Legacy GRC was slow, expensive and needed a specialist to drive it. Automation answers that honestly. Agents pull evidence out of the systems you already run, map one control to every framework asking for it, and check daily rather than once a year before fieldwork begins.
Automation collects the evidence. You still own the control.
Collection automates. Mapping automates. The judgement never has, and no agent is about to take it.
Our promise
“A dashboard you cannot reproduce is a picture.”
Every finding is written against a capability you are being sold — and we license, resell and take referral fees from no platform. The fee is fixed at $5,000, and nothing is charged until you approve it.
Request this readiness reviewThe automation case, in three chapters
What none of it does is operate the control, judge whether the result was adequate, or accept a risk. A demo shows collection working on a clean estate. It cannot show the systems yours has that nobody built an integration for, or the checks a team silenced one spring and forgot.
Our job is the read before you buy. We write down the controls you actually run, work out which a platform would genuinely reach, reproduce one control's evidence the way fieldwork would ask for it, and hand you the questions that make two demos comparable. We sell no platform.
Two halves. Only one automates.
Software owns the evidence about a control. You still own the control.
- Collection - artefacts pulled from systems you run
- Mapping - one control answering six frameworks at once
- Monitoring - checked daily, not once before fieldwork
- Assembly - the audit pack indexed rather than gathered
- The control - somebody still runs it, and owns it
- The judgement - adequate, not merely marked complete
- The exceptions - every check silenced, and by whom
- The opinion - an auditor signs it, and never a dashboard
The agent collects. You still decide.
What software genuinely owns
Pulling the evidence out of the systems you already run, mapping one control to the six frameworks that ask for it, and checking every day rather than once every twelve months. This is real work, it is genuinely dull to do, and a machine does it better than any person with a screenshot tool ever will.
What no agent takes on
Operating the control. Deciding the access review was adequate rather than merely completed. Accepting a risk, and being the person who accepted it. Automation can prove a control ran; it cannot decide the control was the right one to run, and it will never sign anything with a name on it.
When green is the problem
Nobody sets out to automate the wrong evidence. An integration is pointed at the wrong project, a check is written against a field that stopped being filled in, and the collection keeps succeeding. The dashboard still reads 100%, nothing alerts, and the gap is found by the auditor at fieldwork instead.
“The platform is in. Compliance is handled.”
Show me this control, for a date last March.
It is the most common finding we write up.
- Who it is for
- Security & GRC leads
- SaaS & platform vendors
- Startups getting certified
- Growth companies scaling
- Internal audit & risk
An agent pointed at the wrong project does not fail. It succeeds, on schedule, for a year - and the gap is found by the auditor.
Coverage is never the number on the pricing page. The remainder stays manual, and a programme that cannot state its size is guessing.
The exception list is the first thing a good auditor asks a green dashboard for: every check silenced, by whom, and why.
Three questions. Then you’ll know.
No email, no signup. A starting point, not a determination.
Your automation check
Four moments, and the demo shows one.
A sales call covers week zero and skips the two in the middle, which are where the cost and the risk of a rollout actually sit.
-
Inventoried
Week zeroThe controls you actually run are written down, before anyone asks which of them a platform can reach.
-
Connected
Weeks 1-6Integrations go in. Coverage is never what the pricing page implied, and the remainder stays manual.
-
Tuned
Weeks 6-12The false alerts are silenced. This is the step that decides whether anyone still reads the dashboard.
-
Tested
Every 12 monthsAn auditor asks the platform to reproduce a year of evidence. That request is the only real acceptance test.
Teams sign at week zero and count the rollout as done at week six. The step that decides whether any of it works is not on the invoice at all — it is the tuning, and it is the difference between a dashboard people read and one they mute.
What the pitch claims, what we check
12 capabilities as they are sold, and what we go and look at for each. Paired, so every claim on this page can be checked against the capability beside it.
- What is actually automated The evidence about a control, not the control itself
- A written split of which of your controls a platform would operate, which it would only observe, and which it cannot see at all.
- Integration coverage "Hundreds of integrations" - the count is not the question
- Your stack checked against what would genuinely connect, so the manual remainder is a number in the plan rather than a surprise.
- Automated evidence collection Screenshots and exports, gathered continuously
- Whether the artefact collected is the one an auditor accepts, and whether it can still be produced twelve months later.
- Cross-framework mapping One control answering SOC 2, ISO 27001, HIPAA and more
- The mapping read rather than trusted - a control that satisfies one framework often only half-satisfies the next one along.
- Continuous monitoring Checked every day instead of once before fieldwork
- What each check actually tests, how it fails, and whether a failure reaches a person who can do something about it.
- Automated control testing Tests written and run against your live configuration
- Whether the test asserts the control worked or merely that the integration replied, which is not the same finding.
- Policy generation Drafted from your answers rather than from a template
- Whether the generated policy describes the process you run, because a policy nobody follows is a finding rather than a control.
- Endpoint and device checks An agent on the laptop, reporting disk and screen lock
- What the agent can see, what it cannot, and what your own people were told before it was installed on their machines.
- The systems with no API Browser automation, driving a portal like a person would
- Every system in your estate that has no integration named, with the ones a browser agent could reach separated from the rest.
- Vendor risk Questionnaires answered and assessed automatically
- Whether a generated answer is one you would stand behind in front of a customer, which is the only test that matters here.
- Audit reproducibility The request that arrives twelve months after the demo
- One control picked at random and its evidence reproduced end to end, exactly as fieldwork would ask you to produce it.
