grc-manifest.org v1.0 · August 2026 · Draft · DE

An adaptation for German-speaking Europe

From GRC to Resilience

Organizations exist to fulfill a purpose. Security, risk management and compliance are support functions of that purpose, not the other way around.

00 Preamble

That purpose is rarely only economic. Companies carry jobs, and jobs carry people and families. Entire industries carry the supply of what people need to live: energy, water, health, finance, communication, public administration. Whoever attacks an organization does not hit a legal entity. They hit the people who depend on it.

Security is therefore a fundamental right. Germany's Federal Constitutional Court has named it: a fundamental right to the confidentiality and integrity of information technology systems. We read it more broadly: Every organization that serves a societal purpose must be able to exercise this right, which means being able to defend itself and to operate securely. That is not an optional extra and not a cost factor. It is the precondition for fulfilling the purpose at all.

Today's model of governance, risk and compliance has drifted away from this task. It collects evidence instead of producing security. It documents processes instead of understanding them. It creates dependencies instead of building capabilities. In German-speaking Europe, this model meets a regulatory density that structurally overwhelms it.

This manifesto names where the current model fails and what we stand for instead. It is deliberately written as a counter-position. Its goal is not a new extreme but a middle path that holds.

I What we observe

01

The threat accelerates, the defense stays on an annual cycle.

Artificial intelligence drastically shortens the time between vulnerability and attack. The defense still organizes itself in audit cycles, annual reports and periodic reviews. Whoever assesses risks once a year assesses risks that no longer exist.

02

Risk is thought in silos.

Data protection, information security, supplier risk, occupational and environmental safety, enterprise risk, quality management: each discipline looks at risk with its own methods, on its own schedule. The result is not a complete picture but a patchwork of isolated views. Between the silos lie the risks nobody sees.

03

Processes are documented, not lived.

Process documentation is written once and is static from that moment on, while organizations are living systems that change constantly. Documented processes and actual work drift apart.

This is not a side issue. It is the foundation: processes map an organization's flow of information. Whoever does not know their processes cannot know their risks. And whoever does not know their risks is not resilient.

04

GRC has become an end in itself.

The term is ambiguous: financial risk for some, cyber security for others, compliance administration for a third group. What weighs heavier: GRC has turned from a serving support function into bureaucratic self-perpetuation in Max Weber's sense. An apparatus that leads a life of its own, shapes the organization around its needs and forgets whom it serves.

05

Regulation has overtaken the old model.

Until DORA, CRA and NIS2, the rule was: one standard, one certificate, one regulation. That time is over. Today so many legal acts apply at once that meeting one standard no longer means meeting one regulation. The energy sector shows it most clearly: IEC 62443, Section 8a of the German BSI Act with its audit requirements, ISO/IEC 27001 or IT-Grundschutz, NIS2 and the GDPR apply in parallel, each with its own evidence obligations, auditors and cycles. The consequence: ever more resources for a support function, without the organization fulfilling its purpose any better or more securely.

06

Compliance replaces security culture, and an industry lives off it.

A real security culture always produces compliance. Compliance does not always produce a real security culture. Everyone working in this field knows it, and it is knowingly accepted for lack of resources and for reasons of organizational politics.

Around this condition, an industry of promised cures has established itself and earns from it. Its business model is treating symptoms, not producing health: the patient is kept just healthy enough to reliably fall ill again. In medical terms: pathogenesis instead of salutogenesis.

07

Sovereignty is demanded, non-sovereignty is cultivated.

Digital sovereignty stays a slogan as long as it is only thought at the level of states, cloud providers and vendors. Where it would actually have to emerge, with the people inside the organizations, the opposite is systematically cultivated. Two dependency patterns shape the picture: public administration delegates the ability to understand its own processes, risks and systems to external consultants. And leadership decides on processes, tools and security far away from the people who do the actual work and truly know the flows of information.

Sovereignty that rests on the dependence of the non-sovereign is not sovereignty. It is a risk.

Every chain is as strong as its weakest link. Real digital sovereignty is therefore neither a procurement question nor a question of location. It is a question of capability at every level, and it grows from the inside out: sovereign individuals form sovereign teams, and only these form a sovereign, resilient organization.

08

The blind spot: communication and change.

Communication and change management are the mechanism through which enablement and cultural change happen at all. Exactly this exchange between roles, hierarchy levels and expert silos does not take place, although keeping the organization running is the shared interest of everyone involved. Without it, every principle stays on paper.

