Disclaimer: Independent educational project. Not affiliated with GoRico. Built by Kaushal Khodifad. Data from public sources; figures are estimates.return to portfolio
Disclaimer: Independent educational project. Not affiliated with GoRico.
TechCorp Solutions
3 Active Programs
TC

Risk Register

Inherent vs residual scoring across the demo risk register.

1

Critical Inherent (20+)

6

Under Active Mitigation

10.24.7

Avg Inherent → Residual

10

Total Risks

IDTitleCategoryInherentResidualStatusTreatmentOwner
RSK-001Third-Party Payment Processor BreachRisk of data breach through payment processing partner Stripe leading to exposure of customer financial data and PCI non-compliance.Third-Party208MitigatingmitigateCISO
RSK-002Ransomware Attack on Production InfrastructureRisk of ransomware infection disrupting production services and encrypting customer data hosted on AWS infrastructure.Technical156MitigatingmitigateSecurity Operations Lead
RSK-003Failure to Achieve SOC 2 Certification by Target DateRisk of missing the Q3 2026 SOC 2 audit window, delaying enterprise sales pipeline and impacting revenue targets.Compliance126MitigatingmitigateCISO
RSK-004Insider Threat - Privileged User Data ExfiltrationRisk of a privileged employee or contractor exfiltrating sensitive customer financial data.Operational104MitigatingmitigateCISO
RSK-005API Authentication Bypass VulnerabilityRisk of undiscovered vulnerability in PayFlow API authentication mechanism allowing unauthorized access to customer financial data.Technical126MitigatingmitigateSecurity Engineering Lead
RSK-006Key Personnel DepartureRisk of losing critical security and engineering staff affecting institutional knowledge and compliance program continuity.Operational96AssessedmitigateVP of People
RSK-007Cloud Service Provider OutageRisk of extended AWS outage impacting availability of PayFlow API and customer-facing services beyond SLA commitments.Technical83AcceptedacceptVP Engineering
RSK-008Regulatory Change Impact - State Privacy LawsRisk of new state-level privacy regulations requiring significant platform modifications to meet varying data residency and consent requirements.Compliance94AssessedmitigateGeneral Counsel
RSK-009Physical Office Security BreachRisk of unauthorized physical access to Austin HQ office resulting in theft of employee devices or exposure of sensitive information.Operational32AcceptedacceptFacilities Manager
RSK-010Open Source License Compliance ViolationRisk of inadvertent use of open source components with incompatible licenses in commercial SaaS product, leading to legal exposure.Compliance42MitigatingmitigateEngineering Manager

Synthetic demo register - the same 10 rows the dashboard heatmap renders, so the two views cannot disagree. Inherent = likelihood x impact before treatment; residual = after the recorded mitigations. Risks you add here score residual = inherent until a treatment is recorded, and live in this browser session only (no persistence in the demo).

↑ Independent educational project by Kaushal Khodifad. GoRico is a real company in the GRC & compliance automation space; this design and the underlying prototype were built by Kaushal as a portfolio study. Not affiliated with, endorsed by, or representative of GoRico's actual product. Data is from public sources. Figures are estimates.

Return to portfolioOpen the live demo