.webp)
Clients ask for it in procurement. Investors look for it in due diligence. Regulators expect evidence, not assurances. A public GRC profile gives your organisation a scored, independently verified view of its governance, risk, and compliance maturity. It is visible to the people who need to see it, exactly when they need to see it.
2026 has changed the stakes. Provision 29 now requires UK boards to declare control effectiveness publicly. DORA holds ICT providers accountable. The UK Cyber Security and Resilience Bill extends liability to a wider set of organisations. And Verizon's 2026 Data Breach Investigations Report found that 48 per cent of all breaches now involve a third party.
Organisations that can demonstrate GRC maturity publicly are winning contracts, satisfying regulators, and retaining clients. Those that cannot are losing ground to competitors who can.
A public GRC profile is a hosted, independently scored profile page on grci.net. It shows your organisation's GRC Index score, maturity level, and domain-by-domain breakdown.
Clients, investors, and regulators can view it directly via a shared link. You can also use a shareable badge in tender responses, RFP submissions, and investor communications.
The profile is the output of a GRC Index benchmark assessment. The assessment evaluates your organisation across six domains, each scored from 0 to 100. The result is a total GRC Index score and a maturity level from 1 to 5.
GRC Index Score:
Maturity Level:
Domain Breakdown:
Six Domains Covered:
Shareable Badge:
Several converging pressures in 2026 make public GRC evidence no longer optional. Each one creates a different kind of demand for transparent, verifiable governance data.
Provision 29 of the UK Corporate Governance Code 2024 came into force for financial years beginning on or after 1 January 2026. Boards of premium-listed UK companies must now declare whether their material controls were effective.
This declaration covers financial, operational, reporting, and compliance controls. It is included in the annual report, which is a public document. A public GRC profile provides the evidential backbone that makes that declaration defensible.
Related reading: See our full guide to Provision 29 at grci.net/blog/provision-29-corporate-governance-code.
The UK Cyber Security and Resilience Bill was introduced to Parliament in November 2025. It is expected to receive royal assent in 2026. It modernises the Network and Information Systems Regulations 2018 and significantly extends scope.
The Bill introduces a two-tier penalty structure. Standard breaches carry fines up to 10 million pounds or 2 per cent of global turnover. Serious breaches carry fines up to 17 million pounds or 4 per cent of global turnover. Ongoing contraventions can attract penalties of up to 100,000 pounds per day.
Organisations in scope include operators of essential services, managed service providers, data centres, and designated critical suppliers. A public GRC profile signals to regulators that governance is active and evidenced.
DORA became fully enforceable across the EU in January 2025. It requires financial entities to ensure that their critical ICT third-party providers maintain defined security and resilience controls.
Procurement teams at EU financial institutions now ask ICT providers for evidence of resilience standards before contracts are signed. A public GRC profile, with a strong score in Operational Resilience, is direct evidence.
The UK Sustainability Reporting Standards (UK SRS) were published on 25 February 2026. They require organisations to describe governance structures, risk management processes, and board oversight of material risks in clear, public language.
Investors and lenders now depend on reliable governance data to meet their own reporting obligations. A public GRC profile provides exactly the kind of structured governance evidence that UK SRS requires companies to produce and disclose.
Third-party risk is now a boardroom topic for enterprise buyers. According to Verizon's 2026 Data Breach Investigations Report, 48 per cent of breaches involve a third party. That figure was 30 per cent the prior year.
Procurement teams are responding. GRC maturity is increasingly a contractual prerequisite. Questionnaire fatigue is driving buyers toward standardised, publicly accessible evidence. A public GRC profile answers the due diligence question before it is asked.
Your public GRC profile serves four distinct audiences. Each has a different reason for needing your GRC data.
Each audience has different questions. Your public GRC profile answers all of them with a single, structured source of verified evidence.
Organisations with verified, publicly accessible GRC evidence have a measurable advantage in competitive procurement. Here is why.
Enterprise buyers spend significant time chasing security questionnaires, compliance declarations, and audit reports from vendors. Most of this information is requested, received, filed, and never properly scored.
A public GRC profile replaces that process with a single, standardised, independently verified reference. Procurement teams spend less time gathering evidence. Your organisation moves through due diligence faster.
