actually use. A technically sound workflow can still remain isolated from the people it needs to help.
In the original post, I described a sourcing practitioner who put together a useful AI-assisted process with ordinary documents, an API, and a prompt. The point was not the complexity of the stack. It was whether the process helped someone do their work.
That is the question I want to keep asking about GRC engineering: what does it help your organization do, beyond collecting evidence faster?