ISMS Copilot
Specialist AI for GRC work

An AI GRC assistant for compliance work

ISMS Copilot is specialist AI for GRC work: it drafts the policies, runs the risk assessments, maps the controls, and prepares the audits. It is not a GRC platform, and it does not try to be one.

Last updated: 2026-09-02

ISMS Copilot is an AI GRC assistant

It covers the judgment layer of governance, risk, and compliance: the work practitioners actually lose days to. Framework-specific policy drafting. Structured risk assessments. Mapping one control across several frameworks. Statements of Applicability with rationales. Audit walkthrough preparation. Framework questions during implementation.

It is not a GRC platform: it does not connect to your stack to collect evidence and does not monitor controls continuously. It is the writing and reasoning layer teams run alongside their evidence platform, or beside it while they run no platform. It is also not a replacement for your consultant or your auditor: strategy, accountability, and sign-off stay with people.

Want the full three-layer breakdown (agentic GRC platforms, specialist AI for GRC work, AI governance of agents)? It lives in the taxonomy guide.

What you can hand it

The GRC work ISMS Copilot handles, end to end.

  • Framework-specific policy drafting

    Policies aligned to the specific framework, control, and your operating model, not generic templates. ISO 27001 Annex A, SOC 2 TSCs, NIS 2 measures, HIPAA safeguards.

  • Risk assessments

    Structured asset, threat, likelihood/impact, and treatment work under ISO 27001 clause 6.1.2 or the equivalent in your framework, with defensible rationales.

  • Cross-framework control mapping

    Map one control across ISO 27001, SOC 2, NIS 2, NIST CSF, GDPR, and more, so adding a second framework shows coverage and gaps instead of restarting from zero.

  • Statements of Applicability

    SoA entries with applicability decisions, current state, and justification for each control. You still own and sign it.

  • Document analysis

    Upload existing policies, audit reports, or risk registers (PDF / DOCX / XLS) and get gap analysis and improvement suggestions back.

  • Audit preparation

    Rehearse the auditor's questions: control design rationale, evidence walkthroughs, exception handling, Stage 1 and Stage 2 readiness.

  • Regulatory applicability reasoning

    Whether NIS 2, DORA, the EU AI Act, HIPAA, PCI DSS, or the CRA applies to you, reasoned from the actual articles and criteria, with free checkers for many of them.

  • Agent-accessible GRC work

    The same engine reachable from coding agents via MCP, from your own software via the OpenAI-compatible API, and from partner products via embed.

Full list, with coverage tiers per framework: the frameworks hub (99+ frameworks across 19 jurisdictions).

How you reach it

Practitioner chat

Fast, Think, and Beyond multi-document modes at chat.ismscopilot.com, with workspaces for client or project separation.

Account MCP

Connect coding agents such as Claude Code, Cursor, and Codex to your ISMS Copilot account via MCP.

OpenAI-compatible API

Existing OpenAI clients keep their code and change the base URL. Grounded compliance reasoning as a sub-agent step.

Embed

Partner products ship a compliance-trained assistant inside their own UI, with their branding.

White label

For larger GRC and consulting platforms that want the engine under their own brand. Waitlist.

Alongside your GRC platform, not against it

The pattern that works: two layers, two jobs.

The platform

Evidence and monitoring

GRC platforms in this category connect to your infrastructure to collect evidence and monitor controls, and maintain the compliance state of record; feature sets vary by vendor and plan, and each vendor's documentation is the source of truth. Examples: Vanta, Drata, Scrut, Sprinto, Scytale, Secureframe, Hyperproof, OneTrust.

The assistant

Writing and reasoning

Drafts the policies the platform monitors, designs the controls before they are checked, writes the risk assessments and SoA rationales, and prepares the audit narrative. Category example: ISMS Copilot.

