Signify Playground
73 pieces where the decision is yours and the consequence lands before the explanation does. Nothing is locked. Pick by discipline, or by the time you have actually got.
Clear the search, or widen the discipline back to All.
A piece serving two disciplines appears in both rows, so the board shows 115 placements across 73 pieces.
How real is your ethics programme?
Twenty questions for a quick read, or fifty for a full programme review — across the eight domains of a working ethics programme: code and policy, ownership, training, speak-up channels, investigation, non-retaliation, third parties, and board oversight. Not a values survey — a check on whether the machinery exists and is used.
How ready are you against NIST CSF 2.0?
Twenty questions for a quick read, or fifty for an outcome-by-outcome deep dive — across the six Functions of CSF 2.0, including Govern, the one most self-assessments skip. Not a Tier rating: a map of which outcomes you could actually evidence tomorrow.
How ready is your data privacy function?
Twenty questions for a quick read, or fifty for a full programme review — across the eight domains a privacy function has to hold up: governance and roles, records and lawful basis, transparency, individual rights, retention, vendors and transfers, security, and breach response. Scored, with your weakest domain named.
The Ethics Cup
Five knockout rounds, drawing on all three weeks, so the Final needs what the earlier rounds taught. Each opponent is a temptation rather than a team, every phase has a plausible middle answer as well as a right one, and seven shortcuts across the tournament will get you carded.
Say It Straight
The comfort trade, in both directions: softening a message until it cannot be acted on, and defending before listening. Two conversations — giving hard feedback, then receiving it when it is partly unfair. No turn has an answer that is free on both axes.
The Deadline You Can't Make
The late confession: every move that buys silence is cheap on the day you make it and expensive by the end. Five checkpoints across ten days, two axes — the cost you shift onto other people and what the client believes when you speak. Winnable, and only through telling someone before you had proof.
In Scope?
Silent absorption reads as generosity and quietly destroys the record everyone needs when the budget runs out. Twelve unwritten requests where absorbing, recording, raising and declining are four different answers — and refusing everything is wrong three times.
Whose Words Are These?
Attribution is answered by reflex in both directions: citing to avoid owning a claim, and shipping borrowed work because the borrowing felt small. Twelve items where the four answers are genuinely different and one of them stops the work. See your reflex rate.
Declare It
One disclosure policy applied to every setting is the mistake, in both directions: declaring everything until nobody reads declarations, and declaring nothing where an undertaking was given. Twelve contexts, four answers, three of which are not about disclosure at all.
Run the Number
Implementation cost is compared carefully and run cost arrives after the decision. Twelve technology choices where the deciding number is build, run, exit — or where the two quotes are not for the same thing and the honest answer is that they cannot be compared yet. See your build-cost myopia rate.
Who Banks This?
A saving nobody's budget gives up never appears. Twelve business case lines to sort: bankable cash, real capacity that is not cash, activities and milestones that are not benefits at all, and numbers with no baseline underneath them. See whether your case would still reconcile twelve months in.
Who Owns It?
Every box in an operating model has a name in it, which is exactly why the model looks complete and behaves like it has holes. Twelve capabilities to judge: properly owned, named but powerless, split between two so nobody decides, or orphaned outright. Three questions decide each — can they decide, fund it, and refuse.
Sequence It
A roadmap ordered by appetite fails in month four. Twelve initiatives, each with something specific standing in front of it: a technical prerequisite, a decision nobody has taken, or a team already committed elsewhere — and four that could genuinely start on Monday. See how much of your sequence was wish-order.
The Pilot Trap
A pilot measures its conditions as much as its tool. Twelve that succeeded — some through volunteers, some through support no rollout will reproduce, some with no success criteria at all, and some designed to be believed. See your volunteer-effect blindness before it costs a rollout budget.
Independent Enough?
Independence fails in two directions and only one of them gets talked about. Twelve engagements an in-house function is really offered — work you advised on, a committee seat, a favour for the CFO, a bonus set by the auditee. Take it, safeguard it, hand it to someone else, or say it is not audit's to do; then see whether you were over-cautious or over-comfortable.
Scope the Audit
A scope that covers everything tests nothing. Thirteen candidate objectives for one procure-to-pay audit — some carrying real risk, some already covered by second line, some impossible to conclude on however important they sound, and some that are procedures rather than objectives. Sort them, then see whether your scope would have spent the budget on the testable or the risky.
Root or Symptom
An action written from the wrong cause closes and recurs. Twelve findings, each carrying the operating detail that gives the real cause away — a control that cannot work as built, a team with no hours, an incentive pulling the other way, or a task nobody knew was theirs. Assign the family, then see whether you reached for awareness because it is the cheapest action to write.
Rate the Issue
Severity inflation is directional and it compounds: every finding rated by how annoying it is devalues every honest rating in the same report. Fifteen findings to rate by exposure, four of which the evidence does not size at all. See your inflation rate, and whether you were willing to say a finding could not be rated yet.
Close or Carry
Closing on assertion is invisible — nobody audits the follow-up process. Twelve actions and the evidence offered for each: assertions, partial completions, dashboards without workings, and the case where management did something other than what was agreed. Decide each, then see how green your register would have been.
Grant or Revoke — an access review drill
Twelve rows from an entitlement review: a group identifier with no description, no owner and no last-use data; an undated screenshot supplied by the system owner whose access is under review; a leaver whose user account was disabled and whose service principal still holds a write-capable API key. Approve, revoke, re-scope, or say the evidence does not reach it — then see your rubber-stamp rate, because a review that approves rows it could not have judged still produces evidence that the control operated.
