08 Build an Enterprise GRC Dashboard
Welcome to the eighth project in:
Module 11 — Enterprise GRC Transformation Project
In the previous projects, you built:
Enterprise Risk Assessment ↓Information SecurityManagement System ↓ISO 27001 Gap Assessment ↓SOC 2 Readiness Review ↓PCI DSS Assessment ↓Cloud Compliance Review ↓Enterprise ComplianceControl MatrixCloudNova now has:
Risks
Controls
Compliance Requirements
Evidence
Audit Findings
Exceptions
Remediation Plans
Third-Party Risks
Policies
AssessmentsBut management has a new problem:
Too MuchGRC DataExecutives do not need hundreds of spreadsheets.
They need:
DecisionIntelligenceYour assignment is to transform CloudNova’s GRC data into an:
EnterpriseGRC DashboardProject Objective
Section titled “Project Objective”Your objective is to move CloudNova from:
GRC Data ↓Spreadsheets ↓Reports ↓Manual Analysisto:
GRC Data ↓Metrics ↓KRIs / KPIs ↓Dashboards ↓Trends ↓Executive Insight ↓Management DecisionsThe dashboard should answer:
What Are OurBiggest Risks?
Are ControlsWorking?
Where Are WeNon-Compliant?
What FindingsAre Overdue?
Which VendorsCreate Risk?
Are RisksIncreasing?
Are RemediationPrograms Working?
Where DoesManagement Needto Act?Mission Information
Section titled “Mission Information”Project Type: Enterprise GRC Reporting & Analytics
Difficulty: Advanced
Estimated Time: 6–8 Hours
Primary Role: GRC Analyst / GRC Reporting Analyst
Supporting Roles: CISO / CRO / Compliance / Internal Audit / Risk Owners / Control Owners / TPRM / Privacy / Security Operations
Environment: Spreadsheet / BI Platform / GRC Platform / Reporting Platform
Deliverable: Enterprise GRC Executive Dashboard & Reporting Framework
Learning Objectives
Section titled “Learning Objectives”By completing this project, you will learn how to:
-
design an enterprise GRC dashboard.
-
identify executive GRC reporting requirements.
-
distinguish operational and executive reporting.
-
define GRC KPIs.
-
define GRC KRIs.
-
establish metric owners.
-
define thresholds and tolerances.
-
calculate risk exposure.
-
visualize enterprise risk.
-
report inherent and residual risk.
-
report control effectiveness.
-
report compliance coverage.
-
track evidence readiness.
-
report audit findings.
-
track remediation.
-
report policy compliance.
-
visualize exceptions.
-
report third-party risk.
-
identify overdue activities.
-
perform trend analysis.
-
identify risk concentration.
-
create executive risk summaries.
-
establish dashboard governance.
-
prevent misleading GRC metrics.
-
build continuous GRC reporting.
Scenario
Section titled “Scenario”CloudNova’s GRC team currently maintains:
Risk Register.xlsx
ISO27001.xlsx
SOC2.xlsx
PCI-DSS.xlsx
Cloud-Compliance.xlsx
Audit-Findings.xlsx
Vendor-Risk.xlsx
Exceptions.xlsx
Remediation.xlsxEvery month, analysts manually copy information into:
Executive-GRC-Report.pptxThe process takes:
3–5 DaysEvery MonthDifferent reports show different numbers.
The CISO asks:
How ManyCritical RisksDo We Have?Risk Management says:
7Compliance says:
11Internal Audit says:
9The problem is not visualization.
The problem is:
No SingleSource of TruthYour Mission
Section titled “Your Mission”Design CloudNova’s enterprise GRC reporting architecture.
Your dashboard must integrate:
Enterprise Risk
Controls
Compliance
Audit
Remediation
Exceptions
Third-Party Risk
Policies
KRIs
KPIsinto one management view.
Required Deliverables
Section titled “Required Deliverables”Create:
01 GRC Reporting Requirements
02 GRC Data Model
03 Metric Catalogue
04 KRI Register
05 KPI Register
06 Enterprise Risk Dashboard
07 Control Effectiveness Dashboard
08 Compliance Dashboard
09 Audit & Findings Dashboard
10 Remediation Dashboard
11 Third-Party Risk Dashboard
12 Exception Dashboard
13 Executive GRC Dashboard
14 Executive GRC Report
15 Dashboard Governance Standard
16 Continuous Reporting PlanPart 1 — Understand the Purpose of a GRC Dashboard
Section titled “Part 1 — Understand the Purpose of a GRC Dashboard”A dashboard is not:
A Collectionof ChartsA dashboard should support:
DecisionMakingEvery dashboard element should answer:
What DoesManagement Needto Know?and:
What DecisionMight ThisInformationTrigger?Part 2 — Start With the Audience
Section titled “Part 2 — Start With the Audience”Different audiences require different information.
Board ↓Strategic Risk
Executive Management ↓Enterprise Exposure
CISO / CRO ↓Risk & Control Health
GRC Team ↓Compliance Operations
Control Owners ↓Control Performance
Risk Owners ↓Risk TreatmentPart 3 — Executive vs Operational Dashboard
Section titled “Part 3 — Executive vs Operational Dashboard”An executive dashboard might show:
Top Enterprise Risks
Critical Findings
Risk Trend
Compliance Posture
Control Effectiveness
Major Vendor Risks
Overdue RemediationAn operational dashboard may show:
Evidence Requests
Control Tests
Assessment Tasks
Vendor Reviews
Policy Reviews
Exceptions
Tickets
Due DatesDo not mix everything into one screen.
