Ask your assistant about your GRC program.

OpenGRC ships an MCP server, so Claude and ChatGPT can read and update your compliance program directly.

Your compliance program, in the tool you already talk to

Most GRC work is not hard, it is just tedious. Finding which controls have no evidence. Working out which vendors are overdue for review. Writing the same incident summary for the third time this quarter.

The Model Context Protocol (MCP) is an open standard for connecting AI assistants to live systems. OpenGRC Enterprise ships a native MCP server — 40 tools and 5 prompts — so instead of exporting a report and pasting it into a chat window, your assistant queries your actual program — and can act on it.

It works with Claude, ChatGPT, and any other client that speaks MCP. Nothing is copied anywhere: your assistant connects to your OpenGRC instance, authenticates as you, and sees exactly what you would see.

What it does

Read the program. Change the program. Find anything.

Read your whole program

Read your whole program

Controls, implementations, risks, audits, vendors, incidents, policies, assets and access reviews. Ask a question in plain language and get an answer from live records, not a stale export.

Take action, not just look

Take action, not just look

Open an incident and assign its tasks. Log a risk. Update an implementation. Raise a remediation project. The server supports creating and updating records, not only reading them.

Semantic search across everything

Semantic search across everything

A dedicated search tool ranks policy excerpts, implementations, controls and risks by meaning rather than keyword, so "what is our password rotation rule" finds the clause even when it never says "rotation".

What you can actually ask

Once connected, these are ordinary requests rather than reporting projects:

  • “Which SOC 2 controls have no implementation evidence attached?”
  • “Summarise every open high risk and tell me who owns each one.”
  • “Which vendors are overdue for their annual review?”
  • “Open an incident for this phishing report, apply our standard playbook, and assign the containment tasks.”
  • “What does our policy actually say about encrypting laptops?”
  • “Draft the gap analysis between our current controls and ISO 27001 Annex A.”
  • “Which audit requests are still outstanding, and how long have they been open?”

The assistant does the fetching, filtering and drafting. You keep the judgement.

Connecting it, and keeping it safe

Setup takes a few minutes. The server speaks OAuth 2.1 with dynamic client registration, so you authorise your assistant the same way you would any other app — no API keys to mint, copy or rotate by hand. Step-by-step instructions are in the documentation.

It respects your permissions

The MCP server authenticates as a user and inherits that user's permissions. It cannot read or change anything the person behind it could not read or change in the interface. If access is denied, that is a permission boundary doing its job, and the assistant is told so plainly.

Your data does not train anything

We do not use Customer Data to train, fine-tune or otherwise improve AI models, and we do not permit our subprocessors to do so. That is a contractual commitment, not a policy footnote — see our security page and Terms of Service §4.11.

Everything is attributable

Records created or changed through the MCP server are attributed like any other change, so your audit trail stays intact. An assistant acting on your behalf is still you, and the history shows it.

MCP questions, answered

What is MCP?

The Model Context Protocol is an open standard for connecting AI assistants to external systems. Rather than pasting exports into a chat window, the assistant connects directly to the system and works with live data. It is supported by Claude, ChatGPT and a growing number of other clients.

Which assistants does the OpenGRC MCP server work with?

Can it change data, or only read it?

Is my data used to train AI models?

Can the assistant see things the user cannot?

Is the MCP server available in the Community edition?