Roll nine GRC signals into one health score: policy currency, control testing, finding closure, register freshness, exceptions, training and coverage.
Control testing completion carries the most weight because it is the pillar that produces the evidence everything else relies on, and finding closure is next since an organisation that finds issues and does not close them is generating risk information rather than reducing risk. The two weakest pillars are named explicitly, because a single roll-up number invites a discussion about the number instead of about the work. GRC dashboards usually show ten green metrics and one red, and the aggregate is what gets reported upward; making the weakest pillars part of the output keeps the conversation on the thing that is actually broken. This is a management estimate for steering the programme, not an assurance opinion.
GRC Health Score
Health score = weighted mean of nine pillars: control testing 18, finding closure 15, policy currency 12, register freshness 12, exception backlog 10, third-party coverage 10, framework coverage 8, training 8, incident SLA 7.
Health score = weighted mean of nine pillars: control testing 18, finding closure 15, policy currency 12, register freshness 12, exception backlog 10, third-party coverage 10, framework coverage 8, training 8, incident SLA 7. Control testing completion carries the most weight because it is the pillar that produces the evidence everything else relies on, and finding closure is next since an organisation that finds issues and does not close them is generating risk information rather than reducing risk. The two weakest pillars are named explicitly, because a single roll-up number invites a discussion about the number instead of about the work.
GRC dashboards usually show ten green metrics and one red, and the aggregate is what gets reported upward; making the weakest pillars part of the output keeps the conversation on the thing that is actually broken. This is a management estimate for steering the programme, not an assurance opinion.
This calculator takes 10 inputs: Policies reviewed within their review cycle, Planned control tests completed this year, Findings currently open, Of those, findings past their due date, Days since the risk register was last reviewed, Open policy exceptions, Mandatory training completion, Critical vendors assessed within 12 months, Average framework control coverage, Incidents handled within their SLA. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Because it is the source of nearly all your assurance evidence. If tests are not completed, then policy currency, framework coverage and finding closure are all claims without support — you know what you intended, not what is happening.
No, and a zero usually means exceptions are being handled informally instead. A healthy programme has a visible, small, expiring exception population; what the score penalises is a backlog that grows because nothing ever expires.