Part 4 — Define Reporting Requirements
Section titled “Part 4 — Define Reporting Requirements”Interview:
Board
CEO
CISO
CRO
CIO
Compliance
Internal Audit
Risk Owners
Control OwnersAsk:
What DecisionsDo You Make?
What GRC InformationSupports Them?
How FrequentlyDo You Need It?
What ThresholdRequires Escalation?Part 5 — Build Reporting Requirements Register
Section titled “Part 5 — Build Reporting Requirements Register”Record:
| Requirement | Audience | Frequency | Owner |
|---|---|---|---|
| Top Enterprise Risks | Board | Quarterly | CRO |
| Critical Findings | CISO | Monthly | Audit |
| Control Effectiveness | CISO | Monthly | GRC |
| Compliance Status | Executive | Monthly | Compliance |
| Vendor Risk | Procurement | Monthly | TPRM |
Part 6 — Establish the GRC Data Model
Section titled “Part 6 — Establish the GRC Data Model”Before creating charts, define the relationships.
Business Service ↓Asset ↓Risk ↓Control ↓Requirement ↓Evidence ↓Test ↓Finding ↓RemediationAlso connect:
Vendor
Policy
Exception
Incident
OwnerPart 7 — Establish Unique IDs
Section titled “Part 7 — Establish Unique IDs”Use identifiers such as:
RISK-001
CTRL-IAM-003
FIND-027
EXC-012
TPRM-019
REM-044
KRI-007
KPI-014These allow records to be linked.
Part 8 — Establish Authoritative Sources
Section titled “Part 8 — Establish Authoritative Sources”Define which system owns each data type.
Example:
| Data | Authoritative Source |
|---|---|
| Enterprise Risks | Risk Register |
| Controls | Common Control Library |
| Findings | Audit Register |
| Vendors | TPRM Register |
| Remediation | Remediation Register |
| Exceptions | Exception Register |
Future state:
AuthoritativeData Sources ↓GRC Data Model ↓DashboardPart 9 — Data Quality Comes First
Section titled “Part 9 — Data Quality Comes First”A dashboard built on poor data produces:
BeautifulWrong AnswersValidate:
Completeness
Accuracy
Consistency
Timeliness
Ownership
UniquenessPart 10 — Define Metrics
Section titled “Part 10 — Define Metrics”A metric should contain:
Metric ID
Metric Name
Purpose
Formula
Source
Owner
Frequency
Threshold
Target
AudiencePart 11 — KPI vs KRI
Section titled “Part 11 — KPI vs KRI”A:
KPImeasures performance.
A:
KRIindicates risk exposure.
Example:
KPI
Critical VulnerabilitiesRemediated Within SLAversus:
KRI
Number ofOverdue CriticalVulnerabilitiesPart 12 — Example KPI Register
Section titled “Part 12 — Example KPI Register”| KPI | Target | Frequency |
|---|---|---|
| Controls Tested on Time | ≥95% | Monthly |
| Findings Closed Within SLA | ≥90% | Monthly |
| Vendor Reviews Completed | ≥95% | Monthly |
| Policy Reviews Completed | 100% | Quarterly |
Part 13 — Example KRI Register
Section titled “Part 13 — Example KRI Register”| KRI | Threshold | Direction |
|---|---|---|
| Critical Risks | >5 | Lower Better |
| Overdue Critical Findings | >0 | Lower Better |
| Privileged Accounts Without MFA | >0 | Lower Better |
| Critical Vendors Without Assessment | >0 | Lower Better |
Part 14 — Define Thresholds
Section titled “Part 14 — Define Thresholds”Avoid arbitrary:
Green
Amber
RedDefine measurable thresholds.
Example:
Critical FindingsOverdue
0→ Green
1–2→ Amber
3+→ RedPart 15 — Align Thresholds With Risk Appetite
Section titled “Part 15 — Align Thresholds With Risk Appetite”Thresholds should connect to:
Risk Appetite
Risk Tolerance
Control Expectations
Compliance Requirements
SLAPart 16 — Build Enterprise Risk Dashboard
Section titled “Part 16 — Build Enterprise Risk Dashboard”Start with:
Total Risks
Critical Risks
High Risks
Residual Risks
Accepted Risks
Overdue Treatments
Risk Trend
Top Risk DomainsPart 17 — Risk Heat Map
Section titled “Part 17 — Risk Heat Map”Use:
Likelihood ×ImpactExample:
IMPACT
1 2 3 4 5 ┌──────────────── 5 │ 4 │LIKELIHOOD 3 │ 2 │ 1 │Populate risks based on the approved enterprise methodology.
Part 18 — Show Inherent vs Residual Risk
Section titled “Part 18 — Show Inherent vs Residual Risk”For example:
RISK-001
Inherent:Critical
Controls ↓
Residual:MediumThis helps management understand:
ControlValuePart 19 — Risk Reduction
Section titled “Part 19 — Risk Reduction”Where the methodology supports it, compare:
Inherent Risk ↓Controls ↓Residual RiskDo not invent mathematically precise risk reduction percentages unless the underlying methodology supports them.
Part 20 — Show Risk Trend
Section titled “Part 20 — Show Risk Trend”Example:
Critical Risks
Q1 ████████ 8
Q2 ███████ 7
Q3 █████ 5
Q4 ████ 4Trend provides more information than a single number.