In practice: teams running a platform use ISMS Copilot to deepen the drafting and reasoning layer alongside their platform: policies, risk assessments, SoA rationales, audit narratives. Teams not yet on a platform use it for the documentation and judgment work, and move to a platform when evidence automation becomes the bottleneck. Either way, the auditor still audits you, not your tools.

What it does not do

  • No evidence collection from your infrastructure.
  • No continuous control monitoring.
  • No compliance system of record.
  • No certification, no audit opinion, no legal advice.
  • No training on your data. Database and file storage in Frankfurt (EU). Conversation and upload retention is configurable; provider and moderation retention is documented in the Trust Center.

ISMS Copilot is the AI GRC assistant we built

Self-serve from day one: a free plan with no card required, paid plans from $20/month, no enterprise sales call. Chat, MCP, API, and embed on the same engine.

Frequently asked questions

What is an AI GRC assistant?

An AI GRC assistant is a specialized AI assistant for GRC work: the human-judgment layer of governance, risk, and compliance. It drafts framework-specific policies, runs structured risk assessments, maps controls across frameworks, generates Statements of Applicability, and prepares audit walkthroughs. It is not a GRC platform: it does not connect to your cloud stack to collect evidence and does not continuously monitor controls.

Is ISMS Copilot an AI assistant for GRC?

Yes. ISMS Copilot is specialist AI for GRC work across ISO 27001, SOC 2, GDPR, NIS 2, DORA, HIPAA, ISO 42001, the EU AI Act, plus more frameworks and regional transpositions in the same workspace. It is grounded in a curated compliance knowledge base, built to refuse rather than guess, and reachable through chat, MCP, an OpenAI-compatible API, and embed.

Is an AI GRC assistant a GRC platform?

No. GRC platforms automate evidence collection and continuous control monitoring: they integrate with your infrastructure, pull live security signals, and maintain compliance state as a system of record. An AI GRC assistant does the writing, reasoning, and mapping work on top of that state (or beside it when you do not yet run a platform). Most teams pursuing certification benefit from both layers in combination.

How is an AI GRC assistant different from using ChatGPT or Claude?

General-purpose AI is capable but not specialized: without grounding, it can invent control numbers, confuse framework revisions, and miss jurisdiction-specific requirements. A specialist AI GRC assistant is built on a curated knowledge base of real implementation experience, answers from that base, and refuses rather than guesses when it does not know. Always verify outputs against official documentation.

Can I use an AI GRC assistant alongside a GRC platform?

Yes, and that is the common pattern. The platform watches the controls; the assistant writes the policies the platform monitors, designs the controls before they are checked, drafts the risk assessments and SoA rationales, and prepares the audit narrative. ISMS Copilot is built to complement evidence platforms, not to replace them.

Which frameworks does ISMS Copilot cover?

ISMS Copilot has curated knowledge for 99+ frameworks across 19 jurisdictions, including ISO 27001, SOC 2, GDPR, NIS 2, DORA, HIPAA, NIST CSF and 800-53, CMMC, CCPA, ISO 42001, ISO 27701, the EU AI Act, and the EU Cyber Resilience Act, plus country-specific regimes like TISAX, HDS, ENS, Essential Eight, PIPEDA, Loi 25, PDPA, and MAS TRM. The frameworks hub is the source of truth for what ships today.

How do AI agents access it?

Agent access runs on three surfaces: Account MCP for coding agents (Claude Code, Cursor, Codex and other MCP clients), an OpenAI-compatible API for custom agents and platforms, and an embeddable assistant for partner products. All three hit the same grounded compliance engine.

What does an AI GRC assistant not do?

It does not collect evidence from your infrastructure, does not continuously monitor controls, does not maintain a compliance system of record, does not certify you, and does not replace your auditor, CPA, or legal counsel. It supplies the reasoning and drafting layer; accountability stays with your team and your auditor.

How much does it cost?

ISMS Copilot is self-serve: a free plan with no card required, then paid chat plans from $20/month with team plans above that. No enterprise sales call and no quote-based pricing for chat. API and Embed have separate pricing on their product pages.