There’s a moment that happens in almost every mature compliance program.
It’s not during the audit kickoff.
It’s not when the report is delivered.
It’s usually on a random afternoon.
You’re staring at a Slack message from engineering asking why this control evidence is suddenly urgent again. Your inbox has three vendor questionnaires waiting. Your GRC tool says you’re “on track,” but your gut says you’re barely holding the line.
And you’re exhausted. Not from the frameworks themselves, but from all the work no one ever budgets for.
We’ve spent over a decade running SOC 2, ISO 27001, PCI DSS, HITRUST, HIPAA, and SOX programs for hundreds of companies. We’ve lived inside audit calendars. We’ve rebuilt evidence libraries at 2 a.m. We’ve owned the outcomes when things went sideways.
And here’s the truth most people don’t like to say out loud:
The frameworks aren’t the hard part. The hidden work around them is.
This post is about that hidden work - the real SOC 2 operations and ISO 27001 compliance effort that never shows up in scoping calls, project plans, or tooling demos, but dominates the actual job.
Most compliance planning starts with a clean, deceptively simple question:
“How much effort will SOC 2 / ISO 27001 / PCI take?”
Pretty much every conversation I have ever had with a CISO or Head of GRC has started out that way.
The answers are usually framed around:
That framing is convenient. It’s also incomplete.
Because what consumes time isn’t auditing the controls. It’s everything required to keep those controls alive between the audits.
That’s the work no one accounts for.
Every framework has its share of nuances that GRC teams must account for. Here are some examples across SOC 2, ISO 27001, and PCI DSS to drive the point home.
SOC 2 is often sold as “lighter weight” or “foundational.” In practice, it creates a constant operational tax.
Here’s what actually happens between reports:
Screenshots expire. Logs roll over. Configurations drift.
Every quarter, someone has to:
None of that is “audit work.” It’s operational maintenance.
People change roles. Teams reorganize. Responsibilities blur.
Which means someone is always:
This is human labor, not checklist labor.
Temporary compensating controls have a way of becoming permanent.
Tracking them requires:
No framework accounts for the time it takes to manage that reality.
ISO 27001 is positioned as “systematic” and “management-driven.” That’s true and it’s exactly why the hidden work compounds.
Policies, risk registers, SoA decisions, management reviews — none of them are one-time tasks.
Every change in:
Triggers ripple effects across the ISMS.
Maintaining coherence takes constant interpretation from real GRC professionals, not automation. Someone has to do the thinking.
Risk registers don’t update themselves and project management activities don’t happen without someone seeing to it.
Someone has to:
If you want to do this type of work correctly - it is thinking work experienced GRC professionals need to do. It doesn’t scale linearly.
Every non-conformity or process improvement from last year becomes a commitment to show progress toward this year. (Remember that “continuous improvement” clause?)
Someone has to remember:
That institutional memory lives in people - until it doesn’t.
PCI is often treated as a “once-a-year fire drill.”
That’s a fantasy.
In reality:
The hidden work shows up as:
PCI doesn’t just test controls. It tests organizational discipline.
Can you see how as you add compliance requirements the “hidden work” becomes mission critical to a GRC team’s success? Can you see why it needs to be operationalized?
That’s why this job can become overwhelming and teams reach for predictable solutions like audit automation or green checkbox solutions. We are all desperate for a solution. But often those traditional tools don’t solve for the root cause.
Rigid GRC platforms promise structure to achieve a green checkbox.
What they deliver:
The work doesn’t go away. It just moves.
These are good people that offer temporary relief through manual labor.
But here’s what actually happens:
The pain is deferred, not resolved.
Smart, burned-out GRC leaders hold everything together with memory and grit.
This works – for a while - until it doesn’t.
When it breaks, it breaks publicly.
And the result is great people check out. They start hunting for a new job with hope it will be better somewhere else. Which continues this whole cycle we’re talking about.
You need something that solves the root cause.
Here’s what years of running these programs teaches you:
Compliance frameworks don’t fail because they’re too complex. They fail because people treat GRC like projects or point-in-time endeavors. No one owns the lifecycle work between moments of scrutiny.
The invisible labor (and fix) is managing the full lifecycle of your compliance workstreams:
Treating compliance as a “point in time” activity guarantees exhaustion. But if you can build agents to help take over the workload in an intuitive way it creates huge opportunities.
This isn’t hype. I’ve seen them. And we are building them every day.
To be clear, we didn’t start with AI and look for compliance problems.
We spent a decade drowning in compliance problems. We were just like you working out of a mix of spreadsheets, word documents, file repositories, and traditional GRC platforms.
We did that for a decade and for 100s of clients across 1000s of assessments.
AI agents are the only thing that finally made sense.
We are GRC operators who have earned the right to build AI agents.
Not because AI is exciting, but because the hidden work was breaking good teams.
Our agents aren’t dashboards. They aren’t replacements. They’re teammates whose job is to carry the invisible load:
They exist to protect human judgment, enable efficiency, and operate as an extension of your workload in a sensible and intuitive manner.
My experience is that when GRC lifecycle work is owned - really owned - something shifts.
GRC leaders:
Teams:
Audits:
That’s not just transformation. That’s relief. That’s a program that does the job it was intended to do rather than treating the entire profession like a box to be checked.
SOC 2, ISO 27001, PCI DSS, and the whole world of compliance requirements aren’t going away. If anything, expectations are increasing.
The future of compliance isn’t more spreadsheets or louder tooling.
It’s acknowledging the work that’s always been there and finally designing systems that respect it.
We build AI agents because we have operated GRC programs longer and deeper than almost anyone. And once you’ve carried the invisible work long enough, you stop pretending it doesn’t exist.
It’s time we started truly empowering GRC teams and the companies they support.