Part 21 — Top Enterprise Risks
Section titled “Part 21 — Top Enterprise Risks”Example:
| Risk | Residual | Trend | Owner |
|---|---|---|---|
| Ransomware | Critical | ↑ | CISO |
| Cloud Misconfiguration | High | → | Cloud |
| Third-Party Breach | High | ↑ | TPRM |
| Data Leakage | High | ↓ | CISO |
Part 22 — Add Risk Aging
Section titled “Part 22 — Add Risk Aging”Track:
Risk Created
Treatment Due
Days Open
Last Review
Next ReviewPart 23 — Risk Concentration
Section titled “Part 23 — Risk Concentration”Identify whether many high risks exist in:
Cloud
Identity
Third Parties
Applications
Data
Business UnitThis helps management allocate resources.
Part 24 — Build Control Effectiveness Dashboard
Section titled “Part 24 — Build Control Effectiveness Dashboard”Report:
Total Controls
Key Controls
Controls Tested
Effective
Partially Effective
Ineffective
Not Tested
Overdue TestsPart 25 — Example Control Dashboard
Section titled “Part 25 — Example Control Dashboard”CONTROL HEALTH
Enterprise Controls 142
Key Controls 47
Effective 119
Partially Effective 14
Ineffective 5
Not Assessed 4
Overdue Tests 7Part 26 — Control Effectiveness Percentage
Section titled “Part 26 — Control Effectiveness Percentage”A basic metric may be:
Effective Controls ÷Controls Tested ×100But always explain what is included in the denominator.
Part 27 — Report by Control Domain
Section titled “Part 27 — Report by Control Domain”| Domain | Effective | Partial | Failed |
|---|---|---|---|
| IAM | 91% | 7% | 2% |
| Network | 94% | 4% | 2% |
| Cloud | 81% | 12% | 7% |
| Logging | 88% | 8% | 4% |
| Privacy | 79% | 14% | 7% |
Part 28 — Identify High-Impact Failed Controls
Section titled “Part 28 — Identify High-Impact Failed Controls”Prioritize controls supporting:
Critical Risks
Multiple Frameworks
Critical Systems
Sensitive Data
Regulatory RequirementsPart 29 — Control Concentration
Section titled “Part 29 — Control Concentration”A failed control mapped to:
ISO 27001
SOC 2
PCI DSS
ISO 27017has broader impact than an isolated low-risk control.
Part 30 — Build Compliance Dashboard
Section titled “Part 30 — Build Compliance Dashboard”Report:
Applicable Frameworks
Requirements
Coverage
Control Effectiveness
Evidence Readiness
Open Gaps
Assessments
Certification / Audit DatesPart 31 — Framework Summary
Section titled “Part 31 — Framework Summary”Example:
| Framework | Coverage | Effective Controls | Open Gaps |
|---|---|---|---|
| ISO 27001 | 96% | 90% | 8 |
| SOC 2 | 95% | 91% | 6 |
| PCI DSS | 91% | 87% | 10 |
| ISO 27017 | 89% | 84% | 12 |
| ISO 27018 | 86% | 81% | 14 |
Part 32 — Separate Coverage From Compliance
Section titled “Part 32 — Separate Coverage From Compliance”Do not display:
ISO 2700196% Compliantwhen the metric actually means:
96% of ApplicableRequirements HaveMapped ControlsUse precise metric labels.
Part 33 — Evidence Readiness
Section titled “Part 33 — Evidence Readiness”Calculate:
EvidenceAvailable ÷EvidenceRequired ×100where the required evidence population is clearly defined.
Part 34 — Show Upcoming Assessments
Section titled “Part 34 — Show Upcoming Assessments”Example:
ISO Surveillance Audit42 Days
SOC 2 Evidence Freeze67 Days
PCI Assessment103 DaysThis allows proactive preparation.
Part 35 — Build Audit Dashboard
Section titled “Part 35 — Build Audit Dashboard”Track:
Audits
Findings
Severity
Owner
Age
Due Date
Status
Repeat FindingsPart 36 — Example Audit Dashboard
Section titled “Part 36 — Example Audit Dashboard”AUDIT & ASSURANCE
Open Findings 38
Critical 2
High 9
Overdue 11
Repeat Findings 4
Average Age 73 DaysPart 37 — Finding Aging
Section titled “Part 37 — Finding Aging”Use aging buckets:
0–30 Days
31–60 Days
61–90 Days
91–180 Days
180+ DaysPart 38 — Repeat Findings
Section titled “Part 38 — Repeat Findings”Repeat findings deserve special attention.
They may indicate:
Weak Root Cause Analysis
Poor Remediation
Management Inaction
Control Design Problems
Insufficient OwnershipPart 39 — Finding Trend
Section titled “Part 39 — Finding Trend”Track:
New Findings
Closed Findings
Reopened Findings
Overdue Findings
Repeat Findingsover time.
Part 40 — Build Remediation Dashboard
Section titled “Part 40 — Build Remediation Dashboard”Track:
Open Actions
Critical Actions
Overdue Actions
Due This Month
Completed
Awaiting Retest
Failed RetestPart 41 — Remediation Funnel
Section titled “Part 41 — Remediation Funnel”Finding ↓Action Created ↓Owner Assigned ↓Remediation ↓Evidence Submitted ↓Retest ↓ClosedPart 42 — Remediation Aging
Section titled “Part 42 — Remediation Aging”Measure:
Days Open
Days Overdue
Original Due Date
Revised Due Date
ExtensionsPart 43 — Watch Repeated Extensions
Section titled “Part 43 — Watch Repeated Extensions”Example:
Original Due:March
Extended:May
Extended:July
Extended:SeptemberThis should trigger management attention.
Part 44 — Remediation SLA
Section titled “Part 44 — Remediation SLA”Define expectations based on severity.
Example:
| Severity | Target |
|---|---|
| Critical | 30 Days |
| High | 60 Days |
| Medium | 90 Days |
| Low | 180 Days |
These are illustrative; CloudNova should define targets based on its risk model.
