Skip to content

Lab 01 β€” Build GRC Dashboard

Modern GRC teams manage large amounts of information across:

Risk Registers
Control Libraries
Compliance Assessments
Internal Audits
Third-Party Assessments
Policy Exceptions
Security Findings
Remediation Plans
Continuous Compliance Monitoring

Raw GRC data alone does not help leadership make decisions.

In this lab, you will transform operational GRC data into an enterprise GRC dashboard that provides meaningful visibility into:

Enterprise Risk
↓
Risk Appetite
↓
Control Health
↓
Compliance
↓
Audit Findings
↓
Third-Party Risk
↓
Remediation
↓
Executive Decisions

This lab simulates work commonly performed by:

  • GRC Analysts

  • Cyber Risk Analysts

  • Compliance Analysts

  • Risk Managers

  • Security Governance Analysts

  • Internal Audit teams

  • GRC Platform Administrators

Field Details
Lab Type GRC Dashboard & Reporting
Primary Role GRC Analyst
Supporting Roles Risk Manager, Compliance Manager, Internal Audit, Security Governance
Difficulty Intermediate
Estimated Time 90–120 minutes
Environment Spreadsheet / GRC Platform Simulation
Primary Deliverable Enterprise GRC Dashboard
Secondary Deliverables Risk Register, Control Dashboard, Compliance Scorecard, Findings Tracker
Skills Practiced Risk Reporting, KRIs, KCIs, Compliance Metrics, Executive Reporting

You are working as a GRC Analyst at Meridian Digital Services.

Meridian operates:

Cloud Infrastructure
Customer SaaS Platforms
Corporate IT
Payment Processing
Third-Party SaaS Services
Remote Workforce

The organization maintains several compliance obligations, including:

ISO 27001
SOC 2
PCI DSS
Privacy Requirements
Internal Security Policies

Management currently receives separate spreadsheets from:

Risk Management
Cybersecurity
Compliance
Internal Audit
Vendor Risk
IT Operations

Leadership has identified a major problem.

There is no consolidated view showing:

Top Risks
Risk Appetite Breaches
Control Failures
Compliance Gaps
Audit Findings
Vendor Risk
Overdue Remediation

Your mission is to design an Enterprise GRC Dashboard.

By completing this lab, you will:

  1. Build a basic enterprise risk register.

  2. calculate inherent and residual risk.

  3. identify risk appetite breaches.

  4. create a risk heat map.

  5. build control-health metrics.

  6. create compliance scorecards.

  7. analyze audit findings.

  8. monitor finding aging.

  9. analyze third-party risk.

  10. define KRIs and KCIs.

  11. build remediation metrics.

  12. create executive-level GRC indicators.

  13. design an actionable enterprise GRC dashboard.

You will build the following reporting model:

ENTERPRISE GRC
β”‚
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ β”‚ β”‚
Risks Controls Compliance
β”‚ β”‚ β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ β”‚ β”‚
Audit Vendors Findings
β”‚ β”‚ β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚
Remediation
β”‚
↓
Executive Dashboard

You may perform this lab using:

Microsoft Excel
Google Sheets
LibreOffice Calc
GRC Platform Sandbox
Spreadsheet Application

For the lab, a spreadsheet is sufficient.

Create a workbook named:

Enterprise-GRC-Dashboard.xlsx

Create the following worksheets:

01 Executive Dashboard
02 Risk Register
03 Controls
04 Compliance
05 Audit Findings
06 Third-Party Risk
07 Remediation
08 Metrics

Open:

02 Risk Register

Create the following columns:

Field Purpose
Risk ID Unique identifier
Risk Risk scenario
Category Risk domain
Owner Accountable owner
Likelihood 1–5
Impact 1–5
Inherent Risk Likelihood Γ— Impact
Control Effectiveness Effective / Partial / Weak
Residual Likelihood 1–5
Residual Impact 1–5
Residual Risk Residual Likelihood Γ— Residual Impact
Risk Appetite Maximum acceptable risk
Status Within / Breach
Trend Increasing / Stable / Decreasing
Treatment Mitigate / Accept / Transfer / Avoid

Add the following scenarios.

