Writing a risk statement your board will actually act on
Move beyond likelihood × impact heatmaps. A repeatable pattern for decision-grade risk narratives that name the exposure, the owner and the required call.
Move beyond likelihood × impact heatmaps. A repeatable pattern for decision-grade risk narratives that name the exposure, the owner and the required call.
Written by Rahul Menon and pressure-tested on live grc engagements before publication, this blog is designed to move a programme forward the same week you open it.
Every section is annotated with the decision it should unblock, the owner it should sit with, and the evidence it should leave behind — so the artefact still holds up under audit twelve months later.
- Field-tested against real Stage 1 and Stage 2 audit findings
- Mapped to the controls and cadences the GRC faculty deploy in cohort work
- Editable, credit-line optional — use it inside your organisation without attribution
- Includes evidence pointers, owner fields and a first-90-days cadence
- Heads of GRC, CISOs, DPOs and internal audit leads
- Lead Implementers and Lead Auditors preparing for cert cycles
- Consulting teams standing up client programmes
Book a demo with the faculty who wrote this.
Walk through the blog with a MAST practitioner — mapped against your controls, your evidence and your next audit window.
GRC Operating Model — RACI, KPIs and committee charters
Editable charters, decision rights, KPI library and board reporting templates used by MAST faculty on live GRC build-outs.
Vendor risk assessment pack — tiered by criticality
Three-tier vendor questionnaire, scoring rubric, evidence request list and a board-ready third-party risk dashboard.
Third-party risk when your fourth party is an LLM
Vendor risk teams are being asked to assess AI subprocessors they cannot see. What good looks like — contracts, evidence and continuous monitoring.