Most organisations competing for the same contracts do not have a scored, independently verified GRC profile. They have internal policies and, if they are ahead of the pack, an ISO 27001 certificate.
A public GRC profile shows maturity across six domains. It goes beyond information security to cover governance, risk, compliance, resilience, and third-party risk. That breadth is a differentiator most competitors cannot match.
Trust is the foundation of long-term business relationships. Clients who can see your governance maturity score, and watch it improve over time, develop confidence that you are a stable, well-managed supplier.
A public GRC profile that is updated annually turns a one-time compliance exercise into a continuous trust signal. That is a commercial asset with compounding value.
Faster procurement: Pre-answers due diligence questions before buyers ask
Competitive edge: Evidences GRC maturity most competitors cannot demonstrate
Contract retention: Builds ongoing trust with clients who monitor supplier GRC
Tender scoring: Supports higher scores in public sector GRC and security criteria
Investor relations: Provides governance data required by UK SRS and ESG frameworks
A public GRC profile is not a regulatory certification. It does not replace ISO 27001, SOC 2, or ISAE 3402. What it does is provide the structured, scored evidence base that regulators expect to see behind formal certifications.
Think of it as the governance layer that sits above specific technical certifications. ISO 27001 evidences your information security controls. SOC 2 evidences your data and operational controls. A public GRC profile evidences the full governance, risk, and compliance framework that governs all of them.
Provision 29 (UK): Provides the evidential base for board declarations of control effectiveness.
DORA (EU): Operational Resilience domain score directly evidences ICT resilience standards.
NIS2 (EU): Information Security and Compliance domain scores support NIS2 alignment.
UK CSRB: Governance and Oversight scores demonstrate proactive risk accountability.
UK SRS / ESG: Governance domain provides structured board oversight data for public reporting.
FCA SMCR (UK): Creates an audit trail of governance accountability for named senior managers.
How does a public GRC profile compare to the compliance certificates organisations already pursue? The answer depends on what each one covers and what it signals to stakeholders.
The public GRC profile fills a gap that no existing certificate addresses: a comprehensive, publicly accessible, scored view of your entire governance, risk, and compliance position.
The assessment takes four to eight weeks from booking to report. Profile activation follows within days of score validation.
Organisations that complete annual benchmark updates maintain a live, improving GRC profile that stakeholders can rely on as a continuous governance signal.
Book a GRC benchmark today. Receive a scored report across six domains.
Publish your public GRC profile on grci.net.
Share your GRC badge in proposals, tenders, and investor packs.
Score: 0 to 100 | Maturity: 1 to 5 | RAG status per domain
Start at grci.net
A public GRC profile is a hosted, independently scored profile page on grci.net. It shows an organisation's GRC Index score, maturity level from 1 to 5, and domain breakdown across six areas: governance, risk, compliance, information security, operational resilience, and third-party risk. Clients, investors, and regulators can view it via a direct link. A shareable badge is also provided for proposals and procurement responses.
Multiple regulatory and commercial pressures make public GRC evidence essential in 2026. Provision 29 requires boards to declare material controls effectiveness publicly. DORA requires ICT providers to demonstrate resilience to EU financial entities. The UK Cyber Security and Resilience Bill extends penalties to up to 4 per cent of global turnover. Enterprise buyers increasingly use GRC maturity as a procurement filter. A public GRC profile addresses all of these requirements simultaneously.
ISO 27001 is a formal certification covering information security management. A public GRC profile covers the full governance, risk, and compliance landscape across six domains. It is faster to obtain than ISO 27001, provides a scored view rather than a binary pass or fail result, and is designed to be shared directly with any stakeholder as a real-time trust signal.
A public GRC profile on grci.net is accessible to anyone the organisation shares the link with. Enterprise clients can use it in procurement due diligence. Investors can review it as part of ESG or governance assessment. Regulators can reference it in supervisory reviews. The organisation controls whether to publish the profile openly or share it on a restricted basis.
The GRC Index benchmark assessment takes four to eight weeks from booking to final report. Once the assessment is complete and the score is validated, the public profile is activated on grci.net and a shareable badge is issued within days.
© 2025 GRC Index. All rights reserved.