Part 45 — Remediation Performance KPI
Section titled “Part 45 — Remediation Performance KPI”Example:
Actions ClosedWithin SLA ÷Actions Closed ×100Part 46 — Root Cause Dashboard
Section titled “Part 46 — Root Cause Dashboard”Categorize findings by root cause:
Process
Technology
People
Governance
Training
Configuration
Ownership
ResourcesPart 47 — Why Root Cause Matters
Section titled “Part 47 — Why Root Cause Matters”If:
23 Findingsshare:
WeakAccess Governancemanagement should not fund:
23 SeparateFixesIt should address the:
SystemicRoot CausePart 48 — Build Exception Dashboard
Section titled “Part 48 — Build Exception Dashboard”Track:
Open Exceptions
Critical Exceptions
Expiring Soon
Expired
Compensating Controls
Unapproved ExceptionsPart 49 — Exception Aging
Section titled “Part 49 — Exception Aging”Example:
EXCEPTION HEALTH
Open 27
Expiring <30 Days 8
Expired 3
High Risk 5
Without CompensatingControls 2Part 50 — Exception Concentration
Section titled “Part 50 — Exception Concentration”Identify:
Which ControlsGenerate theMost Exceptions?Example:
MFA 11
Encryption 7
Patch SLA 5
Logging 4This may reveal unrealistic standards or weak implementation.
Part 51 — Build Third-Party Risk Dashboard
Section titled “Part 51 — Build Third-Party Risk Dashboard”Track:
Total Vendors
Critical Vendors
High-Risk Vendors
Assessments Due
Assessments Overdue
Open Findings
Expired Contracts
Missing Assurance
Vendor IncidentsPart 52 — Example TPRM Dashboard
Section titled “Part 52 — Example TPRM Dashboard”THIRD-PARTY RISK
Vendors 286
Critical 31
High Risk 42
Assessments Overdue 17
Critical VendorsWithout Current Review 3
Open Vendor Findings 28Part 53 — Vendor Risk Concentration
Section titled “Part 53 — Vendor Risk Concentration”Identify dependence on:
Cloud Providers
Identity Providers
Payment Providers
Managed Service Providers
Critical SaaSPart 54 — Fourth-Party Risk
Section titled “Part 54 — Fourth-Party Risk”Where relevant, understand:
CloudNova ↓Vendor ↓SubprocessorA critical service may depend on many external organizations.
Part 55 — Vendor Assurance Status
Section titled “Part 55 — Vendor Assurance Status”Report:
SOC Report
ISO Certification
Penetration Testing
Security Assessment
Privacy Review
Contract Review
BCP ReviewPart 56 — Policy Dashboard
Section titled “Part 56 — Policy Dashboard”Track:
Policies
Approved
Due for Review
Overdue Review
Exceptions
AcknowledgementsPart 57 — Example Policy Dashboard
Section titled “Part 57 — Example Policy Dashboard”POLICY GOVERNANCE
Policies 42
Current 36
Review Due 4
Overdue 2
Pending Approval 3Part 58 — Connect Policies to Controls
Section titled “Part 58 — Connect Policies to Controls”The dashboard should support:
Policy ↓Controls ↓Risks ↓FrameworksPart 59 — Build Executive Dashboard
Section titled “Part 59 — Build Executive Dashboard”The executive dashboard should not contain:
150 MetricsAim for:
CriticalDecision IndicatorsPart 60 — Executive Dashboard Structure
Section titled “Part 60 — Executive Dashboard Structure”A practical layout:
┌──────────────────────────────────────────┐│ ENTERPRISE GRC OVERVIEW │├───────────────┬───────────────┬──────────┤│ Critical Risk │ Control Health│ Findings │├───────────────┼───────────────┼──────────┤│ Compliance │ Remediation │ Vendors │├───────────────┴───────────────┴──────────┤│ Risk Trends │├──────────────────────────────────────────┤│ Management Attention Items │└──────────────────────────────────────────┘Part 61 — Executive Summary Metrics
Section titled “Part 61 — Executive Summary Metrics”Example:
ENTERPRISE GRC
Critical Risks 5
High Risks 17
Effective Key Controls 91%
Critical Findings 2
Overdue High Findings 7
Evidence Readiness 89%
Critical Vendor Risks 3
Expired Exceptions 2
Overdue Remediation 9Part 62 — Add Trends
Section titled “Part 62 — Add Trends”Instead of:
Critical Risks5show:
Critical Risks5↓ from 7Trend provides context.
Part 63 — Add Targets
Section titled “Part 63 — Add Targets”Example:
Control Effectiveness
Actual:91%
Target:95%
Status:Below TargetPart 64 — Add Risk Appetite
Section titled “Part 64 — Add Risk Appetite”Example:
Critical Risks
Actual:5
Tolerance:2
Status:OutsideRisk AppetitePart 65 — Management Attention Section
Section titled “Part 65 — Management Attention Section”Highlight only issues requiring decisions.
