Every template here was built for a real program, used in production, and refined through audits, board presentations, and live incidents. Download, customize, and deploy.
All 12 tools, including the flagship Integrated Risk & Control Register, in one download. The complete toolkit for building or modernizing a GRC, resilience, or ERM program. Save $1,455 vs. buying individually.
Risk Register & Scoring Model + Risk Appetite & KRI Workbook + Board Risk Reporting Pack. The register produces the numbers, the appetite framework draws the lines, the board pack argues the decisions.
Business Impact Analysis + Business Continuity Plan + Tabletop Exercise Playbook. The BIA ranks and flags the gaps, the BCP writes the recovery, the tabletop attacks it before an incident does.
Every template is a standalone, production-ready document with instructions, examples, and customization notes.
Risks, Controls, Issues, Incidents, and Events in one Excel workbook that calculate each other, loss events drive likelihood and floor impact, controls drive residual, open findings degrade controls. The whole program, connected.
A quantitative register that calculates residual risk from control effectiveness instead of guessing it twice, inherent → controls → residual, with an auto-populated dashboard.
Score each process on five impact dimensions, derive a criticality tier, pair it with recovery objectives, and flag where capability can't meet the objective.
Score vendors on exposure (data sensitivity × criticality) and security posture (6 weighted domains), tier them, and drive reassessment cadence, with BAA/DPA tracking for HIPAA.
One control library, cross-walked across SOC 2, ISO 27001, NIST CSF, DORA, and FFIEC, so you map once and maintain a single source of truth.
Define ownership, workflows, escalation paths, and governance structures that actually reflect how your org makes decisions.
End-to-end tabletop exercise design, scenario library, facilitator guide, participant materials, and post-exercise reporting.
An appetite statement with no number in it cannot be violated. Ceilings per domain on the 1–25 scale, KRIs with thresholds, and breach responses someone owns.
A board report written to decide, not inform, every content slide ends in a DECISION strip, and the numbers trace to a data sheet a director can audit.
The BIA says what's critical; this plan says how it recovers, activation, incident command, tier-driven priorities, procedures, and communications.
DORA is an operating-model regulation, not an IT checklist. 62 plain-language requirements across the five pillars, owned across the organization.
Your org is already using AI, the question is whether anyone is keeping score. Deterministic use-case scoring plus a policy people can actually follow.
The five workbooks are Excel (.xlsx), no macros, they recalculate on open, and they also open in Google Sheets and LibreOffice. The Operating Model Canvas and Tabletop Exercise Playbook are Word (.docx) with a PDF reference version. Everything ships with instructions and worked examples.
They're built to be framework-flexible. Primary references are NIST CSF, ISO 27001, SOC 2, and DORA, but the structures work across financial services, technology, and enterprise organizations of any size.
Yes. A single purchase includes a commercial license for use in your own consulting work. You cannot resell the templates as standalone products.
If you need a template adapted for a specific framework, organization size, or regulatory requirement, get in touch. I offer advisory and customization engagements.