- What the auditor still does The opinion. No platform has ever issued one
- A plain statement of the work that stays human, so a green dashboard is never mistaken for a report somebody signed.
Your control set, independently read
From a first framework to a fourth one.
-
Inventory
Which controls you actually run, and what evidence each one throws off on its own.
-
Trace
One control followed from the integration to the audit file, and read at the far end.
-
Sign off and file
You see the draft first. Then the coverage map, the shortlist and the record - dated.
Why teams ask iDharma what a platform will really do
We sell no platform
Nothing to license and no seats to grow, so we have no reason to call your spreadsheet a gap.
No referral fees, ever
We take nothing from any vendor, which is why this page can say a tool sometimes is not worth it.
Tested, not asserted
We reproduce a real control from your real evidence, rather than read a datasheet back to you.
Costed, not just listed
Every gap arrives with what closing it takes in money and hours, so the plan is a budget not a wish.
Four marks, struck on every readiness report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
Automation readiness report
The whole assessment in one document: every control you actually run, which of them a platform could collect evidence for and which it could not, what the mapping to each framework you care about really covers, where the automated evidence would not survive an auditor asking for it, and what stays a human job.
Control and system register
Every control, the system it runs in, the evidence it produces and the owner it belongs to, in a workbook your team can keep current.
Coverage map
What a platform would genuinely reach in your estate, what it would miss, and the manual remainder stated as a number rather than a hope.
Evidence trace
One control followed from the integration to the artefact an auditor would accept, with every step it passes through named and dated.
Scope memo
Which systems and controls were in scope, which were deliberately left out, and the reason for each call written down rather than assumed.
Remediation shortlist
What to fix before you automate and what automation would only make faster, ranked by what an audit actually stops on rather than by ease.
Vendor question sheet
What to ask a platform so two demos can be compared - real coverage, evidence format, what a re-collection costs and what is excluded.
Real numbers, upfront.
- Scope
- Your control set, not our menu
- Input
- Your controls, tools, evidence
- Re-read
- Annually, or on a stack change - a new system or framework
Your control set fixes the scope, so the fee is flat - and nothing is charged until you approve it.
Request your review- Independent readiness report, costed
- Coverage map, system by system
- One control traced end to end
- Vendor question sheet you keep
Four things you have to be able to produce
A green dashboard is not a document. Each of these is either in your hand on the day somebody asks, or it is not.
The inventory,
current
Every control you run, with an owner beside it. A platform can only automate what somebody first wrote down, and the list is almost never the one on the slide.
The coverage,
honest
Which controls the tooling reaches, and which are still a person with a calendar reminder. A programme that cannot state its manual remainder is guessing.
The evidence,
reproducible
One control picked at random and its artefacts produced for a date last quarter. If it takes a week and a vendor support ticket, it is not automated yet.
The exception,
recorded
Every check that has been silenced, muted or marked not applicable, with who decided and why. This is the first list a good auditor asks a green dashboard for.
Four cards, and a dashboard produces none of them.
Plain answers
What it does, where it fails, and what it costs. Answered straight.
Request your reviewWhat does GRC automation actually automate?
The evidence about your controls, not the controls themselves. Collection, mapping to frameworks, and daily checking are genuinely automatable. Operating the control, judging whether it was adequate, and accepting a risk are not.
Does automation replace the auditor?
No, and no platform claims it in writing. An audit opinion is signed by a licensed firm after fieldwork. Automation changes how quickly you can answer them, not whether you need them.
We are twenty people. Is a platform worth it yet?
It depends on how many controls you run and how much of your stack a platform would actually reach - not on headcount. Below roughly thirty controls with good cloud coverage, a spreadsheet and a calendar often still win.
Can AI write our policies?
It can draft them, and the draft is usually better than a downloaded template. The risk is the same either way: a policy describing a process nobody follows is a finding, not a control - and generation makes producing one much faster.
What does iDharma charge for this?
The automation readiness review is a published fixed fee of $5,000. It is the same number in the checkout, it does not move with what we find, and we license, resell and take referral fees from no platform.
Request your readiness review
Tell us what you run and where the evidence lives, and we come back with a scoping call within one business day.
What we need from you
Nothing you do not already have. Most of this is a folder someone can assemble in an afternoon, and we name every document first, in writing, before you commit.
- Which controls you believe you run today
- Which frameworks you are being asked to satisfy
- Any documentation - policies, prior reports
- Where your evidence lives today, tool by tool
- One control you would like us to trace end to end
What happens next
- You send the five items we need.
- You get a scoping call within one business day.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- Published vendor documentation, read directly
- Our own engagements, generalised
- Last read
- 14 September 2026
- Vendors named
- None, deliberately
What it means
- General information about a class of software — not procurement advice, and no professional relationship arises from reading it. It determines nothing about your own estate.
- Where a coverage question is arguable, our reports say so rather than the convenient one.
Scope & limitation
- What platforms do here is a market observation, not benchmarked survey data.
- Only the $5,000 review fee is ours - we take no referral fee from any vendor.
- Do not rest a purchase on it alone; test the claims against your own estate.
Something on this page out of date?
Tell usFrom Insights
Before you buy one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
ISO/IEC 42001, SOC 2 and NIST AI RMF: Which One Your Buyer Is Actually Asking For
One certifies an organisation, one is an opinion about controls over a window, one is a method with nothing to issue. What each covers — and what none of them answers.