ID Risk Category
R-001 Ransomware disrupts critical business services Cybersecurity
R-002 Cloud configuration exposes customer information Cloud
R-003 Critical vendor suffers security breach Third Party
R-004 Privileged account compromise Identity
R-005 Payment environment fails PCI requirements Compliance
R-006 Personal information processed unlawfully Privacy
R-007 Critical systems cannot recover within RTO Resilience
R-008 Critical vulnerabilities remain unpatched Vulnerability

Assign appropriate owners.

Example:

R-001 β†’ CISO
R-002 β†’ Cloud Security Manager
R-003 β†’ Third-Party Risk Manager
R-004 β†’ IAM Manager
R-005 β†’ Compliance Manager
R-006 β†’ Privacy Officer
R-007 β†’ IT Operations Manager
R-008 β†’ Vulnerability Management Lead

Use:

Inherent Risk
=
Likelihood Γ— Impact

Example:

Likelihood = 5
Impact = 5
Risk Score = 25

Use this scoring model:

Score Rating
1–4 Low
5–9 Medium
10–16 High
17–25 Critical

Example:

Ransomware
Likelihood = 5
Impact = 5
Inherent Risk = 25
Rating = Critical

Residual risk represents exposure after considering controls.

Example:

Ransomware
Inherent Risk
5 Γ— 5 = 25
Controls:
EDR
Backups
MFA
Network Segmentation
Security Monitoring
Residual Likelihood = 3
Residual Impact = 5
Residual Risk
3 Γ— 5 = 15

Therefore:

Inherent Risk = 25
Residual Risk = 15

Add an approved risk appetite value for every risk.

Example:

Risk Residual Risk Appetite
Ransomware 15 10
Cloud Exposure 12 9
Vendor Breach 12 10
Privileged Compromise 15 8
PCI Failure 10 8

Determine:

IF Residual Risk > Risk Appetite
THEN
Risk Appetite Breach

Otherwise:

Within Appetite

Your dashboard should clearly identify risks such as:

R-001
Residual Risk = 15
Appetite = 10
BREACH

and:

R-004
Residual Risk = 15
Appetite = 8
BREACH

Create a metric:

Risk Appetite Breaches

For each risk assign:

↑ Increasing
β†’ Stable
↓ Decreasing

Example:

Risk Residual Risk Trend
Ransomware 15 ↑
Cloud Exposure 12 β†’
Vendor Breach 12 ↑
Privileged Compromise 15 β†’
PCI Failure 10 ↓

This helps management understand not only:

Where Are We?

but:

Where Are We Going?

Create a:

5 Γ— 5

risk matrix.

Structure:

IMPACT
1 2 3 4 5
Likelihood 5 M H H C C
4 M M H H C
3 L M M H H
2 L L M M H
1 L L L M M

Plot each enterprise risk according to:

Residual Likelihood
Residual Impact

Example:

R-001
Likelihood = 3
Impact = 5

Place:

R-001

at:

Likelihood 3
Impact 5

Open:

03 Controls

Create:

Control ID Control Domain Owner Status KCI Target Current
IAM-001 Privileged MFA Identity IAM Effective MFA Coverage 100% 98%
VM-001 Vulnerability Remediation Security VM Team Partial Critical SLA 100% 92%
LOG-001 Centralized Logging Security SOC Effective Logging Coverage 100% 99%
ENC-001 Data Encryption Security Cloud Effective Encryption Coverage 100% 100%
BCP-001 Backup & Recovery Resilience IT Ops Partial Recovery Tests 100% 90%
IAM-002 Access Reviews Identity IAM Weak Review Completion 100% 75%

Use:

Healthy
Degraded
Failed

Example:

Privileged MFA
Target:
100%
Current:
98%
Status:
Degraded

Access Reviews:

Target:
100%
Current:
75%
Status:
Failed

Calculate:

Total Controls
Healthy Controls
Degraded Controls
Failed Controls

Example:

Total Controls 6
Healthy 2
Degraded 3
Failed 1

Open:

04 Compliance

Create:

Framework Applicable Controls Passing Failing Missing Evidence
ISO 27001 80 76 4 3
SOC 2 55 53 2 2
PCI DSS 60 56 4 5

