Disclaimer
Last updated: August 11, 2026
Educational Purpose
All content on Do GRC — including learning paths, hands-on modules, AI scenarios, and case studies — is provided strictly for educational and informational purposes. Nothing on this platform constitutes professional legal, audit, compliance, or regulatory advice.
You should always consult qualified professionals for advice specific to your organisation's compliance obligations and regulatory requirements.
No Guarantees
While we strive to provide accurate and up-to-date content, Do GRC makes no guarantees regarding:
- Specific career outcomes, job placements, or salary expectations.
- Passing professional certifications or examinations.
- Regulatory acceptance or audit readiness of any framework implementation.
- The completeness or accuracy of content at any given time.
GRC frameworks and regulations are subject to change. We update our content regularly but cannot guarantee it reflects the very latest revisions at all times.
AI-Generated Content (Unreviewed)
Every user-facing piece of content on Do GRC — including learning paths, rooms, case studies, questions, model answers, scenarios, role-play conversations, lab environments, and all of the games under /play/* — is generated by AI and has not been audited or fact-checked by a human GRC practitioner.
Because content is unreviewed, it may contain:
- Factual errors, inaccuracies, or outdated references.
- Hallucinated controls, clauses, or standards that do not actually exist.
- Misattributed framework names, control IDs, or regulatory citations.
- Oversimplifications that omit material nuance.
Treat everything on the site as a study aid only. Always verify against primary sources (NIST, ISO, the regulator's own publications, vendor documentation) before relying on any of it for real-world decisions.
Any internal automated or AI-based quality checks we perform on the content do not constitute a professional or independent audit and should not be treated as such.
AI Audit of Content
The readings, and the questions and answers, for our learning paths and case studies — together with the readings for our scenarios — have been AI-audited for accuracy, with flagged issues reviewed and corrected.
This audit was itself performed using AI. An AI audit is not a human or independent professional audit: it can miss errors, introduce new ones, and does not guarantee the accuracy, completeness, or currency of any content. Audited content should be treated the same way as the rest of the site — as a study aid to be verified against primary sources.
Lab environments are not covered by that audit at all. Nothing in a lab — the organisation, its evidence, the questions, the answer keys or the marking rubrics — has been audited by a human or put through the AI accuracy audit described above. Any automated consistency checks run over lab content during authoring verify internal coherence, not correctness, and are not a review of any kind.
A full human audit of the content has been considered, but at the scale of this platform it has been found to be unfeasible and not a sound business decision on cost grounds. Having qualified GRC practitioners manually review — and then continually re-review — the entire, ever-growing library of learning paths, case studies, scenarios, question banks and lab environments would be prohibitively expensive. The AI audit described above is the proportionate alternative we have adopted in its place, and it does not extend to the lab environments.
In addition, several features generate content dynamically, on the spot, at the moment you use them — including GRC Coach chat and AI-generated learning journeys, AI Check and AI Assist grading, Role Play, Exam Prep and Interview Prep, lab written-answer marking, the Resume Point Generator, Play Arcade rounds, text-to-speech, and the GRC Toolkit AI-fill helpers. This output does not exist until you request it, so by its nature it cannot be audited in advance and is not covered by any content audit.
AI-Powered Evaluation
Many features on Do GRC are powered by AI. Because an AI is grading AI-generated questions, both the question and the grading can be wrong. AI-powered features include:
- GRC Coach chat and AI-generated learning journeys.
- AI Check and AI Assist on case-study and scenario questions.
- Role Play conversational practice scenarios.
- Lab environment written-answer marking and its feedback.
- Exam Prep and Interview Prep question generation and grading.
- Resume Point Generator.
- Play Arcade AI-generated rounds and AI deep-dive explanations.
- Text-to-speech audio synthesis.
- GRC Toolkit AI-fill helpers across the risk, audit, compliance, vendor, threat, policy, business continuity, and board-reporting modules.
AI-generated feedback, scores, and model answers are provided for learning and practice purposes only. They do not constitute professional legal, audit, compliance, or risk management advice. See the Terms of Service (AI-Powered Features) for further detail on usage limits and liability, and AI Transparency for how AI output is labelled and how its provenance is recorded.
Lab Environments Are AI-Generated and Unreviewed
Everything in a lab environment is generated by AI and has not been reviewed, audited or fact-checked by a human GRC practitioner. That covers the whole of a lab, not only the parts you read:
- The organisation itself — its profile, structure, systems and staff.
- Every artefact of evidence — policies, registers, contracts, tickets, system and identity exports, org charts, diagrams and reports.
- The scenario briefs, the questions and the written prompts.
- The answer keys your structured answers are compared against, and the point values attached to them.
- The marking rubrics, and the AI marking of written answers and the feedback it returns.
The consequence is that a lab can mark you wrong when you are right, and right when you are wrong. An answer key may contain a hallucinated control reference, an incorrect finding, an unsound rating or a mapping that does not hold, and the feedback on a written answer may be confidently mistaken. Nothing in a lab — including a full score — is evidence that a judgement you made is professionally correct.
Treat lab environments as practice at reading evidence, not as an authority on what the right answer is. Verify any control, clause, framework reference or regulatory citation you take from a lab against primary sources before using it anywhere real.
Lab Environments Are Fiction
Every organisation in a lab environment is invented, and so is everything inside it. The companies, staff, customers, suppliers, systems, IP addresses, identifiers and dates were written for the exercise. Any resemblance to a real organisation or person is coincidental.
The evidence in a lab is written to look like the real thing, because reading real formats is the skill being taught. That includes documents modelled on assurance reports, contracts, banking agreements and regulatory correspondence. None of them is a genuine report, agreement or communication, none evidences any real organisation's controls, and none may be relied on or reused outside the exercise. Several contain deliberate errors, because finding them is the point.
The findings, ratings and control mappings in a lab reflect one defensible reading of invented evidence for teaching purposes. They are not professional audit, legal or compliance advice, and a mapping that fits a lab may not fit your organisation.
Third-Party References
Do GRC references third-party frameworks, standards, and tools (such as NIST CSF, ISO 27001, SOC 2, PCI DSS, and others) for educational context. These references do not imply endorsement, affiliation, or partnership with the respective organisations. Trademarks and framework names belong to their respective owners.
External Links
The platform may contain links to third-party websites or resources. We are not responsible for the content, accuracy, or practices of external sites. Visiting external links is at your own discretion and risk.
Non-Affiliation Notice
Do GRC is an independent project and is not affiliated with, endorsed by, or sponsored by TryHackMe or Hack The Box.
Contact
If you have questions about this disclaimer, please contact us at hello@dogrc.com.