# GRC practice library: personal exercises

> A practical learning path for risk owners, compliance and control specialists, auditors and reviewers, from evidence to verified action.

_Updated: 2026-10-06_

GRC Suite connects risk, compliance, internal controls, audit and corrective work inside Railbase. Start with a business objective and an accountable person; follow the evidence through review to a saved result.

The expanded curriculum contains 40 interactive lessons across the GRC components, including the 31 additional workshops below. Availability depends on the installed component release and your role. These are personal practice exercises: a saved answer is not evidence that a live business workflow has been completed. Eight English video lessons are prepared locally, including the four additions below. They do not yet demonstrate all of the expanded curriculum and are not published here.

## Video learning path

The four main process videos cover risk treatment, internal control from design through testing and the period conclusion, compliance investigation, and audit through the issued report. The following additions use the updated risk workspace, explain each responsibility change and verify the saved outcome:

| Additional video | End-to-end outcome | Duration |
| --- | --- | --- |
| From configured scales to an approved assessment | Head of Risk defines the scales; the risk owner enters measured values; assigned reviewers approve the calculated result. | 4:07 |
| From a transfer proposal to an approved response | Insurance expert documents conditions and retained exposure; Head of Risk decides; the owner verifies the accepted response. | 2:48 |
| From an indicator breach to a recorded risk review | Follow an existing completed case from the approved rule and observations through the linked reassessment and recorded decisions. | 2:43 |
| From a risk event to a reconciled loss | Preserve gross loss, received and expected recovery; submit a period reconciliation and retain the approved limit comparison. | 3:04 |

These recordings use fictional company data. They contain English narration, captions and a Railbase introduction and closing; they do not state prices. The indicator video walks through a completed case, while the loss video submits a new reconciliation against existing entries. Interactive practice remains available in the application without waiting for video publication.

## Before you start

Your operator installs the licensed GRC Product in Railbase. Sign in with your own identity, select the intended company and open **Help · Tutorials**, then choose **Product practice** in the topic filter. The library shows lessons provided by your installed release and role. Search for the lesson title below. If a lesson is missing, ask the operator to check the installed GRC release and your company role; a site administrator account alone does not grant company access.

The interactive lessons use fictional **Acme** examples and English or Russian instructions (other interface languages use the English lesson text), like Railbase's own learning library. You can pause, resume after reloading and restart a lesson. Your answers are personal to you and the selected company. Practising another person's review does not give you that person's real permissions. The exercises do not create real risks, cases, payments, workflows or approvals.

## Follow the learning path

| Lesson | Practise as | Result of the exercise |
| --- | --- | --- |
| **GRC: follow an issue to verified closure** | GRC team and business owners | A source-and-scope record, accountable handoff and evidence-based closure plan. |
| **Risk management: from register to review** | Risk owner, action owner and risk expert | Identification, supported assessment, response and acceptance of the action result by its assigned reviewer. |
| **Internal Control: from process to follow-up** | Internal Control expert | A plan covering process, risks, coverage, owners, versions, testing and sources. |
| **Build a risk-control matrix** | Internal Control and business owners | A reviewed practice matrix with separate process and control ownership. |
| **Assess control design** | Internal Control expert and reviewer | Design criteria, evidence, limitations and a reviewed conclusion. |
| **Select controls for a testing plan** | Expert, manager and function head | Explicit selection, justified exclusions, assignments and plan approval. |
| **Compliance: investigate and resolve a case** | Compliance expert and function head | Applicable obligation, supported case review and corrective-work plan. |
| **Audit: from finding to reviewed report** | Audit team, reviewer and action owner | A scoped finding, verification of the owner's evidence and review of the exact report revision. |
| **Smith: review a proposal before using it** | GRC expert and authorised reviewer | A bounded request, rejection of an unsupported claim and a human-review plan. |

Start with the GRC lesson, then follow the lessons for your actual job. Existing Risk and Internal Control lessons retain their established role restrictions. The four cross-functional GRC lessons are available to GRC Product roles; all business operations keep their own access checks.

## Additional process workshops

These workshops extend the introductory learning path. Each has a scoped case, a decision that must be supported by evidence, and a saved result to verify after reopening. Actual business operations require the relevant company and object assignments.