Calculate:

Compliance %
=
Passing Controls
Γ·
Applicable Controls
Γ—
100

Example:

PCI DSS
56 Γ· 60 Γ— 100
= 93.3%

Add:

Active Exceptions
Expired Exceptions
Evidence Stale
Assessments Overdue

Example:

Framework Active Exceptions Expired Stale Evidence
ISO 27001 3 0 2
SOC 2 2 1 3
PCI DSS 5 1 4

Open:

05 Audit Findings

Create:

Finding ID Finding Severity Owner Open Date Due Date Status
F-001 MFA missing for privileged accounts Critical IAM 01-Jan 15-Jan Open
F-002 Vulnerabilities past SLA High Security 05-Jan 05-Feb Open
F-003 Access review incomplete High IAM 10-Jan 10-Feb Open
F-004 Backup recovery testing incomplete Medium IT Ops 15-Jan 15-Mar Open
F-005 Vendor assessment overdue High TPRM 20-Jan 20-Feb Open

Use:

Finding Age
=
Current Date
-
Open Date

Create aging buckets:

0–30 Days
31–60 Days
61–90 Days
91–180 Days
180+ Days

Use:

IF
Current Date > Due Date
AND
Status β‰  Closed
THEN
Overdue

Track:

Critical Overdue
High Overdue
Medium Overdue

Add:

Repeat Finding?

Values:

Yes
No

Repeat findings should receive special attention because they may indicate:

Weak Remediation
Poor Root Cause Analysis
Governance Failure
Management Inattention

Open:

06 Third-Party Risk

Create:

Vendor Criticality Inherent Risk Residual Risk Assessment Findings
Cloud Provider A Critical 20 10 Complete 1
Payment Provider B Critical 25 15 Complete 4
SaaS Provider C High 16 8 Overdue 2
Marketing Vendor D Medium 9 4 Complete 0
HR Platform E High 16 10 Due 1

Calculate:

Total Vendors
Critical Vendors
High-Risk Vendors
Assessments Overdue
Open Critical Findings

Flag vendors where:

Criticality = Critical

and:

Residual Risk β‰₯ High

Example:

Payment Provider B
Critical Vendor
+
Residual Risk = 15
+
4 Findings

This should appear prominently on the dashboard.

Open:

07 Remediation

Create:

Action ID Source Severity Owner Due Date Status Validation
A-001 F-001 Critical IAM 15-Jan In Progress Pending
A-002 F-002 High Security 05-Feb In Progress Pending
A-003 F-003 High IAM 10-Feb Blocked Pending
A-004 F-004 Medium IT Ops 15-Mar Complete Validated
A-005 Vendor B High TPRM 28-Feb In Progress Pending

Calculate:

Total Actions
Open Actions
Completed Actions
Overdue Actions
Blocked Actions
Critical Overdue Actions

Open:

08 Metrics

Create:

Metric Type Target Source Owner
Risk Appetite Breaches KRI 0 Risk Register CRO
Critical Findings Past SLA KRI 0 Audit GRC
Privileged MFA Coverage KCI 100% IAM IAM
Vulnerability SLA Compliance KCI 100% Scanner Security
Assessments Completed KPI 100% GRC Compliance
Vendor Assessments Overdue KRI 0 TPRM TPRM

For:

Privileged Accounts Without MFA

define:

0
=
Normal
1
=
Warning
>1
=
Critical

For:

Critical Findings Past SLA

define:

0
=
Normal
1
=
Warning
>1
=
Critical

Open:

01 Executive Dashboard

Create the following sections.

Display:

Critical Risks
High Risks
Risk Appetite Breaches
Risks Increasing

Example:

Critical Risks 3
High Risks 5
Risk Appetite Breaches 4
Risks Increasing 3

Display:

Healthy Controls
Degraded Controls
Failed Controls

Example:

Control Health
Healthy 65%
Degraded 25%
Failed 10%

Display:

ISO 27001
SOC 2
PCI DSS

Example:

ISO 27001 95%
SOC 2 96%
PCI DSS 93%

Do not treat these percentages as risk ratings.

