← Back to directory

CISO Assistant

CISO Assistant · Compliance, Risk & Regulatory

MCP ServerVendor

Open-source GRC platform from intuitem that you self-host, mapping controls across frameworks including SOC 2, ISO 27001, NIST and DORA, with an MCP server so an assistant can query your risk assessments and compliance posture. The only entry in this category you can run without a vendor agreement.

GRCopen sourcesecurity
Status
Vendor
Auth
None
Hosting
Local
Community rating
Not rated yet
Role

Provides data. A read-only feed from one provider; it answers questions, doesn't act, and doesn't expect other servers alongside it. More on Source servers → All seven roles →

Open documentation →

Caveats

  • Self-hosted, so uptime, patching and access control are yours. The community edition also omits features found in the paid version.
  • Auth is listed as none because the server runs locally against your own instance. That means anything with local access reaches your full risk register, so do not expose it beyond your own machine or network.
  • Firm-as-a-company GRC. It tracks security frameworks, not adviser regulatory filings.
Rate this server

How to connect CISO Assistant

Step 1

Check the vendor's documentation

This listing does not publish a public endpoint or install command yet. Open the vendor documentation above for access details, then follow the general steps in our connection guide.

Step 2

Authenticate with no credentials

No credentials are required for public data. Rate limits still apply, so avoid bulk pulls from a chat client.

Step 3

Verify, then widen access

Restart your client, confirm the server's tools appear, and run one read-only question first. Keep client-side approval prompts on for any tool that can write, trade or send. Confirm with your firm's compliance policy before connecting systems holding client data.

Prompts that use this server

Starter prompts from the Practice Stacks that rely on Compliance, Risk & Regulatory.

Compliance history and diligence file

The regulatory record a buyer's counsel will request.

Sell / M&A ReadinessCompliance, Risk & RegulatoryAdvisor & Firm Intelligence / Prospecting

Read-only: assemble my firm's regulatory record from two directions, my internal compliance or GRC systems for what they actually hold (policy versions, control testing, vendor diligence, open findings and remediation status) and the public regulatory and firm-intelligence sources for registration history, ADV disclosures and complaints. Show them side by side and flag anything disclosed publicly with no internal record, or internally tracked that the public record does not reflect. List exam findings and correspondence separately as 'to gather offline' unless a connected system genuinely holds them. Cite each source and mark anything unverified as 'to confirm'. Do not file, submit or amend anything.

Guardrail · Read-only. The internal half of this record usually lives outside any connected tool, and filings are amended through official channels only.

Diligence readiness checklist

A gap list before you open a data room.

Sell / M&A ReadinessCRMCompliance, Risk & RegulatoryAccounting & Tax

Build a diligence readiness checklist across client, financial, custody and compliance records. For each item say whether it exists today, where it lives, and what work is needed. Use read-only access, keep client identities out of the output, and do not create or share a data room or upload any document.

Guardrail · Read-only. Never let a tool export client data to an external destination.

Annual compliance review prep

A gap list against your compliance calendar.

Compliance & Audit ReadinessCompliance, Risk & RegulatoryCRM

Read-only: review my annual compliance calendar against what my connected systems can actually evidence. Use the compliance or GRC platform for the items it genuinely holds, such as policy versions, control testing, vendor diligence and open findings, and use CRM for the client-facing items, disclosure delivery, agreement dates, suitability updates and contact records for the sample under review. List Item / Owner / Due / Status / Evidence location / Source tool, and mark any calendar item that no connected system covers as 'no connected source' rather than inferring its status. Do not mark anything complete, edit records or file anything.

Guardrail · Read-only. Most servers in this category cover firm security and GRC rather than adviser books and records, so expect gaps a person has to fill.

Read the full connection guide →