GOVERNANCE & RISK · CASE STUDY
GRC Risk Portal
A business application connecting risk ownership, mitigation and accountable collaboration.
MY CONTRIBUTION
Designed and developed major portal functionality and enhancements: risk workflows, department-based access, mitigation collaboration, comments, notifications, deep links, KRIs and role-aware editing.
Users — GRC & Cybersecurity, GRC administrators, department Chiefs, Risk Champions, department users and authorized management.
The business problem
Risk registers and email discussions did not keep responsibility, mitigation actions and review context together.
How the solution works
- 01Risk
- 02Mitigation
- 03Department review
- 04Comment
- 05Notification / open risk
- 06GRC oversight
Access is part of the business logic: global visibility is different from department visibility, and viewing a record does not imply permission to edit every field.
What I designed and developed
- Risk register · Ownership, likelihood, impact, residual risk, response, mitigation and departmental responsibility.
- Scoped access · Global or assigned-department visibility, with edit permissions controlled by role.
- Mitigation review · Responsible departments review actions and exchange traceable comments with GRC.
- Notifications & deep links · Contextual messages connect the recipient directly to the relevant risk and mitigation.
- KRIs · Corporate / project views, ownership, appetite, limits, escalation triggers, actual values and role-restricted fields.
- Governance records · Permission-aware incidents, policy / procedure documents and filtered risk exports.
Business improvement
- Centralized risk information with controlled departmental visibility.
- Traceable mitigation discussions and less fragmented email communication.
- Standardized KRI management, clearer incident visibility and permission-aware exports.
Original solution technology
Power Apps · SharePoint · Power Automate · HTML / CSS · Deep links
Launch the demo to explore connected workflows with synthetic data. Permissions and notifications are simulated locally—not production services or real security enforcement.