Display:

Critical Findings
High Findings
Overdue Findings
Repeat Findings

Display:

Critical Vendors
High-Risk Vendors
Overdue Assessments
Critical Vendor Findings

Display:

Open Actions
Overdue Actions
Blocked Actions
Critical Overdue

Create:

Risk Residual Trend Appetite Owner
Ransomware 15 ↑ Breach CISO
Privileged Compromise 15 β†’ Breach IAM
Vendor Breach 12 ↑ Breach TPRM
Cloud Exposure 12 β†’ Breach Cloud

Create a section named:

Management Attention Required

Example:

1. Privileged MFA below target
2. Critical ransomware risk above appetite
3. Payment provider residual risk remains High
4. PCI DSS remediation overdue
5. Access review control failed

This is one of the most important dashboard sections.

A possible design:

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ ENTERPRISE GRC DASHBOARD β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ Critical β”‚ Appetite β”‚ Critical β”‚ High-Risk β”‚
β”‚ Risks β”‚ Breaches β”‚ Findings β”‚ Vendors β”‚
β”‚ 3 β”‚ 4 β”‚ 2 β”‚ 7 β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ β”‚
β”‚ RISK HEAT MAP β”‚
β”‚ β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ CONTROL HEALTH β”‚ COMPLIANCE β”‚
β”‚ β”‚ β”‚
β”‚ Healthy 65% β”‚ ISO 27001 95% β”‚
β”‚ Degraded 25% β”‚ SOC 2 96% β”‚
β”‚ Failed 10% β”‚ PCI DSS 93% β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ AUDIT FINDINGS β”‚ THIRD-PARTY RISK β”‚
β”‚ β”‚ β”‚
β”‚ Critical 2 β”‚ High Risk 7 β”‚
β”‚ High 8 β”‚ Overdue 5 β”‚
β”‚ Overdue 4 β”‚ Critical Issues 3 β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ MANAGEMENT ATTENTION REQUIRED β”‚
β”‚ β”‚
β”‚ β€’ Privileged MFA below target β”‚
β”‚ β€’ Ransomware risk above appetite β”‚
β”‚ β€’ Payment provider remediation overdue β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Create a chart using:

Month
Critical Risks
High Risks

Example dataset:

Month Critical High
Jan 2 8
Feb 2 7
Mar 3 7
Apr 3 6
May 4 5

Ask:

Is enterprise risk improving or deteriorating?

Create:

Aging Findings
0–30 20
31–60 14
61–90 8
91–180 5
180+ 3

Your dashboard should make:

180+ Day Findings

easy to identify.

Create:

Month Compliance
Jan 89%
Feb 91%
Mar 94%
Apr 96%
May 95%

Ask:

Why Did Compliance
Drop in May?

The dashboard should encourage investigation rather than simply displaying numbers.

Design your dashboard so that users conceptually move from:

Executive Dashboard
↓
Risk
↓
Control
↓
Finding
↓
Remediation

Example:

Cyber Risk
↓
Identity Risk
↓
IAM-001
↓
MFA Coverage 98%
↓
2 Admin Accounts
Without MFA
↓
A-001 Remediation

Before finalizing your dashboard, verify:

Are All Risks Owned?
Are Risk Scores Correct?
Are Appetite Breaches Correct?
Are Control Metrics Current?
Are Compliance Calculations Correct?
Are Findings Complete?
Are Due Dates Accurate?
Are Vendor Ratings Current?
Are Remediation Actions Linked?
Are Metrics Traceable?

Imagine presenting your dashboard to:

CEO
CRO
CISO
CIO
Compliance Officer

You have five minutes.

You should be able to explain:

Our Current Risk
What Changed
Where We Exceed Appetite
Where Controls Are Failing
What Compliance Gaps Matter
What Is Overdue
Who Owns Remediation
What Leadership Needs to Do

Your dashboard must include:

  • enterprise risk summary.

  • top risks.

  • risk heat map.

  • risk trends.

  • risk appetite breaches.

  • control-health summary.

  • compliance scorecard.

  • audit findings.

  • finding aging.

  • third-party risk.

  • remediation status.

  • KRIs.

  • KCIs.