Example:
MANAGEMENT ATTENTION
01 Two critical IAM findings overdue.
02 Three critical vendors have incomplete assessments.
03 Cloud logging remediation is 45 days overdue.
04 Two risk exceptions expired.
05 Residual ransomware risk exceeds approved tolerance.Part 66 — Every Red Metric Needs a Path to Action
Section titled “Part 66 — Every Red Metric Needs a Path to Action”Bad dashboard:
Critical Risks5🔴Better:
Critical Risks5 ↓View Risks ↓Risk Owners ↓Treatment Plans ↓Due DatesPart 67 — Drill-Down Architecture
Section titled “Part 67 — Drill-Down Architecture”Design:
Executive Dashboard ↓Domain Dashboard ↓Register ↓Individual Record ↓EvidencePart 68 — Example Drill Down
Section titled “Part 68 — Example Drill Down”Control Health81% ↓Cloud Controls ↓Failed Controls ↓CLD-004Cloud Logging ↓Evidence ↓RemediationPart 69 — Dashboard Hierarchy
Section titled “Part 69 — Dashboard Hierarchy”Use:
Level 1Board
Level 2Executive
Level 3Management
Level 4Operational
Level 5Record / EvidencePart 70 — Board Reporting
Section titled “Part 70 — Board Reporting”Board-level reporting should focus on:
Strategic Risk
Risk Appetite
Major Incidents
Regulatory Exposure
Material Control Issues
Critical Third Parties
Cyber Resilience
Major InvestmentsPart 71 — Avoid Technical Detail at Board Level
Section titled “Part 71 — Avoid Technical Detail at Board Level”Avoid:
Security Groupsg-0845...Has Port22 OpenReport:
Cloud ExposureRisk ExceedsApproved TolerancePart 72 — CISO Dashboard
Section titled “Part 72 — CISO Dashboard”The CISO may require:
Enterprise Risk
Control Health
Security Findings
Compliance
Vulnerabilities
Cloud Risk
Third Parties
Exceptions
RemediationPart 73 — GRC Operations Dashboard
Section titled “Part 73 — GRC Operations Dashboard”GRC teams need:
Assessments Due
Control Tests Due
Evidence Requests
Policy Reviews
Vendor Reviews
Open Findings
Exceptions
Remediation TasksPart 74 — Control Owner Dashboard
Section titled “Part 74 — Control Owner Dashboard”Control owners need:
My Controls
Failed Controls
Evidence Due
Tests Due
Exceptions
RemediationPart 75 — Risk Owner Dashboard
Section titled “Part 75 — Risk Owner Dashboard”Risk owners need:
My Risks
Risk Rating
Treatment
Actions
Due Dates
KRIs
ExceptionsPart 76 — Metric Ownership
Section titled “Part 76 — Metric Ownership”Every metric needs:
OwnerThe owner is responsible for:
Definition
Data Source
Accuracy
Threshold
Review
EscalationPart 77 — Metric Catalogue
Section titled “Part 77 — Metric Catalogue”Example:
| Metric | Owner | Source | Frequency |
|---|---|---|---|
| Critical Risks | CRO | Risk Register | Monthly |
| Control Effectiveness | GRC | Control Tests | Monthly |
| Overdue Findings | Audit | Findings Register | Weekly |
| Vendor Reviews | TPRM | Vendor Register | Monthly |
Part 78 — Metric Definition
Section titled “Part 78 — Metric Definition”Do not define:
Open Findingswithout answering:
Does This IncludeLow Findings?
Vendor Findings?
Audit Findings?
Security Findings?
Past-Due Findings?
Accepted Findings?Part 79 — Metric Dictionary
Section titled “Part 79 — Metric Dictionary”For each metric document:
Name
Purpose
Definition
Formula
Numerator
Denominator
Exclusions
Data Source
Owner
Frequency
Target
Threshold
EscalationPart 80 — Data Freshness
Section titled “Part 80 — Data Freshness”Display:
Last UpdatedExample:
Risk DataUpdated:26 Aug 202618:00Part 81 — Different Data Frequencies
Section titled “Part 81 — Different Data Frequencies”Not all information updates equally.
SIEM→ Near Real-Time
Vulnerability Data→ Daily
Risk Register→ Monthly
Policy Review→ Quarterly / Annual
Board Reporting→ QuarterlyPart 82 — Dashboard Refresh Strategy
Section titled “Part 82 — Dashboard Refresh Strategy”Define:
Dataset
Source
Refresh Frequency
Owner
Failure Alert
Last Successful RefreshPart 83 — Data Validation
Section titled “Part 83 — Data Validation”Before publication:
Extract ↓Validate ↓Reconcile ↓Calculate ↓Review ↓PublishPart 84 — Reconciliation
Section titled “Part 84 — Reconciliation”Example:
Dashboard:37 Findings
Audit Register:38 FindingsDo not publish until the difference is understood.
Part 85 — Dashboard Governance
Section titled “Part 85 — Dashboard Governance”Create a:
GRC DashboardGovernance Standardcovering:
Metric Approval
Definitions
Data Sources
Ownership
Thresholds
Refresh
Access
Quality
Changes
RetentionPart 86 — Change Control
Section titled “Part 86 — Change Control”Dashboard metrics should not silently change.
Example:
Old Formula ↓Change Request ↓Impact Analysis ↓Approval ↓Version ↓New FormulaPart 87 — Maintain Metric Version
Section titled “Part 87 — Maintain Metric Version”Record:
Metric Version
Formula Version
Effective Date
Change
ApproverPart 88 — Dashboard Access Control
Section titled “Part 88 — Dashboard Access Control”Some GRC information may contain:
Sensitive Risks
Audit Findings
Vulnerabilities
Vendor Issues
Legal Matters
Personal DataApply:
Least PrivilegePart 89 — Dashboard Integrity
Section titled “Part 89 — Dashboard Integrity”Executives rely on dashboard data.
Therefore protect:
Source Data
Calculation Logic
Thresholds
Reports
Access
Change HistoryPart 90 — Auditability
Section titled “Part 90 — Auditability”You should be able to answer:
Where DidThis NumberCome From?For every metric.
