Blog

Frequently Asked Questions from Customers

HelmGuard Team

Blog

Frequently Asked Questions from Customers

HelmGuard Team

In this article

No headings found on page

Request a demo

By clicking the submit button, you agree to HelmGuards' Privacy Policy

Request a demo

By clicking the submit button, you agree to Helmguards' Privacy Policy

Introduction

This FAQ answers the questions that risk, compliance and security leaders most often ask when evaluating HelmGuard: what our AI agents do, how they keep your team in control, how we protect your data and how our AI agents support audit & regulatory scrutiny.

What is Agentic GRC (Governance Risk & Compliance)?

Agentic GRC uses AI Agents to execute risk, compliance and security work, and not simply assist people with it.

HelmGuard is an Agent-native GRC platform designed from the ground up around Agents that can understand context and evidence, assess risk, execute work, take actions and escalate exceptions within defined boundaries.

What is an AI Agent?

An AI agent is software that's given and executes a goal rather than a way of outlining a process that you need to follow. An AI agent plans the steps itself, uses tools and data to carry them out, checks the results and keeps going until the job is done. It hands over to a person when it needs help with a decision. A chatbot answers questions; an agent does the work.

For example, an ERM agent asked to keep the risk register current might watch incident logs, audit findings, regulatory changes and news, then link each new signal to the risks and controls it affects. If a risk looks outside appetite, it drafts an updated rating with the evidence cited and sends it to the risk owner to approve.

What is the difference between an Agentic GRC platform vs a legacy GRC platform with AI bolted on?

Traditional GRC platforms such as Archer, MetricStream and Vanta are typically built around a system-of-record paradigm: Data Capture (via forms) → Review & Approval Workflow → Reporting. AI is then added to individual steps as a feature, such as summarisation, recommendations or copilot, which is an AI you can talk to to get answers about the data in the system.

An AI-native, Agentic GRC architecture is fundamentally different and has a system-of-action paradigm:

Context → Agent → Tools → Actions → Evidence → Outcome:

  • Context — The Agent brings together the information required to understand the task: policies, regulations, controls, risks, contracts, assessments, internal data and external signals. Rather than working from a single form or record, it can build a broader picture of the situation.

  • Agent — The Agent interprets the context, determines what needs to be done and decides how to progress the task based on defined objectives, policies and guardrails. It can reason across multiple sources rather than simply following a predefined workflow.

  • Tools — The Agent can access the tools and systems it needs to perform the work, such as GRC data, document repositories, email, security platforms, regulatory sources or third-party systems. Tools give the Agent the ability to interact with the business rather than simply generate text.

  • Actions — The Agent can then execute the required work: request evidence, analyse documents, assess controls, update records, create actions, escalate issues, trigger workflows or initiate remediation. Actions can be subject to approval depending on their risk and impact.

  • Evidence — Every action should produce an auditable trail of what was done, why it was done and what information supported the decision. This creates evidence of the work performed, rather than simply recording that a workflow step was completed.

  • Outcome — The process ultimately delivers a tangible GRC outcome: a completed assessment, validated control, remediated issue, updated risk position, compliance evidence or management decision.

The key difference is that the Agent is not simply assisting a human within a workflow. It can move from understanding the context, through reasoning and tool use, to executing work and producing an auditable outcome. This is what turns AI from a feature within GRC into an active execution layer for GRC.

Why shouldn’t we build our own Agentic GRC system, specific to our needs?

You can absolutely build an individual Agent if your internal IT team has the expertise and bandwidth to develop and support it.

The bigger question is whether you want to take on the job of building and maintaining a GRC platform — and, increasingly, an AI platform.

The visible AI is the easy part. The hard part is everything required to make it enterprise-grade and fit for purpose: integrations, permissions, evidence management, workflows, audit trails, security, governance, data controls, model management and continuous maintenance.

And then there is the challenge of keeping up with the frontier models themselves. There is no single “best” AI model. A model from OpenAI may outperform a Claude model on one GRC task, while another model may be better on a different task — and the balance of quality, speed and cost is constantly changing.

To know which models are genuinely best for GRC, you need comprehensive evaluations based on real GRC tasks, measuring accuracy, reasoning quality, consistency, speed and cost. You also need to evaluate whether the Agent's outputs are sufficiently reliable and explainable to support defensible risk and compliance decisions.

This is an area where HelmGuard has invested significant resources. We have built our own evaluations and tested multiple providers and models across GRC use cases. As a result, we don't rely on a single model — we use the best model for the job, balancing quality, speed and cost.

But model selection is only part of the challenge. In GRC, getting the answer is not enough. You need to be able to defend the decision. That means being able to understand what the Agent knew, what evidence it considered, how it reached its conclusion, what action it took, and where human accountability sits.

If you build internally, you inherit that entire R&D and governance burden. And it doesn't end when you launch your first Agent. You have to maintain the platform, evaluate new models, manage changing AI capabilities, update integrations and ensure decisions remain secure, auditable and defensible as the technology evolves.

You also create key-person dependency, fragmented processes and an AI system that your own Security, Risk, Audit and Regulatory teams will eventually need to scrutinise and govern.

With HelmGuard, you get the platform, controls, integrations, evaluations and AI infrastructure already built — and continuously evolving. You retain the flexibility to configure Agents around your specific processes, data and requirements, while maintaining the governance and evidence needed for defensible decision-making.

How autonomous are the Agents?

You control the level of autonomy. Agents can assist, recommend, execute with approval, or execute autonomously, depending on the activity and your risk appetite.

