img-our-grc-nightmares-blog1
  • GRC
  • 5th Aug 2025
  • 1 min read

Why GRC Teams Are Struggling in 2025

wiktoria_s
  • Written by
Wiktoria Strozik
View my profile on
In Short...
  • GRC confidence is high in 2025, with most organisations believing they are prepared for major risk or compliance events, but this confidence often masks underlying weaknesses.

 

  • Many teams still rely heavily on spreadsheets, disconnected tools, and manual workarounds, creating gaps between perceived control and real operational resilience.

 

  • Overstretched teams and critical skills shortages are common, particularly in mid-sized organisations where GRC responsibilities are often shared with non-specialists.

 

  • Fragmented tooling and slow, manual processes limit visibility, delay response times, and make it harder to demonstrate compliance consistently.

 

  • As regulatory pressure increases, these hidden challenges are becoming harder to ignore, exposing the growing gap between confidence and actual GRC capability.

 

  • The goal isn’t just to react to attacks, but to anticipate, prevent and minimise the impact of potential disruptions.

The Risk Reckoning: Why GRC Teams Are Still Struggling in 2025

Despite rising regulatory demands, growing cyber threats and increasing board-level scrutiny, many UK organisations continue to manage governance, risk and compliance (GRC) with outdated tools and manual processes. 

 

In our upcoming ‘Risk Reckoning’ report a 2025 maturity study based on insights from nearly 200 GRC leaders in both large enterprises and scaling organisations, confidence in preparedness sits at an all time.  

 

According to the report, 87% of enterprise executives and 95% of mid-sized GRC leaders believe they are ready to handle a major compliance or security event. 

 

However, the same research paints a more troubling picture beneath the surface.  

 

Their teams still rely on spreadsheets, disconnected systems, and informal, manual process.  

 

These limitations are especially seen in smaller organisations with limited resources and overstretched teams. The result is a widening gap between perceived control and actual operational resilience. 

The Four Hidden Challenges Facing GRC Teams

Across both enterprise and mid-market organisations, the research uncovers four main pain points across risk and compliance teams. 

1. Overstretched Teams

Whether it's a 5-person team managing a portfolio of frameworks or a lean function embedded within operations, GRC teams are being asked to do more with less. In small to mid-sized businesses, 84% of respondents cite limited capacity as the number-one challenge for completing risk assessments and audits on time. 

2. Critical Skills Gaps

Nearly 2/3rds of enterprise respondents report a lack of internal GRC expertise. In scaling organisations, the challenge is compounded by headcount limitations: GRC responsibilities are frequently assigned to operational or IT staff who lack specialist risk or compliance skills. As regulatory demands grow more complex, these hybrid roles struggle to maintain oversight, leading to reactive incident-driven managementand inconsistent controls. 

3. The Use of Inadequate Tools

Spreadsheets remain the primary tool for GRC in most organisations - 60% of enterprises still use them to some extent as part of their key workflows. Among mid-sized businesses, a higher 86% use spreadsheets, and for teams with fewer than five compliance professionals, that spreadsheet reliance is universal. 

 

These workflows are often held together with ad hoc task management methods like email chains, shared folders, and manual reporting. This creates fragmented records, and inconsistent audit trails, making it difficult to track accountability or demonstrate compliance. 

4. Processes Are Slow, Manual, and Inefficient

Evidence collection is still largely manual, reporting cycles are delayed, and risk assessments are often inconsistent. Even where GRC tools exist, they rarely work together. 62% of enterprise organisations use four or more GRC tools, but fewer than half have achieved integration, resulting in duplicated effort, gaps in oversight, and delays in responding to issues.  

 

Because of this, nearly half (49%) struggle to keep up with complex regulatory obligations. At the SMB level where manual methods are the highest, over a third have experienced a breach in the past 36 months, which is often the wake-up call to re-evaluate their GRC approach. 

What’s Driving Spreadsheet Reliance in GRC?

The research points to several underlying causes: 

 

• Cost and familiarity: Spreadsheets are free and easy to use, even if they’re not fit for modern compliance operations. 

 

• Lack of urgency: Many organisations only consider GRC upgrades after a breach, audit failure, or regulatory deadline. 

 

• Workaround culture: Particularly in mid-market teams, “just getting it done” is the default, even if it means bypassing formal process. 
The Risk Reckoning Starts Here

The data highlights a consistent pattern: overconfidence, manual processes, limited visibility, and a reliance on tools that were never designed for the scale or complexity of today’s GRC demands. Many teams continue to operate with resource and capacity constraints that leave little room for proactive risk management.

 

As regulatory pressure increases and expectations rise, these gaps are becoming more visible, presenting the result of overlooked decisions, outdated methods, and deferred improvements.

 

Recognising it is the first step toward closing the gap between confidence and capability.

Want to Learn More?

Based on a survey of 195 UK-based GRC leaders, including C-level executives from organisations ranging from 51 to over 1,000 employees, The Risk Reckoning offers a rare, side-by-side view of the operational challenges facing both enterprise and scaling teams.

 

Produced by SureCloud, the report reveals how high confidence in GRC programmes often masks persistent gaps in skills, tooling, and process maturity, highlighting a growing divide between expectations and real-world capability.

 

Close the Gap Between Confidence and Control

See how SureCloud helps GRC teams move beyond spreadsheets, so you can operate with confidence, not assumption.
Latest articles:
  • GRC

Our Upcoming GRC Events

  • Third-Party Risk Management

The Key Third-Party Risk Management Trends That Will Define 2026

  • Compliance Management

Why SOC 2 Needs a New Approach in 2026

Share this article

Related resources

img-resources-risk-reckoning
  • GRC
  • White Paper
The Risk Reckoning - Exclusive Industry Research report
AI in GRC Promise, Pitfalls and a Practical Path Forward Whitepaper
  • ISO 42001
  • White Paper
AI in GRC: Promise, Pitfalls, and a Practical Path Forward
Compliance_3
  • ISO 27001
  • Compliance
  • Third-Party Risk
  • Guide
Beginners Guide to ISO 27001
The Top 4 Challenges of Risk Management
  • Risk Management
  • Guide
Risk Registers Explained

“In SureCloud, we’re delighted to have a partner that shares in our values and vision.”

Read more on how Mollie achieved a data-driven approach to risk and compliance with SureCloud.

“In SureCloud, we’re delighted to have a partner that shares in our values and vision.”

Read more on how Mollie achieved a data-driven approach to risk and compliance with SureCloud.

“In SureCloud, we’re delighted to have a partner that shares in our values and vision.”

Read more on how Mollie achieved a data-driven approach to risk and compliance with SureCloud.

Vector
Reviews

Read Our G2 Reviews

4.5 out of 5

"Excellent GRC tooling and professional service"
The functionality within the platform is almost limitless. SureCloud support & project team are very professional and provide great...

Posted on
G2 - SureCloud

5 out of 5

"Great customer support"
The SureCloud team can't do enough to ensure that the software meets our organisation's requirements.

Posted on
G2 - SureCloud

4.5 out of 5

"Solid core product with friendly support team"
We use SureCloud for Risk Management and Control Compliance. The core product is strong, especially in validating data as it is...

Posted on
G2 - SureCloud

4.5 out of 5

"Excellent support team"
We've been happy with the product and the support and communication has been excellent throughout the migration and onboarding process.

Posted on
G2 - SureCloud