Good morning, Ahmed.

Here's where your GRC program stands today across all six domains.

Open Risks
38
+4 vs last month
Controls Effective
86%
+3pts vs last month
Open Findings
12
−5 vs last month
Pending Approvals
6
Avg. wait 1.4 days

Risk exposure by category

Current open risks, weighted by rating
Third-Party
9
Cybersecurity
7
Financial
6
Operational
8
Regulatory
5
People
3

Recent activity

Last 24 hours
Vendor Data Retention control tested — passed
Continuous monitoring · 42 min ago
New risk flagged: API rate-limit bypass
AI risk scoring · 2h ago
Access Review Policy v4 approved
Sara Ahmed · 3h ago
Encryption-at-Rest control marked ineffective
SOC 2 audit · 5h ago
Q3 Internal Audit kicked off
Mostafa K. · Yesterday

Guardian flagged 3 controls trending toward ineffective

Evidence freshness has dropped for Encryption-at-Rest, Vendor Access Logging, and Change Approval controls over the last 14 days. Review before your SOC 2 window closes on the 28th.

Governance & Policy

Centralize policies, procedures and ownership so accountability is never in question.

All (24) Active (18) Under review (4) Draft (2)
PolicyOwnerCategoryStatusNext reviewAcknowledged
Information Security Policy
v4.2 · ISO 27001, SOC 2
SASara Ahmed Security Active Nov 12, 2026 94%
Data Retention & Disposal
v2.1 · GDPR
MKMostafa K. Privacy Under review Aug 30, 2026 71%
Access Control Policy
v4.0 · ISO 27001
SASara Ahmed Security Active Jan 18, 2027 88%
Vendor Risk Management Policy
v1.3 · SOC 2
RTRana T. Third-Party Active Dec 4, 2026 79%
Incident Response Plan
v3.0 · NIST CSF
MKMostafa K. Security Active Oct 2, 2026 96%
AI Acceptable Use Policy
v1.0 · Internal
AZAhmed Z. Technology Draft
Business Continuity Policy
v2.4 · ISO 22301
SASara Ahmed Operational Active Feb 9, 2027 83%
Selected policy

Information Security Policy

Owned by Sara Ahmed · Security
Version4.2
StatusActive
Maps toISO 27001, SOC 2
Linked controls14
Next reviewNov 12, 2026
Staff acknowledgement
94%
211 of 224 employees acknowledged
Version history
v4.2 — Added remote-access clause
Sara Ahmed · Jul 2, 2026
v4.1 — Annual review, no changes
Sara Ahmed · Nov 12, 2025
v4.0 — MFA requirement added
Sara Ahmed · Mar 8, 2025

Risk Management

Score, prioritize and track risk across the business with a live, shared risk register.

Risk heat matrix

Likelihood × Impact — 38 open risks
Likelihood →
1
2
3
2
1
1
3
5
3
2
2
4
6
4
2
1
2
3
1
2
0
1
1
0
1
NegligibleMinorModerateMajorSevere
Impact →
All (38) Critical (9) High (13) Medium (11) Low (5)
IDRiskCategoryRatingOwnerStatusTrend
RSK-0114
Third-party API rate-limit bypass
Flagged by AI risk scoring
Cybersecurity Critical MKMostafa K. Mitigating
RSK-0098
Vendor sub-processor data transfer
Cross-border, unencrypted channel
Third-Party Critical RTRana T. Open
RSK-0102
Single point of failure — payments gateway
No automated failover configured
Operational High SASara Ahmed Mitigating
RSK-0087
Stale privileged access accounts
17 accounts unused 90+ days
Security High AZAhmed Z. Open
RSK-0071
Regulatory change — regional data residency
New requirement effective Q1
Regulatory Medium MKMostafa K. Open
RSK-0055
Key-person dependency — DevOps
No documented backup owner
People Low SASara Ahmed Accepted
RSK-0114
Critical

Third-party API rate-limit bypass

Cybersecurity · Owned by Mostafa K.

Guardian raised this rating from Medium to Critical after detecting 3 anomalous traffic spikes bypassing configured limits this week.

LikelihoodLikely (4/5)
ImpactSevere (5/5)
Inherent ratingCritical
Residual ratingHigh
Linked controls3
Treatment plan
Implement stricter per-key throttling at the gateway and rotate affected API credentials. Target completion Aug 22.

Continuous Control Monitoring

Controls are checked continuously, not quarterly, with evidence collected automatically as conditions change.

Total controls
142
Across 6 frameworks
Effective
122
86%
Ineffective
9
+2 this week
Automated tests
96
68% of all controls
All (142) ISO 27001 (44) SOC 2 (38) NIST CSF (26) GDPR (18)
ControlFrameworkFrequencyLast testedStatusAuto
Encryption at Rest
CTL-0042
ISO 27001, SOC 2 Continuous 14 min ago Ineffective
Multi-Factor Authentication
CTL-0011
ISO 27001, NIST Continuous 3 min ago Effective
Vendor Access Logging
CTL-0067
SOC 2 Daily 6h ago Needs review
Change Approval Workflow
CTL-0029
SOC 2, ISO 27001 Weekly 2 days ago Needs review
Data Backup Verification
CTL-0053
ISO 27001 Daily 18h ago Effective
Privileged Access Review
CTL-0018
NIST CSF Monthly 9 days ago Effective
CTL-0042
Ineffective

Encryption at Rest

Maps to ISO 27001 A.8.24, SOC 2 CC6.1
Test frequencyContinuous
OwnerSara Ahmed
Evidence sourcesAWS Config, Vault
Linked risks2
Evidence timeline
2 storage volumes found unencrypted
Automated scan · 14 min ago
Volume encryption verified — 48/50 volumes
Automated scan · 6h ago
Volume encryption verified — 50/50 volumes
Automated scan · 12h ago
KMS key rotation confirmed
Automated scan · Yesterday

Structured Audit Testing

Built for internal auditors — plan, run and document tests in a structured, repeatable way.

