Risks, Controls, Issues, Incidents, and Events in one workbook that calculate each other. Loss events drive likelihood and floor impact with real net loss. Controls drive residual risk. Open findings degrade the controls they hit, automatically.
Most programs keep risks, controls, issues, incidents, and loss events in five disconnected spreadsheets. This workbook connects them: each entity feeds the others, so your risk ratings are conclusions drawn from evidence, not opinions waiting to be challenged.
Every number is a formula over your inputs, not a workshop opinion. Change an input and the ratings move. That's what makes the output defensible.
Inherent → controls → residual. Likelihood suggested from linked events; residual calculated from control effectiveness, with override.
A 30-control starter library typed P/D/C, cited to NIST CSF 2.0 / SOC 2 / ISO 27001 / CIS v8 / PCI DSS 4.0, with effectiveness that open issues degrade.
Findings sourced from Internal Audit, Regulatory Exam, Certification, linked to the control they affect.
Realized loss events on the Basel taxonomy: the seven event types, three loss dates, gross/recoveries/net loss, near-misses and boundary events. Count drives likelihood; net loss floors impact.
The operational-disruption record: outage, root cause, response. Each rolls up to the loss event it produced.
The junction linking risks to the controls mitigating them, the spine of the residual calculation.
Auto-populated: KPI cards, residual heat map, top risks, coverage gaps. Zero manual entry, board-ready.
Every rating is a transparent formula over your inputs, so it holds up when someone asks "why is this rated this way?"
Ratings trace back to the inputs that produced them, the audit story is built in, not reconstructed after the fact.
Controls carry NIST CSF 2.0, SOC 2, ISO 27001, CIS v8, and PCI DSS 4.0 citations, and a Compliance Mapping tab adds the DORA and FFIEC program view, the register doubles as evidence for the frameworks you're assessed against.
The thinking behind the model: The Connected GRC Model and How to Build a Risk Register That Calculates Residual Risk.
A single Microsoft Excel workbook (.xlsx). It recalculates on open, no macros, no add-ins, no subscription. Also opens in Google Sheets and LibreOffice.
No. You fill the shaded input cells; the white cells calculate. Dropdowns prevent bad entries, the Start Here tab walks you through it, and it ships with worked examples you delete before use.
Yes, internally or in client engagements. You can't resell the template itself as a template.
If you need it adapted to a specific framework, org size, or regulator, get in touch, customization and advisory are available.
One workbook. Risks, controls, issues, incidents, and loss events that finally talk to each other.