Good morning, Ahmed.
Here's where your GRC program stands today across all six domains.
Risk exposure by category
Recent activity
Guardian flagged 3 controls trending toward ineffective
Evidence freshness has dropped for Encryption-at-Rest, Vendor Access Logging, and Change Approval controls over the last 14 days. Review before your SOC 2 window closes on the 28th.
Governance & Policy
Centralize policies, procedures and ownership so accountability is never in question.
| Policy | Owner | Category | Status | Next review | Acknowledged |
|---|---|---|---|---|---|
Information Security Policy v4.2 · ISO 27001, SOC 2 |
SASara Ahmed | Security | Active | Nov 12, 2026 | 94% |
Data Retention & Disposal v2.1 · GDPR |
MKMostafa K. | Privacy | Under review | Aug 30, 2026 | 71% |
Access Control Policy v4.0 · ISO 27001 |
SASara Ahmed | Security | Active | Jan 18, 2027 | 88% |
Vendor Risk Management Policy v1.3 · SOC 2 |
RTRana T. | Third-Party | Active | Dec 4, 2026 | 79% |
Incident Response Plan v3.0 · NIST CSF |
MKMostafa K. | Security | Active | Oct 2, 2026 | 96% |
AI Acceptable Use Policy v1.0 · Internal |
AZAhmed Z. | Technology | Draft | — | — |
Business Continuity Policy v2.4 · ISO 22301 |
SASara Ahmed | Operational | Active | Feb 9, 2027 | 83% |
Information Security Policy
Risk Management
Score, prioritize and track risk across the business with a live, shared risk register.
Risk heat matrix
| ID | Risk | Category | Rating | Owner | Status | Trend |
|---|---|---|---|---|---|---|
| RSK-0114 | Third-party API rate-limit bypass Flagged by AI risk scoring |
Cybersecurity | Critical | MKMostafa K. | Mitigating | |
| RSK-0098 | Vendor sub-processor data transfer Cross-border, unencrypted channel |
Third-Party | Critical | RTRana T. | Open | |
| RSK-0102 | Single point of failure — payments gateway No automated failover configured |
Operational | High | SASara Ahmed | Mitigating | |
| RSK-0087 | Stale privileged access accounts 17 accounts unused 90+ days |
Security | High | AZAhmed Z. | Open | |
| RSK-0071 | Regulatory change — regional data residency New requirement effective Q1 |
Regulatory | Medium | MKMostafa K. | Open | |
| RSK-0055 | Key-person dependency — DevOps No documented backup owner |
People | Low | SASara Ahmed | Accepted |
Third-party API rate-limit bypass
Guardian raised this rating from Medium to Critical after detecting 3 anomalous traffic spikes bypassing configured limits this week.
Continuous Control Monitoring
Controls are checked continuously, not quarterly, with evidence collected automatically as conditions change.
| Control | Framework | Frequency | Last tested | Status | Auto |
|---|---|---|---|---|---|
Encryption at Rest CTL-0042 |
ISO 27001, SOC 2 | Continuous | 14 min ago | Ineffective | |
Multi-Factor Authentication CTL-0011 |
ISO 27001, NIST | Continuous | 3 min ago | Effective | |
Vendor Access Logging CTL-0067 |
SOC 2 | Daily | 6h ago | Needs review | |
Change Approval Workflow CTL-0029 |
SOC 2, ISO 27001 | Weekly | 2 days ago | Needs review | |
Data Backup Verification CTL-0053 |
ISO 27001 | Daily | 18h ago | Effective | |
Privileged Access Review CTL-0018 |
NIST CSF | Monthly | 9 days ago | Effective |
Encryption at Rest
Structured Audit Testing
Built for internal auditors — plan, run and document tests in a structured, repeatable way.
Audit programs
| Audit | Type | Lead auditor | Timeline | Status | Findings |
|---|---|---|---|---|---|
Q3 SOC 2 Type II Readiness AUD-2026-014 |
Internal | MKMostafa K. | Aug 1 – Aug 29 | In progress | 3 |
Vendor Access Control Review AUD-2026-013 |
Internal | SASara Ahmed | Jul 14 – Aug 4 | In progress | 2 |
ISO 27001 Surveillance Audit AUD-2026-011 |
External | EYExternal — BSI | Jun 2 – Jun 20 | Completed | 4 |
GDPR Data Mapping Audit AUD-2026-015 |
Internal | RTRana T. | Sep 1 – Sep 22 | Planned | — |
Q3 SOC 2 Type II Readiness
Guardian suggests testing CC6.8 next — historically the most-failed control for SOC 2 engagements of this scope.
Internal Clearance
Combine approvals in one shared area instead of chasing decisions across scattered email threads.
Elevated access — production database, 14 days
Guardian AI Insights
Every recommendation Guardian has surfaced across your GRC program, in one feed.