Knowledge BaseRisk MapOperating Model TemplatesServices AboutWork With Me
The Reference Capability Model

The capabilities of running GRC & resilience, as one model.

Not a tool list, a capability map, in the spirit of a business capability model: what a GRC and resilience function must be able to do, from governance through detection, response, recovery, and assurance. Explore it below. It's opinionated and best-practice-aligned, and it's a starting point we shape to your organization, together.

Interactive · explore the capabilities

The PivotRisk GRC & Resilience Capability Model

Each box is a capability, something the function must be able to do. Click any one and the panel below fills with its best-practice alignment, the AI agent that operates it, its data flows, and ownership (RACI), all at once. Where PivotRisk ships a template for a capability, the panel links to it.

Click any capability to see its full profile below, definition, how it fits the model, best-practice alignment, AI agent, ownership (RACI), data flows, and related terms, and to spotlight how it connects. Switch to Data Flows to see the whole network at once. Boxes are colored by accountable owner.

Start here

Click a capability to inspect it

Pick any box above and this panel fills with its description, the template that implements it, best-practice frameworks, the AI agent that operates it, its data flows (click those to jump), and the full RACI, all at once. Clicking also spotlights how it connects to the rest of the model.

Built on the canon

Standards an architect will recognize

The capabilities are a synthesis of the frameworks that define good governance, risk, resilience, and service practice, so one model satisfies many of them at once.

OCEG GRC Capability Model COSO ERM ISO 31000 NIST CSF 2.0 (incl. Govern) ISO/IEC 27001:2022 ISO 22301 · ISO 22361 IIA Three Lines Model NIST SP 800-53 Unified Common Controls (UCF) · SCF ITIL 4 Google SRE · SLOs / Error Budgets NIST Privacy Framework · ISO 27701 NIST AI RMF · ISO 42001 ISO/IEC 27035 DORA · FFIEC · HIPAA
Why a model, not a checklist

Operating-model-led beats framework-led

Framework-led programs

Built around control catalogs. Compliance is the goal. Work flows to whoever is available. Escalation is ad hoc. Progress is measured by documentation completeness.

Operating model-led programs

Built around capabilities, ownership, and outcomes. Performance is the goal. Work has named owners and clear cadences. Escalation paths are defined and tested. Progress is measured by risk posture.

The four questions a good operating model answers, and how this model answers them

1

Who does what?

Named owners for every capability, shown as the owner colors and full RACI in the model above.

2

How does work flow between capabilities?

Defined handoffs so work doesn't fall through the seams, the Data Flows view above draws every one.

3

What does "done" look like?

Each capability defines outcomes, not just tasks, see its definition and how it fits when you click it.

4

How does the program learn and adapt?

Feedback loops keep it from becoming shelfware, Reporting flows back into the Operating Model.

Where it leads

The model is the foundation. Everything compounds on top.

🔗

Data flows

The connections between capabilities become live calculations, incidents driving likelihood, controls driving residual, issues degrading controls. Evidence in, ratings out.

🗂️

Taxonomy

A shared risk and control taxonomy lets every capability (and every template) speak the same language and roll up into one enterprise view.

🤖

AI agents

Once the model is connected, agents can operate it (re-rating risks, triaging findings, answering questionnaires) over a deterministic engine. How that works →

A starting point, not a finish line

My reference model → your operating model

Explore & adopt, free

  • Explore the full reference capability model on this page
  • Adopt any capability as a ready-made template
  • Read the thinking behind every part in the Knowledge Base
Browse the Templates

Customize together, engagement

  • Tailor the capabilities to your org, sector, and regulators
  • Wire the data flows and taxonomy to how you actually work
  • Design ownership (RACI), cadence, and the path to AI-enabled operations
Build your model with me →

Related Reading