Skip to content
Calcrivo

GRC Health Score Calculator

Roll nine GRC signals into one health score: policy currency, control testing, finding closure, register freshness, exceptions, training and coverage.

Inputs

%
%
findings
findings
days
exceptions
%
%
%
%

GRC Health Score

70.1%

Finding Closure Discipline

67.6%

Findings Overdue

32.4%

Risk Register Freshness

70%

Exception Backlog Score

55.0%

Grade

C — Fair

Weakest Pillar

the exception backlog

Second Weakest Pillar

third-party assessment coverage

Reporting Cadence

Stable with known gaps — track the two weakest pillars monthly

Focus for the Next Quarter

Focus the next quarter on the exception backlog and third-party assessment coverage

Step by step

  1. Values used

    Policies reviewed within their review cycle = 72 %; Planned control tests completed this year = 65 %; Findings currently open = 34 findings; Of those, findings past their due date = 11 findings; Days since the risk register was last reviewed = 95 days; Open policy exceptions = 18 exceptions; Mandatory training completion = 88 %; Critical vendors assessed within 12 months = 61 %; Average framework control coverage = 78 %; Incidents handled within their SLA = 91 %

  2. GRC Health Score

    Health score = weighted mean of nine pillars: control testing 18, finding closure 15, policy currency 12, register freshness 12, exception backlog 10, third-party coverage 10, framework coverage 8, training 8, incident SLA 7.

  3. GRC Health Score

    = 70.1

  4. Finding Closure Discipline

    = 67.6

  5. Findings Overdue

    = 32.4

  6. Risk Register Freshness

    = 70

  7. Exception Backlog Score

    = 55.0

  8. Grade

    = C — Fair

How it works

Control testing completion carries the most weight because it is the pillar that produces the evidence everything else relies on, and finding closure is next since an organisation that finds issues and does not close them is generating risk information rather than reducing risk. The two weakest pillars are named explicitly, because a single roll-up number invites a discussion about the number instead of about the work. GRC dashboards usually show ten green metrics and one red, and the aggregate is what gets reported upward; making the weakest pillars part of the output keeps the conversation on the thing that is actually broken. This is a management estimate for steering the programme, not an assurance opinion.

Formula

GRC Health Score

Health score = weighted mean of nine pillars: control testing 18, finding closure 15, policy currency 12, register freshness 12, exception backlog 10, third-party coverage 10, framework coverage 8, training 8, incident SLA 7.

finding closure
100 − share of open findings that are overdue
register freshness
100 within 90 days, 70 within 180, 40 within a year, 10 beyond
exception backlog
100 − 2.5 points per open exception

Frequently Asked Questions

How is GRC Health Score calculated?

Health score = weighted mean of nine pillars: control testing 18, finding closure 15, policy currency 12, register freshness 12, exception backlog 10, third-party coverage 10, framework coverage 8, training 8, incident SLA 7. Control testing completion carries the most weight because it is the pillar that produces the evidence everything else relies on, and finding closure is next since an organisation that finds issues and does not close them is generating risk information rather than reducing risk. The two weakest pillars are named explicitly, because a single roll-up number invites a discussion about the number instead of about the work.

Why does GRC Health Score matter?

GRC dashboards usually show ten green metrics and one red, and the aggregate is what gets reported upward; making the weakest pillars part of the output keeps the conversation on the thing that is actually broken. This is a management estimate for steering the programme, not an assurance opinion.

What values do I need to enter?

This calculator takes 10 inputs: Policies reviewed within their review cycle, Planned control tests completed this year, Findings currently open, Of those, findings past their due date, Days since the risk register was last reviewed, Open policy exceptions, Mandatory training completion, Critical vendors assessed within 12 months, Average framework control coverage, Incidents handled within their SLA. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Why is control testing weighted highest?

Because it is the source of nearly all your assurance evidence. If tests are not completed, then policy currency, framework coverage and finding closure are all claims without support — you know what you intended, not what is happening.

Is an open exception count of zero the goal?

No, and a zero usually means exceptions are being handled informally instead. A healthy programme has a visible, small, expiring exception population; what the score penalises is a backlog that grows because nothing ever expires.

You might also need