Part 91 — Metric Lineage
Section titled “Part 91 — Metric Lineage”Example:
DashboardCritical Risks = 5 ↓Calculation ↓Risk Register ↓RISK-001RISK-017RISK-021RISK-044RISK-051Part 92 — Avoid Vanity Metrics
Section titled “Part 92 — Avoid Vanity Metrics”Weak:
Security PoliciesCreated:48Better:
Critical PoliciesCurrent:97%Even better:
Critical PoliciesOverdue:2Part 93 — Avoid Activity Metrics Only
Section titled “Part 93 — Avoid Activity Metrics Only”Weak:
10,000VulnerabilitiesScannedBetter:
CriticalVulnerabilitiesOverdue:8Part 94 — Outcome-Oriented Metrics
Section titled “Part 94 — Outcome-Oriented Metrics”Prefer:
Risk Reduced
Controls Effective
Findings Closed
Exposure Reduced
Compliance Gaps Closed
Exceptions Reducedover only:
Meetings Held
Reports Generated
Tickets CreatedPart 95 — Avoid False Precision
Section titled “Part 95 — Avoid False Precision”Risk is often based partly on judgment.
Avoid presenting:
Cyber Risk= 73.684%unless the methodology genuinely supports that precision.
Part 96 — Avoid Universal GRC Score
Section titled “Part 96 — Avoid Universal GRC Score”A single:
GRC Score82%can hide important issues.
For example:
Overall:82%
But:
Critical IAMControl FailedPrefer multiple meaningful indicators.
Part 97 — Use RAG Carefully
Section titled “Part 97 — Use RAG Carefully”GreenAmberRedis useful only when thresholds are clearly defined.
Do not allow:
AnalystFeels AmberPart 98 — Management Commentary
Section titled “Part 98 — Management Commentary”Metrics should be accompanied by concise analysis.
Example:
Critical risks decreasedfrom seven to five.
However, residualransomware risk remainsabove approved tolerancebecause two recoverycontrols are still underremediation.Part 99 — Add Forecasting
Section titled “Part 99 — Add Forecasting”Where sufficient data exists, ask:
At CurrentClosure Rate,
When WillBacklog ReachTarget?Part 100 — Example Remediation Forecast
Section titled “Part 100 — Example Remediation Forecast”Open Findings
Jan 54
Feb 49
Mar 44
Apr 38
May 34If new findings exceed closures:
BacklogIs GrowingPart 101 — Leading vs Lagging Indicators
Section titled “Part 101 — Leading vs Lagging Indicators”Lagging:
SecurityIncidentsLeading:
CriticalControl FailuresStrong dashboards use both.
Part 102 — Example Leading Indicators
Section titled “Part 102 — Example Leading Indicators”MFA Exceptions
Critical Patches Overdue
Control Tests Overdue
Expired Risk Exceptions
Vendor Assessments OverduePart 103 — Example Lagging Indicators
Section titled “Part 103 — Example Lagging Indicators”Security Incidents
Data Breaches
Audit Findings
Service Outages
Regulatory IssuesPart 104 — Risk Velocity
Section titled “Part 104 — Risk Velocity”Some risks develop faster than others.
Consider:
Risk Severity +Risk VelocityA rapidly developing high risk may require faster action.
Part 105 — Emerging Risks
Section titled “Part 105 — Emerging Risks”Include a section for:
EmergingRisksExamples:
AI Governance
New Regulation
Cloud Concentration
Supply Chain Risk
Geopolitical Risk
New Threat TechniquesPart 106 — Risk Appetite Dashboard
Section titled “Part 106 — Risk Appetite Dashboard”Show:
Risk Category
Appetite
Current Exposure
Tolerance
StatusExample:
| Category | Exposure | Tolerance | Status |
|---|---|---|---|
| Cybersecurity | High | Medium | Outside |
| Privacy | Medium | Medium | Within |
| Third Party | High | Medium | Outside |
Part 107 — Aggregate Carefully
Section titled “Part 107 — Aggregate Carefully”Do not simply:
AddRisk Scoresunless the risk methodology supports aggregation.
Focus on:
Distribution
Concentration
Trend
Tolerance
CriticalityPart 108 — Executive Reporting Narrative
Section titled “Part 108 — Executive Reporting Narrative”The dashboard tells:
WhatThe executive report explains:
Why+What NextPart 109 — Executive GRC Report Structure
Section titled “Part 109 — Executive GRC Report Structure”Create:
01 Executive Summary
02 Enterprise Risk
03 Risk Appetite
04 Control Effectiveness
05 Compliance
06 Audit & Findings
07 Third-Party Risk
08 Exceptions
09 Remediation
10 Emerging Risks
11 Management Decisions
12 Next-Period PrioritiesPart 110 — Management Decisions
Section titled “Part 110 — Management Decisions”Every report should clearly identify:
DecisionRequiredExamples:
Approve RiskTreatment Funding
Accept Residual Risk
Escalate Vendor
Approve Exception
Prioritize Remediation
Increase ResourcesPart 111 — Example Executive Narrative
Section titled “Part 111 — Example Executive Narrative”CloudNova currently hasfive critical enterprise risks,of which two exceed approvedrisk tolerance.
Control effectiveness improvedduring the quarter, but cloudlogging and privileged accessremain significant weaknesses.
Nine high-priority remediationactions are overdue.
