Knowledge Base Operating Model Templates Services About Work With Me
Templates & Tools

Stop Building From a Blank Page

Every template here was built for a real program, used in production, and refined through audits, board presentations, and live incidents. Download, customize, and deploy.

Best Value

Complete Template Bundle

All 6 templates in one download — the complete toolkit for building or modernizing a GRC, resilience, or ERM program. Saves $150 vs. buying individually.

  • GRC Operating Model Canvas
  • Risk Register
  • BIA Template
  • Vendor Assessment
  • Tabletop Playbook
  • Control Framework Map
$397
one-time · instant download
Get the Bundle
Secure checkout via Gumroad
Individual Templates

Pick What You Need

Every template is a standalone, production-ready document with instructions, examples, and customization notes.

Risk Register & Scoring Model

Quantitative risk scoring with expected-loss methodology, likelihood/impact scales, and board-ready reporting output.

$79 one-time
  • Expected-loss scoring model
  • Likelihood & impact scales with anchors
  • Risk taxonomy template
  • Executive dashboard view
  • Pre-populated with 30 example risks
Buy Now — $79

Business Impact Analysis (BIA) Template

Structured BIA for identifying critical processes, dependencies, RTOs/RPOs, and recovery priorities across your organization.

$79 one-time
  • Process criticality assessment
  • Dependency mapping worksheet
  • RTO/RPO definition framework
  • Recovery priority matrix
  • Regulatory alignment notes (FFIEC, DORA)
Buy Now — $79

Vendor Risk Assessment Questionnaire

Tiered vendor assessment covering security, resilience, compliance, and contractual requirements — aligned to NIST and ISO 27001.

$97 one-time
  • 3-tier assessment (critical / high / standard)
  • 150+ curated questions with guidance
  • Scoring rubric and risk rating output
  • Contractual requirement checklist
  • Fourth-party risk section
Buy Now — $97

Tabletop Exercise Playbook

End-to-end tabletop exercise design — scenario library, facilitator guide, participant materials, and post-exercise reporting.

$67 one-time
  • 5 scenario templates (ransomware, cloud outage, third-party failure, etc.)
  • Facilitator script and inject library
  • Participant role cards
  • Findings and after-action report template
  • Executive briefing template
Buy Now — $67

Unified Control Framework Mapping

Pre-built control library with cross-framework mapping across SOC 2, ISO 27001, NIST CSF, DORA, and FFIEC.

$127 one-time
  • 200+ controls mapped across 5 frameworks
  • Evidence type definitions per control
  • Ownership assignment template
  • Gap analysis worksheet
  • Audit-ready evidence tracker
Buy Now — $127

Common Questions

What format are the templates?

Word (.docx) and Excel (.xlsx) formats, plus a PDF reference version. All fully editable with instructions and completed examples.

Are these frameworks for a specific industry?

They're built to be framework-flexible. Primary references are NIST CSF, ISO 27001, SOC 2, and DORA, but the structures work across financial services, technology, and enterprise organizations of any size.

Can I use these commercially with clients?

Yes. A single purchase includes a commercial license for use in your own consulting work. You cannot resell the templates as standalone products.

What if I need something customized?

If you need a template adapted for a specific framework, organization size, or regulatory requirement, get in touch. I offer advisory and customization engagements.