Free tools, templates, and packs for Heads of Risk - from diagnosing your framework to building the business case and choosing the right platform. Built from doing the job, not describing it.
Rate your RCSA across five dimensions in 10 minutes. Get a maturity level per dimension and a written diagnosis of where the gaps are.
See the real three-year cost of a GRC tool, not the licence sticker price. Factor in implementation fees, internal admin time, and renewal uplift.
A fill-in-the-blanks pack to get budget approved. Problem statement, cost-of-inaction model, an objection-handling table by stakeholder, and a one-slide board summary.
The clauses that bite - auto-renewal windows, data-exit fees, weak SLAs, uncapped price uplifts. With the exact question to ask the vendor for each.
A weighted scoring grid to compare vendors side by side - UX, deployment speed, first-line adoption, reporting, price, and references. Score three tools, get a number.
The 15 questions that expose hidden fees, weak support, and renewal traps - with what a good answer versus an evasive one sounds like. Take it into the meeting.
A board-ready risk pack skeleton - one-page summary, heat map, top risks, and actions - annotated with what a NED actually reads versus what gets skipped.
The four structural decisions you cannot undo later, a sample taxonomy you can lift, and scoring calibration definitions - the genuinely hard part done for you.
Material control tagging explained plainly, a readiness tick-list against the requirement, and the evidence a board or regulator will expect to see.
A phased migration plan template, an honest view of what actually breaks (people, not data), and a realistic parallel-run timeline.
Take the RCSA Maturity Scorecard. In 10 minutes you'll know exactly where your framework stands and which of these tools will help you most.
Take the scorecard