DEV Community

Cover image for Building a More Complete GRC Platform — The Latest CSFaaS Updates
CSFaaS
CSFaaS

Posted on Originally published at csfaas.com

Building a More Complete GRC Platform — The Latest CSFaaS Updates

While many are taking a summer break, we have been doing what we love: building for you.

Since late July, 55 issues have moved to Done across CSFaaS.

Some introduced new capabilities. Others fixed edge cases, tightened workflows, improved auditability, improved usability, or hardened the platform underneath.

Taken together, they tell an important story: CSFaaS is becoming a more mature, reliable and operational GRC platform, release after release.

Here is a snapshot of what has kept the team busy over the past few weeks.

AI prompts and automation

One of the most important additions is the new ability to create, store and manage reusable AI prompts directly in CSFaaS.

These prompts are designed to help teams automate and standardize recurring GRC activities.

They can be used, for example, to:

  • review controls and evidence;

  • document or assess risks;

  • check framework implementation status;

  • generate summaries;

  • produce recommendations;

  • support audit preparation;

  • standardize recurring analysis and review activities.

Instead of rewriting the same instructions every time, teams can now turn their own methodologies and best practices into reusable AI workflows.

This is also a natural extension of CSFaaS' MCP architecture.

The objective is not to place an AI chatbot next to the platform.

It is to make AI available throughout the GRC operating model, connected to the information already managed inside CSFaaS: frameworks, controls, risks, policies, evidence, audits and related workflows.

AI is no longer a separate assistant sitting next to the GRC platform. It becomes part of the way the GRC platform operates.

MCP hardening

The MCP layer has also received significant attention over the past few weeks.

Several issues were fixed around write operations, usage reliability and restricted permissions. We also improved the way PDF evidence can be read and added protections to prevent internal application codes from being unintentionally modified.

These may sound like technical details, but they become critical when AI agents are allowed to interact directly with governance data.

Launching an MCP server is relatively easy to announce.

Making it reliable enough for real operational use is a different challenge.

A failed write is inconvenient.

An incorrect write can affect traceability.

An accidentally modified identifier can affect data integrity.

As AI becomes more deeply integrated into GRC processes, the reliability of the MCP layer increasingly becomes part of the reliability of the platform itself.

CyFun integration

CyFun has been another major area of work.

Seven workstreams were completed around the CyberFundamentals Framework (CyFun®), including:

  • support for both Documentation maturity and Implementation maturity;

  • a dedicated summary page;

  • import from the official self-assessment workbook;

  • export back to the official workbook format;

  • support for Key Measures and Management Aspects;

  • version-handling improvements;

  • broader integration into the CSFaaS framework architecture.

The important point is not simply that CSFaaS supports another framework.

The objective is to integrate CyFun into the same underlying GRC model already used for other standards and regulations.

That means avoiding unnecessary duplication.

Controls, risks, evidence, policies and implementation work should be reusable wherever possible across multiple frameworks.

For us, adding another framework should not mean adding another compliance silo.

Risk and Demand workflows

A substantial amount of work also went into improving risk and demand workflows.

Recent changes include the ability to create Risk Demands on behalf of another user, cumulative edit permissions for requests and remediation plans, fixes around response rounds, improvements following the Request Information step, and locking certain review parameters once a risk response has been submitted.

These are the kinds of changes that rarely make release headlines.

But they determine whether a workflow remains reliable once multiple people, roles and review cycles are involved.

A workflow that works during a demonstration is one thing.

A workflow that remains consistent when responsibilities change, information is incomplete, reviews are reopened and multiple stakeholders are involved is another.

That is where product maturity starts to show.

Auditability and framework usability

We also continued improving the experience around frameworks, controls and audits.

Recent changes include the addition of an Audit Conclusion tab to audit framework elements, clearer Finding Register and Actions Register views, support for a Partially implemented applicability status, improved control progression behaviour and several fixes affecting maturity and target maturity displays.

We also corrected smaller usability issues, such as evidence names not appearing correctly in drawers and visual inconsistencies in applicability statuses.

Individually, these are small changes.

During a real audit or assessment, however, small inconsistencies quickly become visible.

A GRC platform should reduce ambiguity, not create it.

The more the platform is used as a system of record, the more important this level of detail becomes.

Permissions and activity visibility

Permissions and traceability also continued to evolve.

We extended role-based access in several areas, improved activity log access configuration and refined permissions around requests and remediation plans.

These changes are important because GRC platforms are collaborative by nature.

Different people need different levels of access, but the platform still has to preserve accountability, ownership and traceability.

The challenge is not simply to restrict access.

It is to provide enough flexibility for organisations without weakening governance.

Platform, scale and monitoring

Some of the work happened deeper in the architecture.

This included event-plane storage improvements designed for scale, as well as export capabilities for MCP and API activity monitoring.

These changes are less visible in the user interface, but they matter as the platform grows.

Operational monitoring, activity traceability and scalable storage are not optional once a GRC platform becomes part of day-to-day security and compliance operations.

Product experience

We also continued refining the broader CSFaaS experience.

That included dashboard fixes, navigation improvements, contextual help for Risk Profiling, terminology improvements, framework display refinements and changes to how certain views behave.

Again, none of these improvements is revolutionary by itself.

But users do not experience a product as a list of features.

They experience the accumulation of hundreds of interactions.

Every unnecessary click, unclear label, broken navigation path or inconsistent result creates friction.

Removing that friction is part of building the product.

Education

The last few weeks were not limited to the application itself.

We launched the new CSFaaS Education Program page.

The Education Program is particularly important to us.

Our goal is to make professional GRC tooling more accessible to universities, schools and training programs, so that students can work with the same concepts and workflows they will encounter in real organisations.

Website

We also launched a fully redesigned CSFaaS homepage, with clearer positioning, updated messaging and a better overview of the platform and its capabilities.

We would genuinely like your feedback.

Take a look at the new homepage and tell us what you think — what is clear, what is missing, and what we could improve.

The accumulation matters

There is no single feature that defines these four weeks.

And that is probably the most interesting part.

A mature GRC platform is not built only through large launches.

It is built through the accumulation of improvements across workflows, permissions, auditability, integrations, reliability, AI, infrastructure and user experience.

The small things matter because GRC itself is built on consistency.

When someone runs an audit, reviews a risk, checks evidence, assigns responsibility, maps a framework or lets an AI agent interact with governance data, the platform has to behave predictably.

That is what the last few weeks have been about.

55 issues shipped since late July.

And there is more coming in the next few days, with several major new capabilities that will take CSFaaS another step closer to becoming one of the most complete GRC platforms on the market.

Welcome to the leading edge of GRC.

Top comments (0)