Risk, controls & assurance

Run a connected IT risk lifecycle — not just a static risk register.

Identify, assess, treat and monitor IT risks with connected controls, KRIs, acceptances, third parties, relationships, retained history and management reporting.

AssessmentInherent · residual · target likelihood, impact and rating
AssuranceControls · tests · findings · evidence · remediation
MonitoringKRIs · reviews/events · trends · action queue
ContextThird parties · relationships · framework mapping · appetite
Overview

A complete look at what you are buying

A structured Excel-based IT risk-management system designed to retain the reasoning, ownership, evidence and history behind risk decisions while keeping the management view connected to the source registers.

Product detail

The complete connected system

  • Capacity for up to 200 master risks and 54 ready-made IT risk scenarios for workshops and identification.
  • Inherent, residual and target likelihood, impact, score and rating with residual-to-target gap calculations.
  • Configurable 5×5 residual-risk heat map and top-risk views.
  • Risk appetite thresholds, escalation routes and acceptance authority.
  • Dashboard KPIs, residual-profile charts and category reporting.
  • Prioritised top-50 Action Queue and connected Explorer for a selected Risk ID.
  • Treatment actions with owners, dates, blockers, progress, costs and evidence.
  • Control register covering design, operation, testing, findings and remediation.
  • Assessment History retaining reasoning, evidence, confidence and movement over time.
  • Reviews & Events for incidents, losses, near misses and control failures.
  • KRIs with thresholds, measurements, trend and RAG status.
  • Time-bound risk acceptances with authority, conditions, expiry and review.
  • Third-party risk, assurance, continuity, concentration and exit planning.
  • Risk Relationships for dependencies, causes, shared suppliers, shared controls, objectives and assumptions.
  • User-maintained Framework Mapping, controlled Risk Intake, Owners & Roles, Settings and methodology.
Product detail

The 22 worksheets

  • Start Here · Dashboard · Risk Heatmap · Explore · Action Queue · Risk Register
  • Treatments · Controls · Reviews & Events · Risk Appetite · KRIs · Third Parties
  • Settings · Methodology · Assessment History · Risk Acceptances · Risk Intake
  • Framework Mapping · Owners & Roles · Risk Library · Action Feed · Risk Relationships
Product detail

Built for evidence-based decisions

  • Risk statements can retain source/threat, vulnerable condition, uncertain event and business consequence rather than a vague title alone.
  • Assessment history is separated from the current master position so previous reasoning is not overwritten.
  • Management views point back to the relevant source register instead of becoming disconnected reporting copies.
  • Light blue denotes intended input, light purple joined lookup context and light grey calculated/read-only fields throughout the system.
Included files

What you receive

  • Blank IT Risk Management & Risk Register workbook (.xlsx)
  • Completed fictional demonstration workbook (.xlsx)
  • 29-page Customer User Guide (.pdf)
Who it is for

Designed for practical IT teams

IT managersService ownersCyber-risk teamsRisk & complianceAssurance teamsMSPsConsultants / virtual CISOs
Compatibility

Before you buy

Excel & file requirements

  • Recommended: desktop Microsoft Excel 2021 or Microsoft 365 on Windows or macOS.
  • Macro-free .xlsx format with no VBA, scripts or external data connections.
  • Modern Excel is recommended for the connected views and formulas.
  • Google Sheets, Apple Numbers and older/alternative spreadsheet applications may alter formulas, dropdowns, charts, dates or formatting.

Important limitations

  • The starter scenario library cannot represent every organisation, supplier, technology, law or emerging threat and must be supplemented with local context.
  • Framework Mapping provides traceability only; it does not prove certification, conformity, audit readiness, compliance or control effectiveness.
  • No spreadsheet can identify every risk, authorise acceptance or replace competent professional judgement.
Delivery, licence & support

Clear terms before you purchase

Direct delivery

After verified payment, the purchase is linked to the customer account using the checkout email. Secure download links are generated on demand.

Licence

For the purchaser's own use or internal operations of the purchasing organisation. Reusable source templates must not be resold or redistributed.

Digital content

Direct checkout includes the required immediate-supply acknowledgement. Statutory rights for faulty or non-conforming digital content are unaffected.

Support

Product and access help is available at support@practicalitpacks.com.

Ready to put it to work?

Add it to your Practical IT Packs cart for secure direct checkout, or use Etsy if you prefer the marketplace route.