Identify risk event

OrderTabWhat you do in real lifeLondonBuild example
1Start with the ControlLook at the control you have mapped.Quarterly user-access review
2Identify the AssetDetermine what needs protection.Microsoft 365, project files, HR data
3Identify the ThreatAsk what could cause harm.Former employee, attacker, malicious insider
4Identify the VulnerabilityAsk what weakness could be exploited.Leaver’s account remains active
5Identify the Risk EventDescribe the actual event that could happen.A former employee uses an active account to access confidential project information.
6Identify the CauseExplain why the event could occur.IT is not notified immediately when employees leave.
7Identify the ImpactDetermine what happens if the event occurs.Data exposure, financial loss, contractual issues, reputational damage.
8Identify Affected Assets/DataRecord what could be affected.Client drawings, contracts, employee information
9Record the Risk EventPut the event into the risk register.Unauthorised access to sensitive information following employee termination.
10Link to Requirement/ControlConnect the risk back to your GRC work.ISO 27001 A.5.18 → AC-003 → Risk R-001

The actual LondonBuild risk

You could document it like this:

FieldExample
Risk IDR-001
Risk EventFormer employee accesses company information using an active account.
ThreatFormer employee / external attacker
VulnerabilityAccount not disabled promptly
AssetMicrosoft 365 / project information
CausePoor HR-to-IT offboarding process
ImpactData breach, financial loss, reputational damage
Related RequirementISO 27001 A.5.18
Related ControlAC-003 — Leaver account termination
Risk OwnerIT Manager

Risk Register — Google Sheets

For LondonBuild, your Google Sheet could look like this:

Risk IDRisk EventCauseThreatAssetImpactLikelihoodRisk ScoreRisk LevelRisk OwnerTreatmentStatus
R-001Former employee accesses confidential information using an active accountPoor offboardingFormer employeeProject filesData breach312HighIT ManagerImprove offboardingOpen
R-002Employee accidentally sends confidential client information to wrong recipientLack of verificationHuman errorClient dataData exposure39MediumData Protection OfficerEmail controls/trainingOpen
R-003Ransomware encrypts project filesWeak endpoint protectionCybercriminalProject filesOperational disruption416HighIT ManagerStrengthen EDR/backupsOpen

Where it fits in your GRC process

Identify Risk Event

⬇️

Create / update Risk Register

⬇️

Assess Risk

  • Likelihood
  • Impact
  • Inherent Risk
  • Existing Controls
  • Residual Risk

⬇️

Risk Treatment

  • Mitigate
  • Accept
  • Transfer
  • Avoid

⬇️

Track & Monitor

⬇️

Report

So, if you’re building your GRC portfolio

I would actually create a Google Sheets Risk Register as one of your practical deliverables.

Your tabs could be:

  1. Risk Register
  2. Risk Scoring
  3. Risk Matrix
  4. Risk Treatment
  5. Risk Actions
  6. Risk Dashboard

That would make your learning project much closer to what you’d actually do as a GRC Analyst.