
What I value most is that Scrut keeps compliance running year-round, rather than in frantic bursts right before an audit. Once we connected our cloud and SaaS integrations, the automated tests began flagging misconfigurations as they occurred. We triage each failed test against the controls it impacts and then either remediate it or mark it as ignored with a recorded business justification. When the auditor reviews our work, that justification is already attached right next to the test, so we’re not stuck trying to recreate the reasoning later.
The MCP connector has also been an unexpected win. From our AI assistant, I can look up policies, evidence, and failed tests; upload evidence directly into the correct evidence task; and pull control context into client security questionnaires without constantly switching tabs. During our GDPR audit prep, we handled the gap assessment against the framework and a sweep for pending evidence mostly this way, and it took days off the overall effort. Uploading evidence is close to effortless now: files from our cloud accounts, policy PDFs, and screenshots shared by colleagues can go straight into the relevant evidence task.
Audit findings, the risk register, and CAPAs (corrective and preventive actions) all live in the same place as the controls. That setup makes it easy to trace a finding back to the controls it affects and then close it out with supporting evidence. Vendor risk assessments with Scrut Teammates have also given us a quick first pass on new vendors. Review collected by and hosted on G2.com.
Most of my frustration is with the MCP connector, which is the part of Scrut we rely on most. It reads data well, but it can barely write. Creating risks, logging CAPAs, updating audit findings, completing vendor assessments, and even ignoring tests still have to be done in the web app. That breaks AI-assisted workflows halfway through, and we end up falling back to browser automation, which is slow and brittle. If the connector supported write access for these objects, it would be far more useful.
The second issue is performance on bulk queries. When listing controls, tests, or evidence—and sometimes even when fetching a single long policy—the connector returns far more data than an AI client can handle in one go. Pagination, field selection, and summary views would address this. Document search through the connector also consistently fails to return vault documents. On top of that, the question-answering tool rarely finds an answer even when the information exists, seemingly because it only looks at one document at a time instead of searching across our whole library.
In the web app, closing an audit finding after it’s fixed takes more manual steps than it should. It would help if closure could be auto-suggested when the linked evidence is updated. The answer library also starts empty, and an easier way to seed it from questionnaires we’ve already completed would make the questionnaire features pay off sooner. Review collected by and hosted on G2.com.