Knowledge BaseRisk Map Operating Model Templates Services About Work With Me
Templates & Tools

Stop Building From a Blank Page

Every template here was built for a real program, used in production, and refined through audits, board presentations, and live incidents. Download, customize, and deploy.

Best Value

Complete Template Bundle

All 12 tools, including the flagship Integrated Risk & Control Register, in one download. The complete toolkit for building or modernizing a GRC, resilience, or ERM program. Save $1,455 vs. buying individually.

  • ★ Integrated Risk & Control Register
  • Risk Register
  • Appetite & KRIs
  • Board Pack
  • BIA
  • BCP
  • Tabletop Playbook
  • Vendor Assessment
  • Control Framework Map
  • DORA Readiness
  • AI Governance
  • Operating Model Canvas
$2,497
one-time · instant download
Get the Bundle
Secure checkout via Gumroad
ERM Bundle

Score it, bound it, report it

Risk Register & Scoring Model + Risk Appetite & KRI Workbook + Board Risk Reporting Pack. The register produces the numbers, the appetite framework draws the lines, the board pack argues the decisions.

$597$847 bought individually, save $250
Get the ERM Bundle
Resilience Bundle

What's critical, how it recovers, prove it

Business Impact Analysis + Business Continuity Plan + Tabletop Exercise Playbook. The BIA ranks and flags the gaps, the BCP writes the recovery, the tabletop attacks it before an incident does.

$497$715 bought individually, save $218
Get the Resilience Bundle
Individual Templates

Pick What You Need

Every template is a standalone, production-ready document with instructions, examples, and customization notes.

Risk Register & Scoring Model

A quantitative register that calculates residual risk from control effectiveness instead of guessing it twice, inherent → controls → residual, with an auto-populated dashboard.

$299 one-time
  • 1–5 likelihood & 4-dimension impact scales with definitions
  • Inherent and residual composite scoring (L × max impact)
  • Dropdowns, validation, conditional formatting
  • Auto dashboard: 5×5 heat map, top risks, by category
  • Compliance mapping across 5 frameworks · 6-tab workbook
See Details or buy now →

Business Impact Analysis (BIA)

Score each process on five impact dimensions, derive a criticality tier, pair it with recovery objectives, and flag where capability can't meet the objective.

$259 one-time
  • 5-dimension impact scoring → Peak Criticality → Tier 1–4
  • MTD / RTO / RPO with tier-driven recovery expectations
  • Automatic recovery-gap flagging
  • Auto dashboard: criticality distribution, gaps, by department
  • ISO 22301 / NIST CSF / DORA / FFIEC mapping · 6-tab workbook
See Details or buy now →

Vendor Risk Assessment

Score vendors on exposure (data sensitivity × criticality) and security posture (6 weighted domains), tier them, and drive reassessment cadence, with BAA/DPA tracking for HIPAA.

$299 one-time
  • Exposure × posture → vendor risk score on a 1–25 scale
  • 6 weighted posture domains; automatic tiering
  • Reassessment-due & overdue flags by tier
  • BAA / DPA tracking for HIPAA programs
  • SOC 2 / ISO 27001 / HIPAA mapping · scorecard dashboard
See Details or buy now →

Unified Control Framework Mapping

One control library, cross-walked across SOC 2, ISO 27001, NIST CSF, DORA, and FFIEC, so you map once and maintain a single source of truth.

$299 one-time
  • 45 controls across 8 domains, in auditable language
  • Control-level citations (SOC 2 / ISO / NIST CSF 2.0 / DORA / FFIEC)
  • Preventive / detective / corrective typing
  • Formula-driven gap analysis with coverage % per framework
  • Evidence tracker with auto due dates & overdue flags
See Details or buy now →

GRC Operating Model Canvas

Define ownership, workflows, escalation paths, and governance structures that actually reflect how your org makes decisions.

$197 one-time
  • RACI template across the three lines
  • 3 workflow templates incl. the incident-to-risk feedback loop
  • Escalation thresholds tied to the 1–25 residual scale
  • Governance cadence planner with decision rights
  • Fully completed example (20 pages, Word + PDF)
See Details or buy now →

Tabletop Exercise Playbook

End-to-end tabletop exercise design, scenario library, facilitator guide, participant materials, and post-exercise reporting.

$197 one-time
  • 5 full scenarios with 6–8 timed injects each
  • Facilitator script, decision points, probing questions
  • Role cards for the full incident command structure
  • After-action report template with owned findings
  • One-page executive briefing template (32 pages, Word + PDF)
See Details or buy now →

Risk Appetite & KRI Workbook

An appetite statement with no number in it cannot be violated. Ceilings per domain on the 1–25 scale, KRIs with thresholds, and breach responses someone owns.

$299 one-time
  • Appetite statements with residual ceilings & OVER APPETITE flags
  • 200-row KRI register, green/amber/red both directions
  • Breach response & owner on every KRI
  • Staleness flags on unmeasured indicators
  • COSO ERM / ISO 31000 / NIST CSF GV / DORA mapping
See Details or buy now →

Board Risk Reporting Pack

A board report written to decide, not inform, every content slide ends in a DECISION strip, and the numbers trace to a data sheet a director can audit.

$249 one-time
  • 13-slide PowerPoint template with DECISION strips
  • Executive summary built on deltas and asks
  • Deep-dive format: story · evidence · trajectory · ask
  • Excel data sheet computes the deck tables from your register
  • Methodology appendix for the "why is this a 12?" question
See Details or buy now →

Business Continuity Plan Template

The BIA says what's critical; this plan says how it recovers, activation, incident command, tier-driven priorities, procedures, and communications.

$259 one-time
  • Severity-keyed activation with named authorities
  • Same six command roles as the Tabletop Playbook
  • Recovery priorities driven by the BIA's tiers
  • Per-process procedures + two completed examples
  • Holding statements for clients, regulators, press (30 pp, Word + PDF)
See Details or buy now →

DORA Readiness Assessment

DORA is an operating-model regulation, not an IT checklist. 62 plain-language requirements across the five pillars, owned across the organization.

$299 one-time
  • 62 requirements, article-cited, across all five pillars
  • Proportionality scoping with documented reasons
  • Per-pillar readiness %, Strong / Developing / At Risk
  • 200-row gap register with owners & overdue flags
  • Includes the Art. 28–30 register-of-information rows
See Details or buy now →

AI Governance Starter Kit

Your org is already using AI, the question is whether anyone is keeping score. Deterministic use-case scoring plus a policy people can actually follow.

$299 one-time
  • Use-case risk = autonomy × MAX(data sensitivity, decision impact)
  • OVERSIGHT GAP flags on High/Critical use cases
  • Band-driven review cadence with overdue flags
  • 10-page AI Acceptable Use Policy (Word + PDF)
  • NIST AI RMF / EU AI Act / ISO 42001 mapping
See Details or buy now →

Common Questions

What format are the templates?

The five workbooks are Excel (.xlsx), no macros, they recalculate on open, and they also open in Google Sheets and LibreOffice. The Operating Model Canvas and Tabletop Exercise Playbook are Word (.docx) with a PDF reference version. Everything ships with instructions and worked examples.

Are these frameworks for a specific industry?

They're built to be framework-flexible. Primary references are NIST CSF, ISO 27001, SOC 2, and DORA, but the structures work across financial services, technology, and enterprise organizations of any size.

Can I use these commercially with clients?

Yes. A single purchase includes a commercial license for use in your own consulting work. You cannot resell the templates as standalone products.

What if I need something customized?

If you need a template adapted for a specific framework, organization size, or regulatory requirement, get in touch. I offer advisory and customization engagements.