GRC Health Score Calculator
Roll nine GRC signals into one health score: policy currency, control testing, finding closure, register freshness, exceptions, training and coverage.
Inputs
GRC Health Score
70.1%
Finding Closure Discipline
67.6%
Findings Overdue
32.4%
Risk Register Freshness
70%
Exception Backlog Score
55.0%
Grade
C — Fair
Weakest Pillar
the exception backlog
Second Weakest Pillar
third-party assessment coverage
Reporting Cadence
Stable with known gaps — track the two weakest pillars monthly
Focus for the Next Quarter
Focus the next quarter on the exception backlog and third-party assessment coverage
Step by step
Values used
Policies reviewed within their review cycle = 72 %; Planned control tests completed this year = 65 %; Findings currently open = 34 findings; Of those, findings past their due date = 11 findings; Days since the risk register was last reviewed = 95 days; Open policy exceptions = 18 exceptions; Mandatory training completion = 88 %; Critical vendors assessed within 12 months = 61 %; Average framework control coverage = 78 %; Incidents handled within their SLA = 91 %
GRC Health Score
Health score = weighted mean of nine pillars: control testing 18, finding closure 15, policy currency 12, register freshness 12, exception backlog 10, third-party coverage 10, framework coverage 8, training 8, incident SLA 7.
GRC Health Score
= 70.1
Finding Closure Discipline
= 67.6
Findings Overdue
= 32.4
Risk Register Freshness
= 70
Exception Backlog Score
= 55.0
Grade
= C — Fair
How it works
Control testing completion carries the most weight because it is the pillar that produces the evidence everything else relies on, and finding closure is next since an organisation that finds issues and does not close them is generating risk information rather than reducing risk. The two weakest pillars are named explicitly, because a single roll-up number invites a discussion about the number instead of about the work. GRC dashboards usually show ten green metrics and one red, and the aggregate is what gets reported upward; making the weakest pillars part of the output keeps the conversation on the thing that is actually broken. This is a management estimate for steering the programme, not an assurance opinion.
Formula
GRC Health Score
Health score = weighted mean of nine pillars: control testing 18, finding closure 15, policy currency 12, register freshness 12, exception backlog 10, third-party coverage 10, framework coverage 8, training 8, incident SLA 7.
- finding closure
- 100 − share of open findings that are overdue
- register freshness
- 100 within 90 days, 70 within 180, 40 within a year, 10 beyond
- exception backlog
- 100 − 2.5 points per open exception
Frequently Asked Questions
How is GRC Health Score calculated?
Health score = weighted mean of nine pillars: control testing 18, finding closure 15, policy currency 12, register freshness 12, exception backlog 10, third-party coverage 10, framework coverage 8, training 8, incident SLA 7. Control testing completion carries the most weight because it is the pillar that produces the evidence everything else relies on, and finding closure is next since an organisation that finds issues and does not close them is generating risk information rather than reducing risk. The two weakest pillars are named explicitly, because a single roll-up number invites a discussion about the number instead of about the work.
Why does GRC Health Score matter?
GRC dashboards usually show ten green metrics and one red, and the aggregate is what gets reported upward; making the weakest pillars part of the output keeps the conversation on the thing that is actually broken. This is a management estimate for steering the programme, not an assurance opinion.
What values do I need to enter?
This calculator takes 10 inputs: Policies reviewed within their review cycle, Planned control tests completed this year, Findings currently open, Of those, findings past their due date, Days since the risk register was last reviewed, Open policy exceptions, Mandatory training completion, Critical vendors assessed within 12 months, Average framework control coverage, Incidents handled within their SLA. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Why is control testing weighted highest?
Because it is the source of nearly all your assurance evidence. If tests are not completed, then policy currency, framework coverage and finding closure are all claims without support — you know what you intended, not what is happening.
Is an open exception count of zero the goal?
No, and a zero usually means exceptions are being handled informally instead. A healthy programme has a visible, small, expiring exception population; what the score penalises is a backlog that grows because nothing ever expires.
You might also need
- Risk Register CalculatorCommonly used together
- Enterprise Risk Score CalculatorCommonly used together
- Governance Maturity CalculatorCommonly used together
- Residual Risk CalculatorAlso in Compliance & GRC
- Disaster Recovery RTO CalculatorAlso in Compliance & GRC
- Security Investment ROI CalculatorAlso in Compliance & GRC