Step 1 of 8
Organization Details
Tell us about your organization so we can personalize your risk assessment.
ISO 27001
SOC 2
GDPR
HIPAA
NIST CSF
PCI DSS
ISO 9001
Not sure yet
Step 2 of 8
Business Profile
Help us understand the scale and complexity of your operations.
Organization Profile Required
Annual Revenue
Below Rs10 Cr
Rs10-50 Cr
Rs50-100 Cr
Rs100-500 Cr
Rs500 Cr+
Countries Operating In
1 (India only)
2-5 Countries
5-10 Countries
10+ Countries
☁ Cloud & Technology
Cloud Provider
AWS
Azure
Google Cloud
Oracle
Private Cloud
Hybrid
No Cloud
Step 3 of 8
IT & Cyber Security
Your security posture determines your cyber risk score. Answer honestly for accurate results.
Security Controls High Impact
Multi-Factor Authentication (MFA) deployed?
EDR / Endpoint Detection & Response installed?
SIEM (Security Information & Event Management)?
Security Operations Center (SOC) available?
Testing & Data
Sensitive Data Handled
Customer PII
Financial Data
PHI / Health Records
Intellectual Property
Source Code
Card Data
None
Step 4 of 8
Compliance Status
Tell us your current compliance certifications and audit maturity.
Current Certifications Held
ISO 27001
ISO 9001
ISO 20000
ISO 13485
SOC 2 Type I
SOC 2 Type II
GDPR Compliant
HIPAA
PCI DSS
None Yet
Audit & Policy Maturity
Internal audits conducted regularly?
Information security policies documented & updated?
Security awareness training conducted?
Step 5 of 8
Risk Management
Your risk governance maturity directly impacts your overall GRC score.
Formal Risk Register maintained?
Risk owners assigned for each risk?
Risk treatment plans documented?
Board / Management risk committee exists?
Top Risk Areas (select all that apply)
Cyber Attacks
Data Breach
Regulatory Fines
Vendor Failure
Business Disruption
Fraud
Reputational Damage
AI/Tech Risk
Step 6 of 8
Business Continuity & DR
Resilience planning is critical for surviving disruptions and passing audits.
Business Continuity Plan (BCP) documented?
Disaster Recovery (DR) site available?
DR test conducted in last 12 months?
Step 7 of 8
Vendor Risk & AI Governance
Third-party risks and AI usage are among the fastest-growing risk categories in 2025.
Vendor Risk Management
Third-party security assessments conducted?
Vendor security clauses in contracts?
SOC 2 reports requested from critical vendors?
AI Governance New 2025
AI Tools in Use
ChatGPT
Claude
Microsoft Copilot
Google Gemini
Internal AI
None
AI Usage Policy documented?
AI Risk Assessment conducted?
Sensitive data uploaded to AI tools?
Human review of AI outputs mandated?
Step 8 of 8
Industry-Specific Questions
A few final questions specific to your industry for a precise risk score.
Astra AI is Analyzing Your Responses...
Generating your personalized GRC Risk Assessment Report
Analyzing organization profile...
Calculating cyber risk score...
Evaluating compliance gaps...
Building risk heat map...
Generating executive dashboard...
Preparing recommendations...
Overall Risk Score
--
--
✅ Compliance Score
--%
^ Excellent
Cyber Risk Score
--%
v Review Needed
Open Risks
--
High Priority: --
AI Governance
--%
EU AI Act 2025
Rs Financial Exposure
-- Cr
Potential Loss
Enterprise Risk Heat Map View All Risks ->
CriticalHighMediumLowRare
RareUnlikelyPossibleLikelyAlmost Certain
GRC Maturity Radar
Risk Trend (Last 6 Months) View ->
High Risk
Medium Risk
Low Risk
Compliance Overview View ->
--%
Overall Compliance
Department Risk Score View All ->
Top 10 Risk Register View All ->
| # | Risk | Category | Impact | Likelihood | Score | Trend |
|---|
AI Recommendations View All ->
Need Expert Guidance?
Book a free consultation with our GRC experts and strengthen your organization's resilience.
RK
PS
AV
SM
or call us at +91 73886 90079