GRC Oversight

Live demoFictional sample data. Nothing is saved.

Sign up

12Compliance

Risk Register

Identify risks, score them on a 5x5 likelihood x impact grid, and track residual risk after mitigating controls. Read-only auditors see the register but cannot edit it.

Likelihood x Impact (inherent)

Impact 551011512025
4481211620
33619112115
2246810
112345
Likelihood 12345
Low (1-4)Medium (5-9)High (10-15)Critical (16-25)

Risks (6)

  • Unauthorized access to production database

    MITIGATED

    Overly broad IAM roles could allow lateral movement into prod data stores.

    Inherent: 15 (HIGH)Residual: 5 (MEDIUM)auto↓ reduced by 10

    Mitigation: Least-privilege IAM roles enforced; access reviewed quarterly (CC6.1, CC6.3).

  • Vendor SOC 2 bridge letter missing

    IDENTIFIED

    Key subprocessor's SOC 2 report lapsed; bridge letter not yet obtained.

    Inherent: 12 (HIGH)Residual: not assessed
  • Endpoint disk encryption gap

    MITIGATED

    One device group below target for full-disk encryption enrollment.

    Inherent: 6 (MEDIUM)Residual: 2 (LOW)manual↓ reduced by 4

    Mitigation: MDM policy pushed; remaining devices remediating this week.

  • Single point of failure in on-call rotation

    ACCEPTED

    Incident response relies on one engineer for a critical subsystem.

    Inherent: 9 (MEDIUM)Residual: not assessed
  • Customer data exported to unmanaged laptop

    MITIGATED

    Support workflow allowed a CSV export to a personal device before DLP rollout.

    Inherent: 10 (HIGH)Residual: 4 (LOW)auto↓ reduced by 6

    Mitigation: DLP policy blocks unmanaged-device exports; incident closed (CC7.4).

  • Third-party analytics SDK over-collects PII

    TRANSFERRED

    Mobile SDK captures device identifiers beyond documented scope.

    Inherent: 12 (HIGH)Residual: 4 (LOW)manual↓ reduced by 8

    Mitigation: Contractual DPA amendment signed; SDK config scoped down.