II What we stand for

We propose replacing the term GRC with Resilience. This connects to the lead term that NIS2, the EU's CER Directive and its national implementations already use.

Resilience means an organization's ability to fulfill its purpose under disruption, attack and change, and with it to protect the people who depend on that purpose. It covers the organization's physical and digital inside and outside world: the people, the way they work, and the information and devices they need for it.

Resilience bundles

resilience/
├── information-security
├── data-protection
├── artificial-intelligence
├── business-continuity
└── suppliers-and-third-parties

Stays corporate management

corporate-management/
├── enterprise-risk-management
├── corporate-governance
└── financial-and-legal-compliance

What Resilience does not claim

GRC has historically been broader than these five management systems. Enterprise risk management, corporate governance and financial and legal compliance are not devalued by this proposal. They change frames: they are instruments of corporate management and belong there, next to strategy and financial planning. Resilience replaces GRC where the operation of the organization is being protected, not where the company is being steered. Both fields share a common process and risk base, but they answer different questions: one asks whether the organization does the right thing, the other whether it can keep doing it under disruption.

Connecting to the BSI and public administration

Germany's IT-Grundschutz is the defining framework of its public administration, and it shows both faces of the old model: parts of its standards and modules read as if lawyers wrote them, not the people who run the systems. At the same time, with Grundschutz++ the German Federal Office for Information Security (BSI) is pushing toward machine-readable, automatable governance, exactly the direction of this manifesto.

We want this rethinking to take hold inside the BSI as well. Machine readability only lowers the burden of proof if it maps real processes and risks instead of forms. Otherwise Grundschutz++ becomes the next bureaucracy monster, this time automated. Public administration is not an edge case of this manifesto but a primary addressee: nowhere is the gap between demanded sovereignty and lived consultant dependence wider.

Our values

Through our work we have come to prefer one side over the other:

The second line of each pair has its value. We weight the first higher.

III Our principles

  1. Assess by risk and by relevance, do not collect periodically. Controls are checked continuously, on change, on events, or at justified intervals. The audit frequency follows the risk, not the calendar.
  2. Resilience starts at the beginning, not at the end. Security, privacy and risk requirements belong early in requirements, user stories, procurement, development and deployment, including CI/CD pipelines and change processes. Not in audit preparation. Shift left.
  3. Evidence comes from the work itself. It comes from execution and from reliable primary sources: automated where useful, machine-readable where possible. A screenshot is not proof of effectiveness.
  4. Comply once, prove many times. One shared process and control foundation is mapped onto all applicable regulations and standards, instead of running a separate evidence system per legal act. The only answer to regulatory density that scales.
  5. Living processes are the foundation. Processes are kept current by the people who run them. Risk and control assessment builds on real processes, not on documentation from three years ago.
  6. Threat-driven, not catalog-driven. Controls and risk assessments build on a current, fact-based understanding of the threats that matter. Standards are the starting point, not the finish line.
  7. Enable, do not create dependence. Knowledge is built inside the organization, not bought in. Operational staff shape their own work instead of executing someone else's instructions. External support is measured by whether it makes itself unnecessary.
  8. Security culture is the goal, compliance the result. We create the conditions under which secure collaboration emerges on its own, and then prove the compliance. Not the other way around.
  9. Communication and change are a discipline, not an afterthought. Change management and communication across levels, roles and silos are part of every resilience effort, with their own planning, their own owners and their own success criteria.
  10. The middle path is the goal. Between agile and classic approaches, between automation and judgment, between standard and context there is no black and white. We choose what holds in the organization at hand, including public administration, the energy sector and the Mittelstand.

IV Relationship to the GRC Engineering Manifesto

This manifesto is not a translation. It is a transfer of context. We share the core values of the international GRC Engineering Manifesto: continuous assurance, shift left, measurable outcomes over checkboxes, systems thinking, solutions that grow out of practice rather than off a vendor's drawing board. We oriented ourselves on it deliberately.

German-speaking and European organizations face two problems the international manifesto does not structurally cover: legally mandated multi-compliance, where compliance in the US context is market- and audit-driven, and cultivated non-sovereignty through consultant dependence and hierarchical decision paths.

That is why we extend the approach with sovereignty, living processes, change management and the deliberate middle path. And we replace the term GRC with Resilience, because it carries further in the European regulatory context. We understand this manifesto as a regional evolution that feeds back, not as a split.