GRC Readiness Checkby Agent Trust Cloud

GRC readiness check

Answer 20 questions about your policies, risk register, controls, evidence and AI governance. You get a maturity level from 1 to 5, a score for each area and a prioritised list of gaps with what to do next. Print it or save it as PDF.

Nothing you answer leaves your browser. Takes about 5 minutes.

Policies and ownership
Do you have a documented, approved set of core policies (information security, acceptable use, data protection)?
Is every policy reviewed at least once a year, with the review recorded?
Have staff acknowledged the policies that apply to them?
Is a named person or committee accountable for governance, risk and compliance?
Risk register
Do you keep a risk register listing your key business, security and compliance risks?
Is each risk rated for likelihood and impact using a written method?
Does each risk have an owner and a treatment decision (reduce, accept, transfer or avoid)?
Is the register reviewed at least quarterly and after major changes?
Controls
Have you mapped your controls to a framework such as ISO/IEC 27001, SOC 2 or the NIST Cybersecurity Framework?
Are access rights reviewed regularly and removed promptly when people leave?
Are vendors assessed before onboarding and re-checked periodically?
Do you have an incident response plan that has been tested?
Evidence and monitoring
Is evidence for each control collected and stored in one place?
Is evidence collection scheduled with owners and due dates, rather than done just before audits?
Do leaders see regular GRC metrics (open risks, overdue actions, control test results)?
Are controls tested or internally audited, with findings tracked to closure?
AI governance
Do you keep an inventory of the AI systems and AI tools in use, including those staff adopted on their own?
Do you have an approved AI acceptable use policy?
Are AI systems risk-assessed before use (data, bias, security, legal)?
Do AI agents and automations that act for you have named owners, limited permissions and human approval for high-impact actions?

What the check covers

Gaps on foundational questions answered No or Partly are high priority. See the GRC maturity model for what each level means.

Questions

What is GRC readiness?

Governance, risk and compliance (GRC) readiness is how far you can show that policies are owned, risks are recorded and treated, controls work and evidence exists, before an auditor, a customer's security review or a regulator asks.

How is the maturity level worked out?

Each answer scores 0 to 3 and is multiplied by the question's weight (3 for foundational questions, 2 for the rest). The overall percentage sets the level: under 20% Initial, 20 to 39% Developing, 40 to 59% Defined, 60 to 79% Managed, 80% or more Optimised.

Why is AI governance included?

AI tools and agents now handle company data and take actions. An AI inventory, an acceptable use policy, risk assessment before use and owners with limited permissions for agents belong in the same GRC programme as any other risk.

Is anything I answer stored or sent?

No. The score and gap list are worked out in this page. Nothing is stored after you close the tab, and the page blocks outgoing requests.

Is this an audit or a certification?

No. It's a quick self-assessment to find gaps and decide what to fix first.