About
One practitioner, one thesis: GRC should be engineered, not performed. This page covers who writes this site, what it is, and the rules it is edited by.
Who writes this
Ayoub Fandi is a GRC engineer who does the work he writes about. He is a co-author of the GRC Engineering Manifesto, the document that codified the discipline's principles, and he currently runs GRC Engineering at Lovable, one of the fastest-growing software companies in history. Before that, he started the GRC engineering program at GitLab, where the bottom-up, telemetry-first approach this site argues for was tested against a real enterprise program for over four years.
On top of the day job, he publishes and produces:
- The GRC Engineer newsletter: weekly issues read by roughly 3,500 subscribers, including GRC leaders at the world's best companies.
- The GRC Engineering Podcast: now in season 3, with guests ranging from CISOs rebuilding programs from scratch to founders building the next generation of tooling.
- The State of GRC 2026 report: an independent industry survey with 795 respondents, published free at /report.
The through line is one thesis, argued from evidence: GRC programs should work bottom-up from control reality and telemetry, not top-down from frameworks. Not policy-as-code. Policy from code. If that framing is new to you, what is GRC engineering is the long-form answer, and the GRC engineer role covers what it means as a job.
What this site is
The GRC Engineer is the publishing arm of that thesis, and it is built like the thing it advocates: a versioned body of work, not a content feed. The site ships as releases, 73 and counting, one per week. The full corpus is browsable in the changelog, and the Workshop Terminal on the homepage is the front door to all of it: newsletter issues, podcast episodes, the study guide, the persona quiz, and the report.
The corpus is the point. Individual issues argue one idea each; together they form a documented, internally consistent position on how GRC programs should be designed, staffed, measured, and automated. When two issues disagree, the newer one says so and links the older one. That is what a changelog is for.
Editorial principles
- Real numbers only. Subscriber counts, survey sample sizes, open rates: if a number appears on this site, it is a real one. No inflated reach claims, no invented benchmarks, no salary figures pulled from thin air.
- Practitioner first. Everything published here is grounded in work actually done inside real programs, currently at Lovable, previously at GitLab. If the author has not done it or interviewed someone who has, it does not ship as advice.
- No vendor fluff. Sponsors are clearly labeled and never get editorial control. Tool coverage is based on what tools actually do, not what their category page claims. Criticism of the industry status quo is the product, not a risk to it.
Contact
The fastest way to reach Ayoub is LinkedIn, where the spicier takes live between newsletter issues.
For sponsorships: [email protected]. The newsletter reaches a highly engaged, senior GRC audience; real engagement numbers are shared with serious inquiries, per the editorial principles above.