[ GRC Agents ]

Best compliance MCP servers

Live listings that declare an MCP integration (servers or MCP-using compliance workflows).

Catalog data as of 2026-09-04. Page copy reviewed 2026-09-01. Next editorial review by 2026-10-01. Ordered by recency then name. No paid placement. 10 matched live listings.

The Model Context Protocol (MCP) is an open standard for exposing tools and data to AI agents over a defined interface, so a coding or compliance agent can call structured GRC functions instead of scraping a web app. A compliance MCP server typically surfaces controls, evidence, framework mappings, or policy context as callable tools. This shortlist shows live listings whose integrations field includes MCP, and that tag spans two roles: some products publish an MCP server you connect an agent to, while others are agents that consume MCP from elsewhere. It is still an early category, so the matched set is deliberately small and only some rows ship a published package today. Before treating a row as a server you can wire up, check its mcp_package and docs_url for a real npm package or endpoint, the transport and auth it expects, and which frameworks or data it exposes.

Who this is for. Agent builders, platform engineers, and GRC teams wiring compliance context into developer agents.

Eligibility. Included solely when a live listing tags integrations with MCP. Listings without that tag stay on other shortlists or the main directory. The tag does not guarantee a published npm MCP package or server vs client role.

How order works. Matched agents are filtered from the live catalog, then sorted by date_added (newest first) and name. Paid skip-the-queue fees buy publish timing, never rank or praise on this page. House products (Better ISMS) appear under the same rules with an ownership note. See /transparency.

Target query: best compliance MCP servers. Parent hub: /best. Full catalog: /directory.

Four MCP servers (Rules, Insights, Workflow, Assistant) that let AI agents create and execute compliance rules, query evidence and compliance posture, and build compliance workflows against the ComplianceCow platform.

evidencemonitoring

Enterprise MCP server from Comply that connects the ComplyAI financial-services compliance platform to AI tools, so authorized teams can build agentic workflows such as trade pre-clearances, policy guidance, and annual reviews.

policymonitoringaudit prep

Open-source MCP server from IBM that lets AI agents query and update IBM OpenPages GRC objects such as issues and controls over HTTP or stdio.

audit prepmonitoring

Hosted MCP server that exposes Secureframe compliance data as tools for AI assistants: controls, tests, vendors, frameworks, risks, and more.

monitoringevidencevendor riskSOC 2ISO 27001CMMC
open-source

Open-source compliance platform agent that handles requirements, docs, risks, controls, and evidence for SOC 2, GDPR, HIPAA, and ISO.

evidencepolicyaudit prepchat/tasksSOC 2GDPRHIPAA

Named GRC agent inside Vanta that drafts policies, checks evidence, answers questionnaires, and flags vendor risk.

policyevidencequestionnaire responsevendor riskSOC 2ISO 27001GDPR

General-purpose Anthropic Claude used via Skills/MCP for custom GRC workflows in enterprise teams.

chat/taskspolicyaudit prepISO 27001SOC 2GDPR

ISMS Copilot

Listed by Better ISMS (same rules as everyone)

SaaS

Compliance AI engine for 75+ frameworks. Chat, tasks, and account MCP so agents and practitioners run GRC work with an auditable trail.

chat/taskspolicyaudit prepISO 27001SOC 2GDPR

ISMS Copilot for Agents

Listed by Better ISMS (same rules as everyone)

SaaS

Account MCP + PAT so Claude Code, Cursor, and other agents use your ISMS Copilot workspace tools directly.

chat/taskspolicyISO 27001SOC 2GDPR

ISMS Directory MCP

Listed by Better ISMS (same rules as everyone)

open-source

MCP server that lets agents search a curated directory of human GRC services and submit listings.

chat/tasksISO 27001SOC 2GDPR