THE RISK LIFECYCLE, DRAWN TO SPEC
Eight stages. Each one has a gate that must be satisfied before a risk advances — enforced by the platform, not by a reminder in someone’s calendar.
Fig. 1 — Risk lifecycle and stage gates
GATEOwner assigned
GATEInherent scored
GATEResidual scored
GATEActions logged
GATEUnder review
GATETreatment set
GATEGRC Manager
TERMINALRejection needs a comment
Inherent and residual carried separately, banded low through critical, plotted on a heat matrix the whole team reads the same way.
A structured questionnaire sets each vendor’s tier; the tier sets the reassessment interval. Overdue is computed, not remembered.
Locations, business units, solutions and processes reviewed against hosting, data, authentication, encryption and logging.
Vendor, service and assessment findings share a single working list, each with an owner and a due date, promotable to the register.
NIST CSF 2.0, SOC 2, HIPAA, ISO 27001, PCI-DSS v4.0, NIST 800-53, HITRUST, FedRAMP, CMMC, SWIFT CSP, NERC CIP, NIST AI RMF, CSA CCM.
Actor, role, timestamp and field-level diff on every change, written server-side from a verified session.