Management attention is requiredfor IAM remediation, cloudlogging modernization andthree critical third-partyassessments.Part 112 — Dashboard Review Meeting
Section titled “Part 112 — Dashboard Review Meeting”Establish a recurring:
GRCManagement ReviewParticipants may include:
CISO
CRO
Compliance
Internal Audit
Security
Privacy
TPRM
Business Risk OwnersPart 113 — Review Agenda
Section titled “Part 113 — Review Agenda”Use:
Critical Risks
Risk Appetite Breaches
Failed Key Controls
Critical Findings
Overdue Remediation
Vendor Risks
Expired Exceptions
Compliance Deadlines
Emerging Risks
Management DecisionsPart 114 — Escalation Rules
Section titled “Part 114 — Escalation Rules”Define automatic escalation triggers.
Example:
Critical FindingOverdue ↓CISOCritical RiskOutside Tolerance ↓Executive RiskCommitteeCritical VendorAssessment Expired ↓TPRM+Business OwnerPart 115 — Continuous GRC Reporting
Section titled “Part 115 — Continuous GRC Reporting”Move from:
Quarter-EndSpreadsheetExercisetoward:
AuthoritativeData ↓Automated Collection ↓Validated Metrics ↓Dashboard ↓Alerts ↓Management ActionPart 116 — Automation Opportunities
Section titled “Part 116 — Automation Opportunities”Potential integrations include:
Identity Platform
Cloud Platforms
SIEM
Vulnerability Management
Endpoint Management
Ticketing
CMDB
Vendor Management
HR
GRC PlatformPart 117 — Example Automated Control Metric
Section titled “Part 117 — Example Automated Control Metric”Identity Platform ↓MFA Data ↓Daily Calculation ↓MFA Coverage ↓Threshold ↓Dashboard ↓AlertPart 118 — Example Automated Risk Signal
Section titled “Part 118 — Example Automated Risk Signal”VulnerabilityScanner ↓Critical VulnerabilityPast SLA ↓KRI ThresholdExceeded ↓Risk Dashboard ↓EscalationPart 119 — Future GRC Architecture
Section titled “Part 119 — Future GRC Architecture”CloudNova’s target architecture becomes:
Enterprise Systems ↓Security Systems ↓Business Systems ↓GRC Data Layer ↓RiskControlsComplianceAuditVendorsExceptions ↓Metrics Engine ↓KRIs / KPIs ↓Dashboards ↓Executive Reporting ↓Management DecisionsPart 120 — GRC Dashboard Maturity
Section titled “Part 120 — GRC Dashboard Maturity”Level 1 — Spreadsheet Reporting
Section titled “Level 1 — Spreadsheet Reporting”ManualReportsLevel 2 — Central Dashboard
Section titled “Level 2 — Central Dashboard”ConsolidatedReportingLevel 3 — Integrated GRC
Section titled “Level 3 — Integrated GRC”ConnectedRiskControlComplianceDataLevel 4 — Automated Reporting
Section titled “Level 4 — Automated Reporting”SystemIntegrations ↓AutomatedMetricsLevel 5 — Continuous Risk Intelligence
Section titled “Level 5 — Continuous Risk Intelligence”ContinuousSignals ↓Risk Indicators ↓Control Health ↓Thresholds ↓Alerts ↓ManagementActionPractical Assignment
Section titled “Practical Assignment”Build CloudNova’s Enterprise GRC Dashboard.
Task 1 — Define Dashboard Audiences
Section titled “Task 1 — Define Dashboard Audiences”Identify reporting needs for:
Board
Executive Management
CISO
GRC
Risk Owners
Control OwnersTask 2 — Build Reporting Requirements
Section titled “Task 2 — Build Reporting Requirements”Create at least:
20 ReportingRequirementsTask 3 — Create GRC Data Model
Section titled “Task 3 — Create GRC Data Model”Connect:
Risks
Controls
Requirements
Findings
Remediation
Vendors
Exceptions
PoliciesTask 4 — Build Metric Catalogue
Section titled “Task 4 — Build Metric Catalogue”Create at least:
30 EnterpriseGRC MetricsTask 5 — Define KRIs
Section titled “Task 5 — Define KRIs”Create at least:
10 Key RiskIndicatorswith:
Threshold
Owner
Source
Frequency
EscalationTask 6 — Define KPIs
Section titled “Task 6 — Define KPIs”Create at least:
10 Key PerformanceIndicatorsTask 7 — Build Enterprise Risk Dashboard
Section titled “Task 7 — Build Enterprise Risk Dashboard”Include:
Risk Distribution
Heat Map
Top Risks
Risk Trend
Risk Appetite
Risk Aging
Risk OwnersTask 8 — Build Control Dashboard
Section titled “Task 8 — Build Control Dashboard”Include:
Control Effectiveness
Failed Controls
Key Controls
Testing Status
Control Domains
Control TrendsTask 9 — Build Compliance Dashboard
Section titled “Task 9 — Build Compliance Dashboard”Include:
Framework Coverage
Control Effectiveness
Evidence Readiness
Open Gaps
Upcoming AssessmentsTask 10 — Build Audit Dashboard
Section titled “Task 10 — Build Audit Dashboard”Include:
Findings
Severity
Aging
Overdue
Repeat Findings
TrendTask 11 — Build Remediation Dashboard
Section titled “Task 11 — Build Remediation Dashboard”Include:
Open Actions
Overdue Actions
SLA
Aging
Retesting
Closure TrendTask 12 — Build Third-Party Dashboard
Section titled “Task 12 — Build Third-Party Dashboard”Include:
Critical Vendors
Risk Ratings
Assessments
Findings
Overdue Reviews
Assurance StatusTask 13 — Build Exception Dashboard
Section titled “Task 13 — Build Exception Dashboard”Include:
Open
Expired
Expiring
Risk
Control
Compensating ControlsTask 14 — Build Executive Dashboard
Section titled “Task 14 — Build Executive Dashboard”Limit the primary dashboard to approximately:
10–15Decision-RelevantIndicatorsTask 15 — Create Management Attention Section
Section titled “Task 15 — Create Management Attention Section”Identify:
Critical Issues
Risk Appetite Breaches
Overdue Actions
Failed Controls
Decisions RequiredTask 16 — Create Executive Report
Section titled “Task 16 — Create Executive Report”Prepare a concise:
Monthly orQuarterlyGRC ReportFinal Validation Checklist
Section titled “Final Validation Checklist”-
authoritative sources identified.
