GRC PLATFORMSHEET 1 OF 1

THE RISK LIFECYCLE, DRAWN TO SPEC

Governance is a workflow, so we built the workflow.

Eight stages. Each one has a gate that must be satisfied before a risk advances — enforced by the platform, not by a reminder in someone’s calendar.

Fig. 1 — Risk lifecycle and stage gates

1

Discovery

GATEOwner assigned

2

Analysis

GATEInherent scored

3

Mitigation Planning

GATEResidual scored

4

Risk Mitigation

GATEActions logged

5

Monitoring

GATEUnder review

6

Closure

GATETreatment set

7

Closure Validation

GATEGRC Manager

8

Closed

TERMINALRejection needs a comment

SPEC / SCORING

Likelihood × impact, 1–25

Inherent and residual carried separately, banded low through critical, plotted on a heat matrix the whole team reads the same way.

SPEC / THIRD PARTY

Cadence by criticality tier

A structured questionnaire sets each vendor’s tier; the tier sets the reassessment interval. Overdue is computed, not remembered.

SPEC / ASSESSMENTS

Internal subjects, same rigour

Locations, business units, solutions and processes reviewed against hosting, data, authentication, encryption and logging.

SPEC / FINDINGS

One queue, tracked to closure

Vendor, service and assessment findings share a single working list, each with an owner and a due date, promotable to the register.

SPEC / FRAMEWORKS

13 versioned frameworks

NIST CSF 2.0, SOC 2, HIPAA, ISO 27001, PCI-DSS v4.0, NIST 800-53, HITRUST, FedRAMP, CMMC, SWIFT CSP, NERC CIP, NIST AI RMF, CSA CCM.

SPEC / EVIDENCE

Append-only audit trail

Actor, role, timestamp and field-level diff on every change, written server-side from a verified session.

See the gates hold on your own risks.

Request a Demo