Cover of the GRC Requirements Catalogue
Free template

GRC Requirements Catalogue

More than 110 requirements in 15 areas, collected from tenders and customer projects. An Excel template for aligning your team, free of charge.

15
Areas
112
Requirements
Excel
Ready to fill in

Template · 112 requirements

Request the catalogue for free

15 areas, 112 requirements as an Excel template. You will receive an email to confirm your address, then the download is ready.

Country code: +49

Would you rather not align the requirements on your own?

We offer a facilitated requirements analysis with your stakeholders, run by one of our consulting partners. Online in four hours for EUR 2,500 net, or as a full day on site for EUR 4,500 net including travel expenses within Germany. Write to us at hello@kopexa.com.

What's inside

  • 15 areas from frameworks and risk management to BCM, suppliers, hosting and support
  • 112 requirements from real tenders and customer projects
  • Set priorities (must, should, could) and owners directly in the template
  • Excel file with scope sheet, ready to share with your team

What the catalogue is for

Anyone looking for a tool for ISMS, risk management or BCM usually starts with a blank spreadsheet and collects requirements from memory. What gets missed are the points that hurt later in daily operation: multiple legal entities, interfaces to the asset inventory, evidence from the vendor.

The catalogue does this groundwork for you. You rate each requirement as must, should or could and end up with a basis you can put in front of any vendor, including us.

Who it is for

For information security, IT management, data protection and executive management in organisations that are selecting a GRC tool or replacing an existing one.

01

Standards & frameworks

14 Requirements

  • ISO 27001 fully covered

  • ISO 22301 (BCM) covered

  • NIS2 / BSIG covered

  • BSI IT-Grundschutz / BSI standards 200-x

  • TISAX covered

  • DORA covered (gap analysis)

  • AI Act covered

  • GDPR / data protection module

  • ISO 27031 covered

  • Create your own catalogues and requirements

  • Mapping between frameworks (integrated management system)

  • Support when standards change

  • Statement of Applicability (SoA) generated from the content

  • Register of requirements and legal obligations

02

Governance & organisation

9 Requirements

  • Role and permission model

  • Permissions at group and department level

  • Multi-tenancy for several legal entities

  • Standard ISMS as a master template for entities

  • Approval workflows for management and owners

  • Configurable workflows

  • Annual planner and cycle planning (ISMS/BCMS)

  • Scales to the required volume

  • Scales with the organisation

03

Assets & protection needs

6 Requirements

  • Asset inventory with categories and structure

  • Protection requirement assessment

  • Inheritance of protection requirements

  • Assisted protection requirement analysis with suggestions

  • Connection to CMDB and asset systems

  • Processes and process map

04

Risk management

10 Requirements

  • Risk analysis and assessment

  • Assets and protection requirements carried into the risk

  • Pre-assessed risks / risk catalogue

  • Threat catalogues (for example BSI elementary threats)

  • AI-assisted suggestions for risks and measures

  • Documented risk acceptance

  • Transfer into measures and tasks

  • Visualisation (heat map, risk matrix)

  • Risk appetite and criticality flags

  • Integrated ISMS and BCMS risk analysis

05

Controls & tasks

8 Requirements

  • Implementation status of controls and measures

  • Effectiveness and maturity with evidence

  • Tasks with recurring reminders

  • Deadline monitoring and notifications

  • Escalation when a deadline is missed

  • Evidence repository

  • Automated technical checks

  • Vulnerability management

06

Document control

7 Requirements

  • Versioning, review and approval

  • Reminders for review dates

  • Automatic list of controlled documents

  • Acknowledgement by employees

  • Automated documents and reports from the data

  • Template library

  • DMS integration (for example SharePoint)

07

Audits & findings

3 Requirements

  • Audit plan and audit programme

  • Audit per control (checklists)

  • Findings turned into tasks

08

Suppliers & third parties

8 Requirements

  • Supplier register with criticality

  • Self-assessment sent to suppliers

  • Recurring assessment based on criticality

  • Third-country transfer and processing agreement per supplier

  • Concentration risk, sub-outsourcing, exit strategies

  • DORA register of information

  • Review of contract clauses (for example DORA Art. 30)

  • Cyber risk check for holdings and small units

09

Incidents & reporting

4 Requirements

  • Incident recording and classification

  • Reporting deadlines for NIS2, DORA and GDPR with reminders

  • Reporting form for employees

  • Connection to ticket and incident systems

10

Business continuity (BCM)

7 Requirements

  • Business impact analysis

  • Graphical view of RTO, RPO and MTPD

  • Damage scenarios and continuity strategies

  • Continuity plans and emergency manual

  • Emergency teams and roles

  • Exercises and recovery tests

  • Alerting, mobile crisis app, offline use

11

Reporting & dashboards

7 Requirements

  • Real-time dashboards

  • KPIs with measurements and charts

  • Your own dashboards

  • Management and CISO dashboard

  • Export to PDF and Excel

  • Connection to BI tools (Power BI, Qlik)

  • Global search across all records

12

People & awareness

3 Requirements

  • Training records

  • User synchronisation from Microsoft 365

  • Onboarding status per employee

13

Integration & technology

11 Requirements

  • REST API

  • Single sign-on with Entra ID / AD

  • Enforced multi-factor authentication

  • Import from Excel, CSV and XML

  • Webhooks and event triggers

  • Integration with process and EAM tools

  • Multilingual (at least German and English)

  • Audit trail and change history

  • No AI training on customer data

  • On-premise operation or export

  • Data portability and exit

14

Hosting, security & vendor

10 Requirements

  • Hosting in Germany or the EU

  • No third-country transfers

  • Development and support in Germany or the EU

  • Vendor holds an ISO 27001 certificate

  • BSI C5 attestation / SOC 2

  • Evidence of the vendor's IT operations and continuity management

  • Encryption, patches, backups

  • Customer-managed keys (BYOK)

  • High availability

  • Data processing agreement under GDPR

15

Support & onboarding

5 Requirements

  • Technical support in the required languages

  • Training for administrators and users

  • Documentation and online help

  • Support during rollout

  • Scalable licence model

Download the full catalogue as an Excel file

All 112 requirements with priorities and owners, ready to fill in. Free, after a short sign-up.

Get the download