Completed
14
This fiscal year
In progress
3
Avg. 11 days remaining
Planned
5
Next starts Sep 1
Open findings
12
4 high severity

Audit programs

Internal and external engagements
AuditTypeLead auditorTimelineStatusFindings
Q3 SOC 2 Type II Readiness
AUD-2026-014
Internal MKMostafa K. Aug 1 – Aug 29 In progress 3
Vendor Access Control Review
AUD-2026-013
Internal SASara Ahmed Jul 14 – Aug 4 In progress 2
ISO 27001 Surveillance Audit
AUD-2026-011
External EYExternal — BSI Jun 2 – Jun 20 Completed 4
GDPR Data Mapping Audit
AUD-2026-015
Internal RTRana T. Sep 1 – Sep 22 Planned

Q3 SOC 2 Type II Readiness

AUD-2026-014 · Structured test plan
In progress
CC6.1 — Verify logical access provisioning process
Tested Aug 6 · Evidence attached · Sara Ahmed
CC6.6 — Confirm encryption of data in transit
Tested Aug 7 · Evidence attached · Sara Ahmed
CC6.1 — Verify encryption of data at rest
Failed Aug 9 · Finding raised · Mostafa K.
CC7.2 — Test incident detection and escalation
Scheduled Aug 14 · Mostafa K.
CC8.1 — Sample change management tickets (n=25)
Scheduled Aug 16 · Rana T.
Progress
13 / 25
Open findings
High
Data-at-rest encryption gap on 2 volumes
Linked to CTL-0042
Medium
Access review evidence incomplete for July
Linked to CTL-0018
Low
Ticket sampling missing 2 of 25 approvals
Linked to CTL-0029

Guardian suggests testing CC6.8 next — historically the most-failed control for SOC 2 engagements of this scope.

Internal Clearance

Combine approvals in one shared area instead of chasing decisions across scattered email threads.

Requested3
Exception: MFA waiver for legacy billing system
RT Rana T.Aug 12
New vendor onboarding — Northwind Analytics
MK Mostafa K.Aug 13
Policy exception: BYOD for contractor team
SA Sara A.Aug 13
In review2
Elevated access — production database, 14 days
AZ Ahmed Z.High risk
Third-party data processing agreement — v2
RT Rana T.Aug 10
Approved18
Access Control Policy v4.0 sign-off
SA Sara A.Approved
Change request — payments API v3 rollout
MK Mostafa K.Approved
Rejected1
Exception: skip code review for hotfix branch
AZ Ahmed Z.Rejected
CLR-0231
High risk

Elevated access — production database, 14 days

Requested by Ahmed Z. · Aug 11
Approval chain
Requested by Ahmed Z.
Aug 11, 9:02 AM
Approved — Sara Ahmed (Security Lead)
Aug 11, 2:40 PM
Awaiting — Mostafa K. (CISO)
Pending, 1.2 days
Reason for request
Temporary elevated read access needed to investigate the encryption-at-rest finding from CTL-0042. Auto-revokes after 14 days.

Guardian AI Insights

Every recommendation Guardian has surfaced across your GRC program, in one feed.

Insights this week
27
Across 6 modules
Accepted
19
70% acceptance
Risk scores updated
14
By AI evaluation
Audit tests suggested
8
3 already scheduled
All (27)
Risk (11)
Controls (9)
Audit (5)
Clearance (2)
Risk · RSK-0114 Raised Third-party API rate-limit bypass from Medium to Critical after detecting 3 anomalous traffic spikes bypassing configured limits this week.
Control Monitoring · CTL-0042 Evidence freshness for Encryption at Rest has dropped 40% over 14 days — 2 storage volumes are currently unencrypted. Recommend immediate remediation before the SOC 2 window closes.
Audit · AUD-2026-014 Suggests testing CC6.8 — Vulnerability Management next. It's the most-failed control in engagements of this scope and hasn't been tested yet this cycle.
Governance · Data Retention Policy This policy is 71% acknowledged with 9 days left before its review date. Historically, policies below 80% at this stage miss their deadline.
Risk · RSK-0087 17 privileged accounts have been inactive 90+ days. Guardian estimates this raises the residual likelihood of Stale privileged access accounts from Possible to Likely.
Clearance · CLR-0231 Elevated database access request has been pending CISO approval for 1.2 days — approaching your 2-day SLA. Recommend a nudge.
Guardian
Online
Guardian Hi Ahmed. Here's what I'm watching right now on the Dashboard.
3 controls are trending toward ineffective — Encryption at Rest, Vendor Access Logging, and Change Approval. Evidence freshness has dropped over the last 14 days.
Risk · RSK-0114 I raised this risk to Critical after 3 anomalous traffic spikes this week. Want me to draft a treatment plan?