GRC Learning AcademyEnterprise documentation
GRC for Insurance · Official academy

Operate governance, risk, and compliance with confidence.

Role-based learning, verified operating procedures, real product walkthroughs, workflow diagrams, and technical reference for the complete insurance GRC lifecycle.

Last reviewed 10 Aug 202639 courses7 labs8 visual guides
SYSTEM MAP 01GRC operating model
Every activity traces from governance intent through control operation, assurance, and accountable remediation.

Getting started

Understand the app, your role, and the safest route to productive work in under 20 minutes.

Before you begin

Use your assigned role. Do not work around ownership or lifecycle controls. “My” views are intentionally scoped to records assigned to you.

01

Confirm your role

Identify whether you operate as GRC Admin, Risk & Control Owner, Auditor, Manager, View Only, or platform Admin.

Compare roles
02

Open the right workspace

Start with My Workspace, Auditor Workspace, or the relevant dashboard before entering a full table.

Tour workspaces
03

Learn the lifecycle

Understand ownership, statuses, dates, evidence expectations, and automation behavior before updating records.

Review procedures
04

Complete your academy

Follow the role path, complete hands-on exercises, pass assessments, and finish the capstone.

Choose academy

Navigation model

SurfaceUse it for
Role workspacePrioritized assigned work and actions
Dashboard viewOperational monitoring and exceptions
TableFull controlled record management
DocumentPolicy, setup, and operating guidance
WorkflowAutomated routing and record creation

First-week checklist

  • Open every workspace available to your role
  • Locate one assigned risk, control, audit, or finding
  • Inspect a linked evidence record
  • Review overdue and due-for-testing views
  • Complete the four foundation courses
  • Run one sandbox workflow lab

Role academies

Curated learning paths aligned to accountability, system access, and operational outcomes.

Shared foundation

Four essential courses establish a common operating vocabulary and safe working practices.

Operating procedures

Verified step-by-step procedures for the most important GRC activities.

LIFECYCLE 02Risk lifecycle
From risk identification through treatment and monitored residual exposure.
LIFECYCLE 03Control testing lifecycle
Scheduled testing, evidence review, effectiveness decision, and response.

Product walkthroughs

Annotated, privacy-safe views based on the live app. Select any view for a guided tour and a larger inspection mode.

Workflows & automation

Understand exactly what triggers, what is checked, what is created, and how duplicate prevention protects the record set.

Active workflow

Control Failure Opens Finding

When a control changes to Ineffective, the workflow searches for an existing non-Closed Control Failure finding before creating exactly one linked finding.

Trigger
Controls effectiveness changed
Guard
Effectiveness = Ineffective
Duplicate check
Same control + source + non-Closed
Fallback owner
GRC Admin
Active workflow

Serious Incident Opens Finding

When an incident is created or severity changes to High or Critical, the workflow creates one linked Incident finding if none remains open.

Trigger
Incident created or severity changed
Guard
Severity = High or Critical
Duplicate check
Same incident + source + non-Closed
Fallback owner
GRC Admin
PROCESS 04Audit to finding
Independent assurance becomes accountable remediation with evidence-backed closure.
SEQUENCE 05Serious incident automation
Trigger, severity guard, duplicate search, owner fallback, and finding creation.

Scenario labs

Data model

The authoritative object map, relationship rules, lifecycle states, and ownership semantics.

RELATIONSHIP MAP 06Core object relationships
Risks are mitigated by controls, validated through evidence and audits, and corrected through findings and remediation.
STATE MACHINE 07Remediation states
Only verified, evidence-backed resolutions should progress to Closed.
RESPONSIBILITY 08Role RACI
Accountability remains explicit across risk, control, audit, and remediation activities.

Troubleshooting

Diagnose behavior systematically, preserve history, and escalate with the evidence needed for a fast resolution.

Universal diagnostic decision tree

  1. ScopeIs the issue one user, one record, one view, or the whole app?
  2. AccessConfirm organization, app, branch, role, ownership, and lifecycle state.
  3. DataVerify field inputs, relationships, dates, statuses, and active filters.
  4. AutomationCheck trigger condition, duplicate guard, owner fallback, and processing delay.
  5. EvidenceCapture expected result, actual result, URL, record ID, time, and screenshots.
  6. EscalateSend the smallest complete evidence pack to the correct accountable role.

Glossary

Shared definitions for governance, risk, control, assurance, incident, and remediation work.

Release notes

Documentation and learning experience updates.

10Aug
2026
Current

Enterprise academy launch

  • Introduced Salesforce-style documentation architecture and global command search.
  • Added six role academies, 39 courses, seven scenario labs, and persistent progress.
  • Added eight system diagrams and eight annotated product walkthroughs.
  • Documented workflows, object relationships, lifecycle states, ownership rules, and evidence standards.
  • Added responsive, dark-mode, keyboard, print, and reduced-motion support.
GRC Learning Academy

Enterprise operating guidance for GRC for Insurance.

Back to topOpen appContent date: 10 Aug 2026