ABCDEFGHIJKLMNOPQRSTUVWXYZ
1
2
Enterprise GRC Readiness Assessment Toolkit
3
Assess Your Governance, Risk, and Compliance Maturity Across 10 Critical Areas
4
5
Brought to you by SecNinjaz
6
7
Purpose
8
This toolkit helps organizations of any size or sector benchmark the maturity of their Governance, Risk, and Compliance (GRC) program across 10 core domains, identify gaps, and build a 90-day remediation plan. It is framework-agnostic and draws on widely recognized reference models (COSO ERM, ISO 31000, ISO/IEC 27001, NIST CSF, COBIT 2019) without requiring adoption of any single standard.
9
10
What's Inside
11
1. Instructions (this tab) - how to complete the assessment.
12
2. GRC Readiness Assessment - 94 questions across 10 domains, scored 0-5.
13
3. GRC Maturity Dashboard - auto-calculated scores per domain, overall score, and a radar chart.
14
4. Gap Register - log and prioritize the gaps the assessment surfaces.
15
5. 90-Day GRC Action Plan - turn gaps into a 0-30 / 31-60 / 61-90 day plan.
16
6. GRC Evidence Tracker - track supporting evidence for each requirement.
17
18
How to Use This Tool
19
1. Open the "GRC Readiness Assessment" tab.
20
2. For each question, select a Response from the dropdown (Not Implemented to Optimized). The Maturity Score, and whether it counts as a Gap, calculate automatically.
21
3. Record whether supporting evidence exists, set a Priority, assign an Owner, and note the action required for any gap.
22
4. Open the "GRC Maturity Dashboard" tab to see auto-calculated scores per domain and overall.
23
5. Log material gaps in the "Gap Register" and sequence remediation in the "90-Day GRC Action Plan".
24
6. Use the "GRC Evidence Tracker" to record where supporting evidence for each requirement lives.
25
7. Repeat quarterly or after a major organizational or regulatory change to track progress over time.
26
27
Maturity Scale
28
Score
29
0 = Not Implemented
30
1 = Initial
31
2 = Developing
32
3 = Defined
33
4 = Managed
34
5 = Optimized
35
36
Disclaimer
37
This toolkit is provided for informational and self-assessment purposes only. It does not constitute legal, regulatory, or professional compliance advice, and completing it does not guarantee compliance with any law, regulation, or standard.
38
39
Need an Expert-Led Assessment?
40
SecNinjaz helps organizations run formal GRC maturity assessments and build remediation roadmaps. To discuss your results, contact SecNinjaz at [INSERT CONTACT EMAIL / LINK].
41
42
(c) 2026 SecNinjaz. Free to use and share with attribution. Not for resale.
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100