| name | grc-risk-treatment-diagram |
| description | Use when creating a draw.io diagram for risk intake, scoring, treatment, exception approval, residual risk, and monitoring workflows in a GRC, security, audit, compliance, privacy, cloud, or risk context. |
| allowed-tools | Write, Bash, Read, WebFetch |
GRC risk treatment diagram
Use this skill to structure the GRC content and visual pattern for risk intake, scoring, treatment, exception approval, residual risk, and monitoring workflows. Then use the drawio skill to generate the native editable .drawio file and optional PNG/SVG/PDF export.
Common Requests
- risk register lifecycle
- vulnerability-to-risk workflow
- vendor risk acceptance
- policy exception approval
Recommended Elements
Include these when relevant:
- risk source
- assessment
- inherent/residual score
- treatment choice
- owner
- approver
- due date
- monitoring
Recommended Output Pattern
Produce a Decision tree or risk treatment lifecycle. Choose a layout that matches the audience:
- Executive: compact lifecycle/capability view with business impact labels.
- Auditor/assessor: explicit evidence, owner, control, cadence, and scope labels.
- Practitioner/engineering: operational systems, data paths, automation, failure/exception paths, and implementation detail.
draw.io Instructions
- Load and follow the
drawio skill.
- Generate native mxGraphModel XML directly. Do not generate Mermaid as the final artifact.