3 questions from the package
From the RFI round. The first shows part of the guide each question carries; the workbook adds follow-ups, how to verify the answer, a priority and a weight.
1. Does your risk register support a configurable risk taxonomy of [taxonomy depth] levels, with each risk assigned to a category in it?
Why it matters. If the taxonomy is fixed, the buyer must force its risk categories into the vendor's structure. Register reports by category then no longer match the categories used in board and committee reporting.
Good answer
- Administrators set the number of levels and the category names in the product's configuration screens
- Categories can be renamed, moved or retired without deleting linked risks or losing their history
- Register views and reports can group and filter risks at any taxonomy level
Red flags
- A fixed number of levels or a preset category list that cannot be changed
- Changing the taxonomy requires vendor professional services or a data migration
- Retiring a category orphans or deletes the risks assigned to it
2. Does your control library support a configurable hierarchy above the individual control, such as control family and control objective, with the number of levels set by our administrators?
Why it matters. If the library is a flat list, the buyer cannot group [control count] controls the way its control owners and auditors navigate them. The buyer then ends up keeping the real structure in a spreadsheet next to the tool.
3. Does your product provide an external-auditor access mode that limits external auditors to the workpapers and evidence we release to them?
Why it matters. If external auditors cannot be given scoped access, the buyer sends evidence by email or file share. The buyer then loses the record of what was provided and when, and risks exposing unrelated material.
Capability areas
Enterprise & Operational Risk Management (12)
Risk registers, taxonomy, inherent and residual scoring, quantitative risk analysis, risk appetite and tolerance, key risk indicators, and the link between risks and their mitigating controls. Excludes vendor-specific risk, which sits in TPR.
Control Library & Control Testing (10)
Control design and ownership, the control library structure, control self-assessment, test-of-design and test-of-effectiveness workflows, and control rating rollups. Excludes automated evidence collection (CCM) and audit engagement management (AUD).
Internal Audit & SOX (10)
Audit universe and planning, engagement workpapers, walkthroughs, sample selection, review and sign-off, SOX scoping and certification, and external-auditor access to evidence. Excludes remediation tracking after findings are raised, which sits in ISS.
Policy Lifecycle & Attestation (10)
Policy authoring, review and approval workflows, versioning, publication to targeted audiences, attestation campaigns and tracking, and linking policies to controls and obligations. Policy exceptions are covered in ISS.
Framework Content & Cross-Framework Mapping (11)
Out-of-the-box security, privacy, financial-reporting and operational-resilience frameworks, a common control set mapped across frameworks so one control tested once satisfies many requirements, custom framework import, and how framework content is updated and versioned. Excludes monitoring of new regulations, which sits in REG.
Regulatory Change Management (8)
Regulatory-change feeds, filtering by jurisdiction and industry, obligation libraries, impact assessment workflows, and tracing a new or amended obligation to the affected policies, controls and owners.
Continuous Controls Monitoring & Evidence Automation (14)
Connector-driven evidence collection from cloud, identity, ITSM, HRIS and code systems, automated control tests and their schedule, control drift and exception alerting, evidence freshness and chain of custody, and the share of an audit that can run without manual uploads. Generic API and SSO capability is out of scope (integration module).
Third-Party & Vendor Risk Management (11)
Vendor intake and inventory, inherent-risk tiering, due-diligence questionnaires and response review, external risk-signal monitoring, fourth-party tracking, and offboarding. This covers the buyer's own suppliers and excludes the GRC vendor's sub-processors.
Issues, Exceptions & Remediation (8)
Capture of findings, deficiencies and control failures from any source, remediation action plans, policy exceptions and risk acceptances with expiry, escalation, and closure validation.
First-Line Adoption & Workflow Configurability (11)
Usability for control and risk owners who are not GRC specialists, task delivery in the tools they already use, no-code and low-code configuration of forms, workflows and scoring by the buyer's own administrators, role-based views, and adoption analytics.
Data Model, Multi-Entity Structure & Risk Reporting (11)
Business hierarchy, linkage of risks and controls to processes, assets and applications, separation of evidence across legal entities and business units, consolidated rollups, and dashboards and board-level reporting. Excludes generic BI connectors.
AI Assistance & AI Governance Module (8)
In-product AI used in GRC work today (suggestions for control and framework mapping, evidence summarization, questionnaire and policy drafting) and modules that inventory and assess the buyer's own AI systems. The vendor's model governance, safety and bias practices are out of scope (AI cross-cutting modules).
Questions about this package
How many Governance, Risk & Compliance (GRC) RFP questions are there?
124 solution questions in 12 capability areas: 26 for the RFI, 63 for the RFP and 35 deep-dive questions for the finalists. The workbook adds 80 due-diligence questions on security, integration, implementation and exit.
What comes with each question?
Why it matters, good-answer signals, red flags, follow-up questions, how to verify the answer (a demo step, a test or a document), and a suggested priority and weight for scoring.
Can I edit the questions?
Yes. The workbook is an ordinary Excel file. Change, add or remove questions, and change the weights; the scorecard recalculates.
Which license do I need?
The Enterprise License covers any number of evaluations inside one organization. The Consultancy License covers use with any number of clients. Neither allows reselling or republishing the questions.