-
unique identifiers established.
-
data relationships defined.
-
data quality validated.
-
data ownership assigned.
-
refresh frequencies defined.
Metrics
Section titled “Metrics”-
metric catalogue created.
-
formulas documented.
-
owners assigned.
-
sources identified.
-
thresholds defined.
-
targets defined.
-
escalation rules established.
Risk Dashboard
Section titled “Risk Dashboard”-
inherent risk represented.
-
residual risk represented.
-
top risks identified.
-
trends shown.
-
risk appetite shown.
-
overdue treatments identified.
-
risk concentration analyzed.
Control Dashboard
Section titled “Control Dashboard”-
key controls identified.
-
effectiveness reported.
-
failed controls identified.
-
testing status reported.
-
trends reported.
-
domain analysis available.
Compliance
Section titled “Compliance”-
framework coverage reported.
-
coverage separated from compliance.
-
evidence readiness reported.
-
gaps reported.
-
upcoming assessments shown.
-
findings reported.
-
severity shown.
-
aging shown.
-
overdue findings identified.
-
repeat findings identified.
-
trends analyzed.
Remediation
Section titled “Remediation”-
actions tracked.
-
owners assigned.
-
SLA tracked.
-
overdue actions identified.
-
extensions monitored.
-
retesting tracked.
Third Parties
Section titled “Third Parties”-
critical vendors identified.
-
risk ratings reported.
-
assessments tracked.
-
overdue assessments identified.
-
findings tracked.
-
assurance tracked.
Exceptions
Section titled “Exceptions”-
open exceptions tracked.
-
expired exceptions identified.
-
upcoming expirations shown.
-
risk documented.
-
compensating controls identified.
Executive Reporting
Section titled “Executive Reporting”-
critical indicators selected.
-
trends included.
-
targets included.
-
risk appetite included.
-
management attention identified.
-
decisions required identified.
-
commentary included.
Governance
Section titled “Governance”-
metric definitions controlled.
-
dashboard changes governed.
-
access controlled.
-
metric lineage available.
-
dashboard quality reviewed.
-
refresh failures monitored.
Expected Project Folder
Section titled “Expected Project Folder”08 Build an Enterprise GRC Dashboard│├── 01 GRC Reporting Requirements├── 02 GRC Data Model├── 03 Metric Catalogue├── 04 KRI Register├── 05 KPI Register├── 06 Enterprise Risk Dashboard├── 07 Control Effectiveness Dashboard├── 08 Compliance Dashboard├── 09 Audit & Findings Dashboard├── 10 Remediation Dashboard├── 11 Third-Party Risk Dashboard├── 12 Exception Dashboard├── 13 Executive GRC Dashboard├── 14 Executive GRC Report├── 15 Dashboard Governance Standard└── 16 Continuous Reporting PlanSuccess Criteria
Section titled “Success Criteria”You successfully complete this project when you can move from:
EnterpriseGRC Data ↓ValidatedData ↓Metrics ↓KRIs / KPIs ↓Risk & ControlAnalysis ↓Dashboard ↓ExecutiveInsight ↓ManagementDecision ↓Actionand confidently answer:
What Are OurTop Risks?
Which RisksExceed Appetite?
Are OurKey ControlsWorking?
Where Are OurCompliance Gaps?
Which FindingsAre Critical?
What IsOverdue?
Which VendorsCreate SignificantRisk?
Which ExceptionsNeed Attention?
Is Our RiskExposure Improvingor Getting Worse?
Where DoesManagement Needto Act?Career Connection
Section titled “Career Connection”This project reflects work performed by:
GRC Analysts
Senior GRC Analysts
Enterprise RiskAnalysts
GRC Managers
Compliance Managers
Internal Auditors
GRC Architects
Security GovernanceProfessionals
Risk Managers
CISO OfficeProfessionalsA beginner may build:
Charts ↓DashboardA professional builds:
Business Question ↓Authoritative Data ↓Metric ↓Threshold ↓Trend ↓Risk Insight ↓DecisionThe key principle is:
A GRC DashboardIs Not AboutShowing More Data.
It Is AboutHelping ManagementMake BetterRisk Decisions.What’s Next?
Section titled “What’s Next?”➡️ Next: 09 — Conduct an Executive GRC Management Review
You have now built the reporting layer connecting:
Enterprise Risk ↓Controls ↓Compliance ↓Audit ↓Third Parties ↓Exceptions ↓Remediation ↓KRIs / KPIs ↓EnterpriseGRC DashboardBut a dashboard alone does not govern the organization.
Someone must:
Review
Challenge
Decide
Assign
Escalate
Accept
Fund
TrackThe next project moves you from:
GRCReportingto:
GRCGovernanceYou will conduct a simulated executive GRC management review where senior leadership evaluates:
Top Enterprise Risks
Risk Appetite Breaches
Failed Key Controls
Critical Findings
Compliance Exposure
Third-Party Risk
Exceptions
Overdue Remediation
Emerging Risksand converts those insights into:
Management Decisions ↓Accountable Owners ↓Target Dates ↓Risk Treatment ↓Follow-Up➡️ Next: 09 — Conduct an Executive GRC Management Review