You define what each Agent can access, decide, change, execute and escalate. High-impact or sensitive actions can require human approval, while lower-risk activities can run autonomously.

This means autonomy is controlled, configurable and appropriate to the task — not all-or-nothing.

Can we test Agents before giving them autonomy?

Yes. Agents can initially operate in a lower-autonomy mode where outputs are reviewed by people before actions are executed.

As confidence grows and Agents prove themselves reliable and accurate, organisations can progressively move through different levels of Agent autonomy.

1. Human-in-the-loop - AI recommends, human decides

The Agent can do a lot of the work — gather information, analyse evidence, make a recommendation — but it stops and asks a person before taking the important action.

Example: An Agent reviews a supplier and recommends: “High risk — additional security evidence required.” A TPRM manager reviews the evidence and approves before the assessment is updated.

2. Human-on-the-loop — AI acts, human supervises

The Agent can act without asking permission every time, but a human is watching and sets the rules and monitors what the Agent is doing. The Agent can take routine actions itself, but people can intervene when something unusual or important happens.

Example: An Agent continuously monitors suppliers and automatically updates low-risk information. If it detects a significant change — such as a serious security issue — it alerts the TPRM team and stops for review.

3. Controlled autonomy — AI acts independently, but within rules set by humans

The Agent is trusted to make and execute decisions within clearly defined boundaries. The human decides what the Agent is allowed to do, what it isn't allowed to do, and when it must escalate.

Example: An Agent can independently assess supplier evidence, update an assessment, request missing information and raise findings. But it cannot change the organisation's risk appetite, override a material risk decision or approve a high-risk supplier.

Every action is recorded so you can see what it did, why it did it and what evidence it used.

Not every decision needs the same level of human involvement. Agents can have more freedom for low-risk, repeatable tasks and more human oversight where decisions could materially affect the business and judgment is required.

How do we, our auditors and our regulators know we can trust an Agent?

HelmGuard Agents operate within defined permissions, decision boundaries and human-approval controls. Every material action is audited and traceable back to the evidence, reasoning and instructions that led to it. For every Agent activity, you can understand:

What it was asked to do
→ The objective, instructions and policies governing the Agent.

What it knew
→ The data, documents, systems and evidence available to it at the time.

What it found
→ The relevant facts, evidence, gaps, inconsistencies and exceptions it identified.

What it concluded
→ The assessment or recommendation it produced and the basis for that conclusion.

What it did
→ The actions it took, systems it interacted with and outputs it created.

Why it did it
→ The rules, policies, instructions and evidence that drove the action.

What evidence supported it
→ The underlying source material, with provenance and citations where applicable.

What it was allowed to do
→ The permissions and autonomy boundaries governing the Agent.

Where a human was involved
→ Decisions requiring review, approval, challenge or escalation, including who approved them.

What changed as a result
→ The resulting updates, actions, exceptions and remediation activities.

This creates a traceable chain from evidence → assessment → decision → action → outcome, giving business users, risk owners, auditors and regulators visibility into how Agentic GRC work was performed.

The Agent can execute the work, but accountability remains with the organisation and its people.

What happens when an Agent is unsure?

It doesn't have to guess.

Agents can request more information, flag uncertainty, escalate to a human or stop pending approval.

Do Agents replace people?

No. Agents replace manual work, not people.

Agents handle repetitive, administrative and evidence-heavy tasks, making the Risk, Compliance and Security operating model more efficient and effective. This allows GRC professionals to spend more time on strategy, judgement, material risk decisions and remediation.

For example, in Risk Management, an Agent can gather KRIs and risk data from different systems, analyse changes, prepare a risk assessment and highlight areas that may require attention. The Risk Manager can then focus on understanding what has changed, challenging the analysis, deciding whether the risk is acceptable and determining what action the business should take.

For business users, Agentic GRC reduces the “homework” involved in risk and compliance — gathering information, preparing assessments and managing follow-up actions, so they can spend less time on administration and more time applying their business judgement.

The goal is not to remove people from the process. It is to give them more time to focus on the work that requires human judgement, accountability and decision-making.

Can an Agent change our risk and compliance methodology or thresholds?

No. Risk methodologies, assessment criteria, thresholds and decision rules remain controlled by authorised users.

Agents can apply those rules and, where configured, recommend changes. They do not independently redefine the organisation's risk framework.

Can Agents create or change risks, controls and issues?

They can, where explicitly configured and authorised.

For example, an Agent could identify a potential issue and automatically create it when confidence exceeds a defined threshold. Lower-confidence cases can instead be routed to a human for review.

Material changes to risk status, severity or other controlled information require human approval.

Does HelmGuard replace our existing GRC platform?

It can, but not necessarily.

HelmGuard can work autonomously as a standalone fully functioning GRC solution or in concert with your existing systems and information sources, allowing Agents to perform work across the enterprise rather than creating another silo.

How is HelmGuard priced?

HelmGuard uses a platform fee + usage pricing model. Usage is measured in AI Workloads—essentially, a request submitted to an AI model and the response returned—so pricing scales with the amount and complexity of work the platform performs, rather than the number of users or modules. 

We can also offer a fixed-price initial period for larger engagements, allowing us to establish actual usage together before agreeing the ongoing usage commitment. This reduces uncertainty and ensures the commercial model remains aligned with the value and workload HelmGuard delivers to you as a customer.

Your platform fee typically includes the cost for implementing the platform specifically to your requirements during onboarding as well as ongoing technical support.