| Workshop | Responsibilities practised |
| --- | --- |
| **Sources: deliver a verified snapshot** | Risk expert, Head of Risk |
| **Risk: approve a method and assess consistently** | Head of Risk, Executive, Risk owner |
| **Risk: respond to an indicator breach** | Risk expert, Risk owner, Head of Risk |
| **Risk: decide on appetite and acceptance** | Risk expert, Head of Risk, Risk owner |
| **Risk: reconcile an event, loss and recovery** | Risk owner, Risk expert, Head of Risk |
| **Risk: complete an assessment campaign** | Risk expert, Risk owner, Head of Risk |
| **Finance: approve the basis for risk valuation** | Risk expert, Head of Risk, Risk owner |
| **Finance: fund a risk response and reconcile costs** | Risk owner, Head of Risk, Action owner |
| **Risk: evaluate transfer and retained exposure** | Insurance expert, Head of Risk, Risk owner |
| **Compliance: resolve a gift and conflict declaration** | Risk owner, Compliance expert, Head of Compliance |
| **Compliance: assess outside interests and related parties** | Risk owner, Compliance expert, Head of Compliance |
| **Compliance: resolve a screening match** | Compliance expert, Head of Compliance |
| **Compliance: test an obligation under its effective policy** | Compliance expert, Head of Compliance, Action owner |
| **Compliance: turn a measured alert into a supported case** | Compliance expert, Head of Compliance |
| **Compliance: verify corrective work before closing an issue** | Action owner, Compliance expert, Head of Compliance |
| **Risk: qualify an employee report** | Risk owner, Risk expert, Head of Risk |
| **Risk: transfer responsibility and preserve history** | Risk expert, Head of Risk, Risk owner |
| **Risk: correct or retire an accepted record** | Risk owner, Head of Risk, Risk expert |
| **Internal Control: establish and test a corporate control** | Internal Control expert, Head of Internal Control |
| **Internal Control: build a complete period assessment** | Internal Control expert, Head of Internal Control, GRC executive |
| **Internal Control: test, remediate and retest** | Internal Control expert, Head of Internal Control, Action owner |
| **Internal Control: retain source editions and execution evidence** | Internal Control expert, Head of Internal Control |
| **Internal Control: prepare a supported management attestation** | Internal Control expert, GRC executive, Head of Internal Control |
| **Internal Control: review the reporting and certification package** | Internal Control expert, GRC executive, Head of Internal Control |
| **Audit: approve a risk-based plan within capacity** | Audit expert, Head of Internal Audit |
| **Audit: resolve a finding through verified follow-up** | Audit expert, Head of Internal Audit, Action owner |
| **Audit: verify assurance for the stated period** | Audit expert, Head of Internal Audit |
| **Audit: complete team, partner and quality review** | External audit team, Audit partner, Engagement quality reviewer |
| **Audit: correct an accepted result without erasing history** | Audit expert, Head of Internal Audit, GRC executive |
| **Smith: take a source-bound proposal to a human decision** | Internal Control expert, Head of Internal Control |
| **Smith: cancel or withdraw a proposal with retained history** | Internal Control expert, Head of Internal Control |

## Work through a lesson

1. Open the lesson and read its fictional evidence and expected output.
2. Select **Start workshop**, complete the highlighted task and save it. Available selectors refer to the practice roster, not the live employee directory.
3. For a supported-decision question, read the evidence before choosing. An unsupported conclusion produces an explanation and leaves the task open. Correct it and retry.
4. Pause when needed. Reopen the lesson or reload to confirm that your saved answers and current task remain available. A cancelled or unsaved edit is not a completed step.
5. Finish the last task and inspect your saved record and history. Restart only when you intend to repeat the exercise; the confirmation prevents an accidental reset.

If a save fails, keep your answers and retry. If another tab changed the same lesson, reload the current revision before continuing. Repeating the same save must not advance the lesson twice. Switching company gives you that company's separate learning record.

## Set up and apply risk assessment methods

The Head of Risk opens **Assessment methods → Prepare a method**. The full-page editor defines the number of likelihood and impact bands, labels, units, boundaries and the resulting level for each heatmap cell. Choose **Numbers — automatic placement** to classify measured values within those boundaries. The first band includes the minimum; exact upper boundaries belong to the lower band. Out-of-range values are rejected, and missing inputs remain unknown. Another authorized decision maker approves the revision through Core. **Open reference** shows the approved scales and criteria without editing controls.

A risk owner opens **My risks → Assessment and response → Prepare assessment**, chooses an approved method and enters the likelihood and impact values in the configured units. The graph highlights their band and calculates the result automatically; category-based methods instead allow selection of the stated coordinates. The method supplies the approach and scales; the cell supplies the resulting risk level. Low and High describe that result, while risk classification groups risks by subject. Changing the method clears the old coordinates. Record the evidence and limitations, submit the assessment, and verify its saved result after the assigned approvals. A new draft method does not replace the approved reference.

## Apply the process to real work

Use your real workspace and authority after the exercise. Select the company, open the assigned object and inspect its current version and scope. Retain the source identity, period and version when evidence passes between workspaces. Repeated delivery is not a second business fact; missing or stale evidence is not a positive control result.

Owners confirm facts and perform corrective actions. The person assigned to check the result examines the evidence and either accepts it or returns it with a reason. The workflow determines who can make that decision; the action owner cannot approve their own work where separation of duties is required. A new control design is not proof that it operated; a completed action is not automatically a closed finding. Review the exact report revision being issued and retain its decision history.

Check the whole result: **your role → your actions → the visible outcome → the saved state after reopening**. Inspect the status, linked evidence, ownership, version and history. If access is denied, ask for the required scoped assignment rather than using another person's identity. If delivery fails, inspect the error and retry the existing operation instead of duplicating the business object.

## Use Smith with human review

The Smith lesson uses a fixed proposal and **does not call a model or spend AI credits**. Real Smith execution requires an operator-configured and approved model connection, an admitted context policy and the appropriate company/object permissions. A local test connection is not approval to send customer data.

Inspect the evidence behind each suggestion. Accepting drafting assistance does not assign owners, publish a matrix, certify effectiveness or sign a report. Keep those decisions in the authorised human workflow. If the provider is unavailable or a request is cancelled, inspect the saved request status before retrying.

## Purchase and deployment

The [GRC guide](/en/learn/grc-suite) shows current availability and the approved offer. New GRC purchases use one company subscription: the greater of USD 99 and 0.5% of monthly company revenue, with the complete GRC capability and 500 audit engagements started per contract year. Previously accepted grants remain unchanged. Purchase uses a verified company and an authorised billing account; prices and applicable tax are confirmed before payment. Individual components have no separate checkout.

[GRC offer](/en/products/grc-suite) · [Railbase learning](/en/learn) · [Business Suite scope](/en/learn/railbase-suites) · [Deployment choices](/en/products/core#deployment)
