CIOPages
All RFP packages

RFP Package · Architecture & Governance

Governance, Risk & Compliance (GRC) RFP questions and template

124 questions, 10 demo scenarios and a five-vendor scorecard for choosing Governance, Risk & Compliance (GRC) software, in one Excel workbook.

What this package is for

Use it to run a Governance, Risk & Compliance (GRC) software selection, from the first long list to the final scorecard.

What the category covers. Software that runs risk, control, audit, policy, regulatory change and third-party risk work in one place, with controls tested continuously against live evidence from cloud, identity and business systems. Bought by risk, compliance, internal audit and security leaders replacing spreadsheets or an older GRC suite, or adding continuous compliance for certifications.

A selection usually runs in three rounds. The package has questions for each:

  • RFI, to the long list. 26 questions screen out products that lack something you need.
  • RFP, to the shortlist. 63 questions ask how each product does the work.
  • Deep dive, to the finalists. 35 questions ask for proof on your own data.

10 demo scenarios tell each vendor what to load and what to show, so every product does the same work in front of you. 80 due-diligence questions cover security, integration, implementation and exit. The scorecard weights the answers and ranks up to five vendors.

Each question comes with why it matters, what a good answer looks like and the red flags, so the people scoring the replies know what to look for.

3 questions from the package

From the RFI round. The first shows part of the guide each question carries; the workbook adds follow-ups, how to verify the answer, a priority and a weight.

1. Does your risk register support a configurable risk taxonomy of [taxonomy depth] levels, with each risk assigned to a category in it?

Why it matters. If the taxonomy is fixed, the buyer must force its risk categories into the vendor's structure. Register reports by category then no longer match the categories used in board and committee reporting.

Good answer
  • Administrators set the number of levels and the category names in the product's configuration screens
  • Categories can be renamed, moved or retired without deleting linked risks or losing their history
  • Register views and reports can group and filter risks at any taxonomy level
Red flags
  • A fixed number of levels or a preset category list that cannot be changed
  • Changing the taxonomy requires vendor professional services or a data migration
  • Retiring a category orphans or deletes the risks assigned to it

2. Does your control library support a configurable hierarchy above the individual control, such as control family and control objective, with the number of levels set by our administrators?

Why it matters. If the library is a flat list, the buyer cannot group [control count] controls the way its control owners and auditors navigate them. The buyer then ends up keeping the real structure in a spreadsheet next to the tool.

3. Does your product provide an external-auditor access mode that limits external auditors to the workpapers and evidence we release to them?

Why it matters. If external auditors cannot be given scoped access, the buyer sends evidence by email or file share. The buyer then loses the record of what was provided and when, and risks exposing unrelated material.

Capability areas

Enterprise & Operational Risk Management (12)

Risk registers, taxonomy, inherent and residual scoring, quantitative risk analysis, risk appetite and tolerance, key risk indicators, and the link between risks and their mitigating controls. Excludes vendor-specific risk, which sits in TPR.

Control Library & Control Testing (10)

Control design and ownership, the control library structure, control self-assessment, test-of-design and test-of-effectiveness workflows, and control rating rollups. Excludes automated evidence collection (CCM) and audit engagement management (AUD).

Internal Audit & SOX (10)

Audit universe and planning, engagement workpapers, walkthroughs, sample selection, review and sign-off, SOX scoping and certification, and external-auditor access to evidence. Excludes remediation tracking after findings are raised, which sits in ISS.

Policy Lifecycle & Attestation (10)

Policy authoring, review and approval workflows, versioning, publication to targeted audiences, attestation campaigns and tracking, and linking policies to controls and obligations. Policy exceptions are covered in ISS.

Framework Content & Cross-Framework Mapping (11)

Out-of-the-box security, privacy, financial-reporting and operational-resilience frameworks, a common control set mapped across frameworks so one control tested once satisfies many requirements, custom framework import, and how framework content is updated and versioned. Excludes monitoring of new regulations, which sits in REG.

Regulatory Change Management (8)

Regulatory-change feeds, filtering by jurisdiction and industry, obligation libraries, impact assessment workflows, and tracing a new or amended obligation to the affected policies, controls and owners.

Continuous Controls Monitoring & Evidence Automation (14)

Connector-driven evidence collection from cloud, identity, ITSM, HRIS and code systems, automated control tests and their schedule, control drift and exception alerting, evidence freshness and chain of custody, and the share of an audit that can run without manual uploads. Generic API and SSO capability is out of scope (integration module).

Third-Party & Vendor Risk Management (11)

Vendor intake and inventory, inherent-risk tiering, due-diligence questionnaires and response review, external risk-signal monitoring, fourth-party tracking, and offboarding. This covers the buyer's own suppliers and excludes the GRC vendor's sub-processors.

Issues, Exceptions & Remediation (8)

Capture of findings, deficiencies and control failures from any source, remediation action plans, policy exceptions and risk acceptances with expiry, escalation, and closure validation.

First-Line Adoption & Workflow Configurability (11)

Usability for control and risk owners who are not GRC specialists, task delivery in the tools they already use, no-code and low-code configuration of forms, workflows and scoring by the buyer's own administrators, role-based views, and adoption analytics.

Data Model, Multi-Entity Structure & Risk Reporting (11)

Business hierarchy, linkage of risks and controls to processes, assets and applications, separation of evidence across legal entities and business units, consolidated rollups, and dashboards and board-level reporting. Excludes generic BI connectors.

AI Assistance & AI Governance Module (8)

In-product AI used in GRC work today (suggestions for control and framework mapping, evidence summarization, questionnaire and policy drafting) and modules that inventory and assess the buyer's own AI systems. The vendor's model governance, safety and bias practices are out of scope (AI cross-cutting modules).

Demo scenarios

Each scenario lists the data to load before the demo, then the steps to show, and the questions it scores.

  1. MFA disabled in a connected cloud account
  2. One access review test across three frameworks
  3. First-line owner completes a quarterly self-assessment
  4. An amended regulation reaches the compliance team
  5. Business-unit owner logs a new operational risk
  6. Testing a key control at quarter-end
  7. Onboarding a critical vendor
  8. Exception to our encryption policy
  9. Two subsidiaries reporting to one board
  10. Our administrator changes the risk assessment form

Due diligence

The workbook carries the screening questions from these modules. Each module is also sold on its own.

Questions about this package

How many Governance, Risk & Compliance (GRC) RFP questions are there?

124 solution questions in 12 capability areas: 26 for the RFI, 63 for the RFP and 35 deep-dive questions for the finalists. The workbook adds 80 due-diligence questions on security, integration, implementation and exit.

What comes with each question?

Why it matters, good-answer signals, red flags, follow-up questions, how to verify the answer (a demo step, a test or a document), and a suggested priority and weight for scoring.

Can I edit the questions?

Yes. The workbook is an ordinary Excel file. Change, add or remove questions, and change the weights; the scorecard recalculates.

Which license do I need?

The Enterprise License covers any number of evaluations inside one organization. The Consultancy License covers use with any number of clients. Neither allows reselling or republishing the questions.

Before you shortlist

The buyer guide compares the products in this category and what decides between them.

Buyer Guide
Governance, Risk & Compliance (GRC)

For the business side of the same change: