TL;DR
- GRACE is Ampcus Cyber’s GRC platform, built as a control-truth ledger where frameworks, controls, evidence, assets, and risk all live on one connected graph, so every compliance verdict traces back to real evidence.
- Evidence is collected continuously and versioned in an append-only ledger, then mapped once across 250+ frameworks, so the same artifact satisfies ISO 27001, SOC 2, PCI DSS, and more without repeated collection.
- Findings translate directly into quantified risk through Grace-Q, which runs Monte Carlo simulation over live posture to produce annualized loss expectancy instead of a color on a heat map.
Picture a CISO heading into a board meeting during the same month an ISO 27001 renewal, a SOC 2 audit, and a PCI DSS reassessment all land on the calendar. The board asks a simple question: are we compliant right now? The honest answer takes three days of pulling screenshots, chasing spreadsheet owners, and cross-checking which evidence file is current. Nothing on the compliance dashboard is wrong. It is just stale, scattered, and impossible to defend on demand.
This is the gap GRACE was built to close. Rather than treating compliance, risk, evidence, and assurance as four separate workstreams, GRACE connects them on a single graph, so the answer to “are we compliant” is always current and always provable.
What Is GRACE and Why Does It Connect Compliance, Risk, Evidence, and Assurance?
GRACE is Ampcus Cyber’s orchestrated GRC platform under ComplyX umbrella, described on its own product page as a control-truth ledger. Frameworks, controls, evidence, assets, and risk all live on one graph, so every verdict is derived from evidence rather than typed into a status field by a person.
That design is why the four concepts in the title are not separate features bolted together. Compliance status is a projection of the evidence graph. Risk is computed from the same findings that drive compliance gaps. Evidence is the substance that makes any claim provable. Assurance is simply what results when the other three are always current and always traceable. GRACE’s own positioning captures this directly: governance, risk, compliance, and evidence, together on one graph. It sits within ComplyX, Ampcus Cyber’s product arm, alongside third-party risk and penetration-testing tools built on the same automation-first philosophy.
How Does GRACE Turn “Are We Compliant?” Into a Question You Can Always Answer?
GRACE answers this question by removing the writable status field most GRC tools rely on. Instead of a person marking a control “compliant” in a box, status becomes a projection over the evidence graph, recomputed as evidence arrives, expires, or fails.
This matters because a writable status field is only as honest as the last person who updated it. If evidence has quietly expired or a control has drifted, a manually maintained tracker will not know until someone checks. GRACE recomputes the verdict continuously, so the platform reflects live posture rather than the last time someone remembered to update a spreadsheet.
How Does GRACE Connect Evidence to Every Compliance Claim?
GRACE connects evidence to every claim through an append-only evidence ledger, where artifacts are collected, versioned, and expired rather than edited in place. In practice, this means the application layer never overwrites a past record. A correction or expiration adds a new entry rather than altering the old one, so the history stays reconstructible. GRACE’s public materials do not detail the specific tamper-evidence mechanism behind this, such as cryptographic hashing or write-once storage, so security architects who need that level of assurance should confirm it directly with the Ampcus Cyber team. Fifteen built-in discovery providers sweep AWS, Azure, GCP, and an organization’s SaaS estate continuously, turning live configuration into evidence streams instead of manual screenshots.
Because nothing is silently overwritten, audit history becomes a fact rather than a reconstruction project. A single piece of evidence, collected once, can satisfy every framework obligation it maps to. GRACE currently crosswalks more than 250 frameworks, including ISO 27001, SOC 2, PCI DSS, HIPAA, NIST CSF, GDPR, DORA, and FedRAMP, onto more than 1,500 controls across 34 security domains.
How Does GRACE Turn Risk Into a Number Leadership Can Use?
GRACE turns risk into a number through Grace-Q, which runs Monte Carlo simulation over an organization’s actual control posture to produce annualized loss expectancy with confidence bands, rather than a subjective red, amber, or green rating.
Gaps in the evidence graph become findings, and findings become quantified risk automatically, since both draw from the same underlying data. This gives CISOs a figure they can put in front of a board or a cyber insurance underwriter instead of a qualitative score that depends on who filled out the assessment. The general approach, converting control gaps into a probabilistic dollar figure through Monte Carlo simulation, sits in the same territory as Open FAIR, the Open Group’s established standard for quantitative cyber risk analysis. GRACE’s own materials do not state that Grace-Q follows Open FAIR’s specific taxonomy, so risk analysts who need that level of methodological detail should confirm it directly. GRACE is explicit that AI-assisted answers here are grounded in the organization’s own graph or clearly marked as advisory, never presented as the decision of record.
How Does GRACE Deliver Assurance Across Multiple Frameworks at Once?
GRACE delivers assurance by making the audit package itself a projection of the same ledger used for daily compliance monitoring, available on any day of the year rather than assembled under deadline pressure.
Because evidence is mapped once and attested everywhere, an organization pursuing ISO 27001 certification while maintaining SOC 2 and PCI DSS obligations is not running three separate evidence-collection efforts in parallel. The underlying assets, controls, and evidence are shared, and only the framework-specific requirements differ. This is what makes GRACE’s audit-readiness claim credible: the proof was never separated from the platform in the first place, so there is nothing to reconstruct when an auditor asks for it. Governance leaders coordinating this across multiple stakeholders gain the same live view the compliance team works from, rather than a summarized report that is already out of date by the time it reaches the board.
What Changes When a Team Moves From Periodic Audits to Continuous Compliance?
Four shifts define the move from periodic to continuous compliance under GRACE, and each one replaces a manual, point-in-time habit with something the graph maintains on its own.
| Category | Traditional GRC | GRACE |
| Control status | Reassessed at quarter-end or audit time | Recomputed continuously as evidence arrives |
| Compliance verdicts | Asserted by whoever updates the tracker | Derived from live evidence, graded by strength |
| Framework handling | Managed separately, framework by framework | Cross-framework, one piece of evidence mapped everywhere it applies |
| Audit preparation | A seasonal crunch before the assessment | A projection of the ledger, available any day of the year |
Teams already running GRACE, the platform’s original workflow-first experience, are migrating toward this graph-native version as the single front door going forward. Both read the same underlying ledger, so the transition changes how the data is presented, not the evidence itself. For a fuller walkthrough of the platform’s origins and capabilities, see What Is ComplyX GRACE?
| See how your own evidence graph would look. Launch GRACE and explore the platform. |
People Also Ask:
Does GRACE Replace My Compliance Team?
No. GRACE removes manual evidence chasing and status tracking, but control ownership, remediation decisions, and audit strategy still belong to your compliance and security teams.
What Frameworks Does GRACE Support?
GRACE crosswalks more than 250 frameworks, including ISO 27001, SOC 2, PCI DSS, HIPAA, NIST CSF, GDPR, DORA, and FedRAMP, onto a shared set of more than 1,500 controls.
Is GRACE the Same as GRACE Classic?
Both read the same control-truth ledger. GRACE Classic is the original workflow-first experience, while the graph-native GRACE is the recommended version as Classic is phased out.
Enjoyed reading this blog? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn.










