Reporting

StepWhat you do in real lifeLondonBuild example
1. Collect GRC resultsGather results from assessments, testing, risks, gaps and remediation15 controls tested, 3 gaps identified
2. Validate the resultsMake sure findings are accurate and supported by evidenceConfirm GAP-001 has evidence and test results
3. Determine key messagesIdentify what management actually needs to knowAccess controls are generally effective, but 2 accounts were not reviewed
4. Summarise risksIdentify the most important risksUnauthorised access risk = Medium
5. Summarise gapsShow important control deficiencies2 of 20 sampled accounts lacked documented review
6. Report remediation statusShow what is open, overdue, or closedAutomated access reconciliation = In progress
7. Calculate GRC metricsTurn results into measurable KPIs/KRIs90% controls effective; 2 open gaps; 1 high-risk issue
8. Compare against requirementsShow compliance/coverage positionISO 27001 access-control requirements: 90% effective
9. Create management reportProduce the formal report/dashboardMonthly GRC Management Report
10. Highlight prioritiesTell management what needs attention firstPrioritise access-review automation
11. Recommend actionsGive management clear decisions/actionsApprove IT remediation by 30 Sep 2026
12. Present to managementExplain findings and recommendationsPresent to CIO/CEO/Risk Committee
13. Track management decisionsRecord decisions, owners and deadlinesIT Manager assigned; deadline 30 Sep
14. Follow upMonitor actions and report progressSeptember report shows remediation completed
15. Close/report final statusConfirm issues are resolved and formally reportedGAP-001 closed after successful retest

Your Reporting spreadsheet could have these tabs

TabPurpose
1. GRC DashboardOverall compliance/risk position
2. Executive SummaryWhat management needs to know
3. Control ResultsEffective / Partial / Ineffective
4. Gap SummaryOpen and closed gaps
5. Risk SummaryHigh/Medium/Low risks
6. Remediation StatusActions, owners and deadlines
7. KPI / KRIGRC performance indicators
8. Framework CoverageISO/NIST/SOC 2/etc. coverage
9. Management ActionsDecisions and assigned actions
10. Reporting HistoryPrevious reporting periods

The most important thing to understand

A GRC Analyst doesn’t just report data.

You turn:

20 controls tested → 18 passed → 2 exceptions → 1 medium risk → remediation required

into:

“Access controls are generally effective, but two accounts were not subject to the required quarterly review. Management should prioritise automated reconciliation before the next review cycle.”

That’s the actual GRC reporting skill.

Your complete GRC workflow is now

1. Requirement

2. Framework

3. Control Objective

4. Control Mapping

5. Crosswalk

6. Risk Event

7. Risk Register

8. Evidence

9. Testing

10. Gap

11. Remediation

12. Reporting

Reporting is the final communication layer — but it feeds back into Risk, Remediation and future Testing.

GRC Reporting Table

#Reporting ElementWhat you do in real lifeLondonBuild Example
1Reporting PeriodDefine the period being reportedQ3 2026
2Assessment ScopeState what was assessedAccess controls, M365, HR systems
3FrameworkIdentify the framework/requirements assessedISO 27001 + GDPR
4Requirements AssessedList requirements reviewedISO A.5.15, A.5.18
5Controls AssessedList controls testedUser access approval + access reviews
6Controls TestedShow number of controls tested20
7Effective ControlsShow controls operating effectively18
8Partially EffectiveShow controls with weaknesses2
9Ineffective ControlsShow failed controls0
10Control Effectiveness %Calculate overall effectiveness90%
11Evidence StatusSummarise evidence collected20/20 evidence requests completed
12Findings/GapsSummarise identified deficiencies2 access-review gaps
13Risk EventsShow risks resulting from findingsUnauthorised access
14High RisksIdentify high-priority risks0
15Medium RisksIdentify medium risks1
16Low RisksIdentify low risks1
17Open RemediationShow outstanding corrective actions1
18Overdue RemediationIdentify late actions0
19Closed RemediationShow completed actions2
20Management PriorityIdentify what management needs to act onAutomate access reconciliation
21RecommendationTell management what should happenImplement automated quarterly reconciliation
22OwnerIdentify person responsibleIT Manager
23Target DateState remediation deadline30 Sep 2026
24Management DecisionRecord what management decidedApproved
25Final StatusGive overall conclusionPartially Effective – Improvement Required

The actual management report

AreaResultStatusManagement Action
Controls Tested20
Effective18🟢Maintain
Partially Effective2🟠Remediate
Ineffective0🟢
Evidence Completion100%🟢Maintain
Open Gaps2🟠Track remediation
High Risks0🟢Monitor
Medium Risks1🟠Treat
Open Remediation1🟠Complete by 30 Sep
Overall Control Effectiveness90%🟠Improve access-review process