GRC Resume Project: Build a Simple Risk Register

A risk register is a practical GRC project because it shows you understand risk, ownership, likelihood, impact, controls, and next steps.

Quick answer
Create a simple spreadsheet with risks, impact, likelihood, owner, existing control, gap, and remediation status.

Risk register fields

FieldExample
Risk IDR-001
Risk statementUsers may retain access after role changes
Asset/processUser access management
LikelihoodMedium
ImpactHigh
Existing controlManager approval required
GapNo quarterly review
Action planRun access review every quarter
OwnerIT manager or system owner
StatusOpen, in progress, closed

Resume bullet

Bullet example

Built a sample GRC risk register to document security risks, map existing controls, identify gaps, assign ownership, and track remediation status.

Interview talking points

  • how you ranked likelihood and impact
  • how you selected controls
  • what remediation means
  • why ownership matters
  • how this supports audits and compliance

Helpful DamnJobs Resources

Before you send more applications, make sure your resume, target role, and keywords line up with the job posting.