  • management-attention section.

  • clear ownership.

  • actionable information.

  • risk register completed.

  • likelihood documented.

  • impact documented.

  • inherent risk calculated.

  • residual risk calculated.

  • appetite established.

  • appetite breaches identified.

  • trends assigned.

  • controls documented.

  • owners assigned.

  • KCIs defined.

  • targets defined.

  • current values recorded.

  • control health determined.

  • frameworks identified.

  • applicable controls documented.

  • passing controls recorded.

  • failing controls recorded.

  • evidence gaps recorded.

  • compliance percentages calculated.

  • findings documented.

  • severity assigned.

  • owners assigned.

  • due dates recorded.

  • aging calculated.

  • overdue findings identified.

  • repeat findings identified.

  • critical vendors identified.

  • inherent risk assessed.

  • residual risk assessed.

  • assessments tracked.

  • vendor findings monitored.

  • remediation actions documented.

  • owners assigned.

  • deadlines recorded.

  • overdue actions identified.

  • blocked actions identified.

  • validation status tracked.

  • executive metrics displayed.

  • top risks displayed.

  • trends displayed.

  • material exceptions highlighted.

  • management actions identified.

  • dashboard data validated.

At the end of this lab, you should have:

Enterprise-GRC-Dashboard.xlsx

containing:

01 Executive Dashboard
02 Risk Register
03 Controls
04 Compliance
05 Audit Findings
06 Third-Party Risk
07 Remediation
08 Metrics

Your portfolio deliverables should demonstrate:

Risk Register
+
Risk Heat Map
+
Control Health
+
Compliance Scorecard
+
Audit Dashboard
+
Vendor Risk
+
Remediation Tracking
+
Executive Dashboard

This lab develops practical skills in:

Enterprise Risk Reporting
GRC Analytics
Risk Appetite Monitoring
Control Monitoring
Compliance Reporting
Internal Audit Reporting
Third-Party Risk Reporting
Remediation Governance
KRI Development
KCI Development
Executive Communication

These skills are directly relevant to roles such as:

GRC Analyst
Cyber Risk Analyst
Compliance Analyst
Security Governance Analyst
Technology Risk Analyst
Third-Party Risk Analyst
GRC Consultant
Risk Manager

Before marking the lab complete, answer:

  1. Which enterprise risks currently exceed risk appetite?

  2. Which risk has the highest residual exposure?

  3. Which risks are increasing?

  4. Which controls are failing?

  5. Which KCI is furthest from its target?

  6. Which compliance framework has the largest gap?

  7. Which evidence is missing or stale?

  8. Which audit findings are overdue?

  9. Are any findings repeated?

  10. Which vendor represents the highest residual risk?

  11. Which vendor assessments are overdue?

  12. Which remediation actions are blocked?

  13. Which critical actions are overdue?

  14. What are the top three KRIs?

  15. What are the top three KCIs?

  16. Which issues require executive attention?

  17. Who owns each major issue?

  18. What should management prioritize first?

  19. Is enterprise risk improving or deteriorating?

  20. Can every dashboard metric be traced back to its source?

You have successfully completed the mission when you can move from:

Raw GRC Data

to:

Risk Information

and finally:

Management Decision

Your dashboard should allow a stakeholder to quickly answer:

What Is Our Risk?
What Is Getting Worse?
Where Are We
Outside Appetite?
Which Controls
Are Failing?
Where Are Our
Compliance Gaps?
What Is Overdue?
Who Owns It?
What Must
We Do Next?

That is the purpose of an enterprise GRC Dashboard.

➑️ Next: Lab 02 β€” Automate Compliance Reporting

In the next lab, you will move beyond manually consolidating GRC information and build an automated compliance reporting workflow.

You will work through:

Compliance Data Sources
↓
Automated Data Collection
↓
Control Mapping
↓
Evidence Collection
↓
Compliance Evaluation
↓
Exception Detection
↓
Reporting
↓
Management Dashboard

The objective is to understand how modern GRC teams reduce repetitive manual compliance work while maintaining reliable, traceable, and audit-ready evidence.

➑️ Next: Lab 02 β€” Automate Compliance Reporting