The unit of delivery is a running program, not a report. A managed GRC provider takes over the recurring work a compliance program generates — administering the platform, keeping evidence current, maintaining policies, running access reviews, staging each audit, and fielding the auditor’s follow-ups — with named people accountable for every piece. Agency staffs the model with forward-deployed engineers who hold credentials in the client’s own tenant; the discipline being managed is GRC itself, and the leadership layer above it is typically a vCISO. What stays in-house is small but non-delegable: risk acceptance, scope decisions, and the signatures only an officer of the company can provide.
The category exists because the two older options leave a gap. A GRC platform subscription gives you excellent monitoring and a long to-do list; a consultant gives you advice about the list. Managed GRC is the third model: the provider works the list. The practical test when evaluating vendors is ownership — when a control fails the week before fieldwork, whose calendar does the fix land on? If the answer is still yours, you bought tooling or guidance, not management. Scope, staffing, and pricing for Agency’s version are laid out on the managed compliance services page.