| Step | What you do in real life | LondonBuild example |
|---|---|---|
| 1. Collect GRC results | Gather results from assessments, testing, risks, gaps and remediation | 15 controls tested, 3 gaps identified |
| 2. Validate the results | Make sure findings are accurate and supported by evidence | Confirm GAP-001 has evidence and test results |
| 3. Determine key messages | Identify what management actually needs to know | Access controls are generally effective, but 2 accounts were not reviewed |
| 4. Summarise risks | Identify the most important risks | Unauthorised access risk = Medium |
| 5. Summarise gaps | Show important control deficiencies | 2 of 20 sampled accounts lacked documented review |
| 6. Report remediation status | Show what is open, overdue, or closed | Automated access reconciliation = In progress |
| 7. Calculate GRC metrics | Turn results into measurable KPIs/KRIs | 90% controls effective; 2 open gaps; 1 high-risk issue |
| 8. Compare against requirements | Show compliance/coverage position | ISO 27001 access-control requirements: 90% effective |
| 9. Create management report | Produce the formal report/dashboard | Monthly GRC Management Report |
| 10. Highlight priorities | Tell management what needs attention first | Prioritise access-review automation |
| 11. Recommend actions | Give management clear decisions/actions | Approve IT remediation by 30 Sep 2026 |
| 12. Present to management | Explain findings and recommendations | Present to CIO/CEO/Risk Committee |
| 13. Track management decisions | Record decisions, owners and deadlines | IT Manager assigned; deadline 30 Sep |
| 14. Follow up | Monitor actions and report progress | September report shows remediation completed |
| 15. Close/report final status | Confirm issues are resolved and formally reported | GAP-001 closed after successful retest |
Your Reporting spreadsheet could have these tabs
| Tab | Purpose |
|---|---|
| 1. GRC Dashboard | Overall compliance/risk position |
| 2. Executive Summary | What management needs to know |
| 3. Control Results | Effective / Partial / Ineffective |
| 4. Gap Summary | Open and closed gaps |
| 5. Risk Summary | High/Medium/Low risks |
| 6. Remediation Status | Actions, owners and deadlines |
| 7. KPI / KRI | GRC performance indicators |
| 8. Framework Coverage | ISO/NIST/SOC 2/etc. coverage |
| 9. Management Actions | Decisions and assigned actions |
| 10. Reporting History | Previous reporting periods |
The most important thing to understand
A GRC Analyst doesn’t just report data.
You turn:
20 controls tested → 18 passed → 2 exceptions → 1 medium risk → remediation required
into:
“Access controls are generally effective, but two accounts were not subject to the required quarterly review. Management should prioritise automated reconciliation before the next review cycle.”
That’s the actual GRC reporting skill.
Your complete GRC workflow is now
1. Requirement
↓
2. Framework
↓
3. Control Objective
↓
4. Control Mapping
↓
5. Crosswalk
↓
6. Risk Event
↓
7. Risk Register
↓
8. Evidence
↓
9. Testing
↓
10. Gap
↓
11. Remediation
↓
12. Reporting
Reporting is the final communication layer — but it feeds back into Risk, Remediation and future Testing.
GRC Reporting Table
| # | Reporting Element | What you do in real life | LondonBuild Example |
|---|---|---|---|
| 1 | Reporting Period | Define the period being reported | Q3 2026 |
| 2 | Assessment Scope | State what was assessed | Access controls, M365, HR systems |
| 3 | Framework | Identify the framework/requirements assessed | ISO 27001 + GDPR |
| 4 | Requirements Assessed | List requirements reviewed | ISO A.5.15, A.5.18 |
| 5 | Controls Assessed | List controls tested | User access approval + access reviews |
| 6 | Controls Tested | Show number of controls tested | 20 |
| 7 | Effective Controls | Show controls operating effectively | 18 |
| 8 | Partially Effective | Show controls with weaknesses | 2 |
| 9 | Ineffective Controls | Show failed controls | 0 |
| 10 | Control Effectiveness % | Calculate overall effectiveness | 90% |
| 11 | Evidence Status | Summarise evidence collected | 20/20 evidence requests completed |
| 12 | Findings/Gaps | Summarise identified deficiencies | 2 access-review gaps |
| 13 | Risk Events | Show risks resulting from findings | Unauthorised access |
| 14 | High Risks | Identify high-priority risks | 0 |
| 15 | Medium Risks | Identify medium risks | 1 |
| 16 | Low Risks | Identify low risks | 1 |
| 17 | Open Remediation | Show outstanding corrective actions | 1 |
| 18 | Overdue Remediation | Identify late actions | 0 |
| 19 | Closed Remediation | Show completed actions | 2 |
| 20 | Management Priority | Identify what management needs to act on | Automate access reconciliation |
| 21 | Recommendation | Tell management what should happen | Implement automated quarterly reconciliation |
| 22 | Owner | Identify person responsible | IT Manager |
| 23 | Target Date | State remediation deadline | 30 Sep 2026 |
| 24 | Management Decision | Record what management decided | Approved |
| 25 | Final Status | Give overall conclusion | Partially Effective – Improvement Required |
The actual management report
| Area | Result | Status | Management Action |
|---|---|---|---|
| Controls Tested | 20 | — | — |
| Effective | 18 | 🟢 | Maintain |
| Partially Effective | 2 | 🟠 | Remediate |
| Ineffective | 0 | 🟢 | — |
| Evidence Completion | 100% | 🟢 | Maintain |
| Open Gaps | 2 | 🟠 | Track remediation |
| High Risks | 0 | 🟢 | Monitor |
| Medium Risks | 1 | 🟠 | Treat |
| Open Remediation | 1 | 🟠 | Complete by 30 Sep |
| Overall Control Effectiveness | 90% | 🟠 | Improve access-review process |