Whose Call — a decision-rights drill
Twelve decisions and four possible owners: the full board, a committee, management, or the shareholders. Appointing the chief executive, setting an individual package inside an approved policy, choosing a payroll vendor, amending the charter, sequencing a programme the board already approved. Place each one — then see your over-reach rate, because pulling decisions up to the full board feels like diligence and is how a board becomes both overloaded and unable to hold anyone to account.
Who Can See This — a cloud exposure drill
Twelve cloud and SaaS configurations, one question each: who can actually reach this? A wildcard bucket policy, a dashboard published under a label that says only people with the link, an ACL granting AuthenticatedUsers — which in that provider means any account in the provider, not in your tenant — and a default sharing setting that applied itself to a folder of HR case files. Public, anyone with the link, tenant-wide, or genuinely restricted, then see your false-assurance rate.
Patch or Wait — a vulnerability triage drill
Twelve findings competing for one finite queue: a 9.8 remote code execution nobody can reach without credentials, a 6.1 authentication bypass that is internet-facing with a published exploit, a container image that was never deployed, a domain admin account with a 2019 password and no CVE at all. Emergency, next cycle, scheduled or accept — then see your over-escalation rate, because escalating everything is the same as prioritising nothing and it spends the credibility you need the week it is real.
Ship or Tune — a detection-writing drill
Twelve proposed detections and one call on each: a rule keyed to procdump.exe that any rename evades, an alert on every PowerShell execution in the estate, a threat-feed lookup that is stale by construction, and a handful that are genuinely ready to ship. Widen it, narrow it, rewrite it or ship it — then see how often you waved one through, because a rule that matches today's sample and nothing an attacker would do differently tomorrow is carried on the coverage report as though it worked.
The Request Clock — a subject-access scoping drill
One subject access request and fourteen things the search turned up: an e-mail thread of colleagues' opinions about her, the team's absence spreadsheet, privileged advice, a manager's notebook at home, CCTV with eleven other faces in it. Disclose, redact, withhold under an exemption or rule it out of scope — then see your over-disclosure rate, because handing over a third party's data is a breach you commit while satisfying somebody else's rights.
Keep or Kill — a retention and deletion drill
Twelve things your organisation is still holding and one call each: rejected CVs from fourteen months ago, card numbers kept for smoother returns, a leaver's entire mailbox, analytics with full IP addresses on a default nobody chose, a training set with names in the free text. Delete now, keep, legal hold or minimise — then see your over-retention rate, because every extra year is breach surface and discovery risk bought for nothing.
The Control Statement Clinic — make it testable
Twelve control statements lifted from the shape of real catalogues. For each, name which of the seven attributes it fails to pin down — who, what, when, how, evidence, frequency, owner — then choose which of three rewrites a tester could work from. The wrong rewrites are the two real failure modes: longer and more confident but still unfalsifiable, and precise about the wrong activity entirely.
Rely or Reject — an evidence-reliability drill
Eighteen pieces of evidence, each with the provenance you would actually have: an undated screenshot, a client Excel extract, the same extract with the extraction observed and the row count footed, a SOC 2 Type 1 offered for operating effectiveness, a sample drawn from an unvalidated population. Call each one rely, rely with caveats or reject, then name the provenance reason behind it — the completeness-and-accuracy intuition that IPE testing lives on.
Personal, or Not? — a data-scope drill
Twelve things a system holds and one call each: personal data, not personal, or only in context. Hashed e-mail addresses, a dynamic IP, an employee number with no name column, an inference about pregnancy. You are scored on accuracy and on the number that matters more — your false-negative rate, because ruling identifiable data out of scope is the error that ends in a notification.
Confidently Wrong — naming the AI failure mode
Eight answers from a model that sounds equally sure of all of them: an invented case with a real docket number, a genuine Article cited for content it does not contain, a penalty figure from the draft Regulation, a headcount it has no way to know. Sort each into fabrication, staleness, faulty reasoning or should-have-declined — because each one needs a different control, and “the AI was wrong” is not a finding anyone can act on.
Blast Radius — an identity attack-path sim
A service-desk account got phished and has no admin rights of its own. Walk the path it can actually take through the identity graph, then cut exactly three edges. Disabling the breached account reduces the reach by nothing — group nesting and a service account nobody owns built all of it.
The Alert Queue — 40 alerts, one analyst
One shift, forty alerts, twelve alert shapes — and every real alert paired with a near-identical benign twin whose severity rating is no help at all. At the end you get the number nobody measures: how your accuracy on the final ten compared with your first ten.
Plan the Year — an audit-plan allocation sim
1,800 audit hours, fourteen auditable entities and no way to cover them all in depth. Set the depth on each one, then the year delivers its eight surprises. Half the mark is what you caught — the other half is whether the plan was defensible before you knew any of it.
How managed is your third-party risk?
Twenty checks for a quick read, or fifty for a full portfolio review, across the eight domains of a managed third-party programme — governance, inventory and tiering, due diligence, contracts, monitoring, concentration and exit, the fourth-party chain, and incidents. Scored, with your gaps named.
Starting XI — pick your cyber line-up
Your security stack is a football team. Choose a formation, fill the eleven from a transfer budget, then watch the attack play down the pitch and see which channels get breached.
Road to the Final — a knockout tournament
Pick one of five sides — cyber, audit, AI governance, resilience or privacy — and go from the Round of 32 to the Final. Every tie is a real decision under pressure: win the matches, mind your discipline, and lift the trophy.
Tie-Out — a forensic deduction
Management hands you a binder and a story. Tie every claim to the evidence — corroborate, contradict, or flag it unsupported — then follow the contradictions to the truth.
The Coalition Vote — 5-day vote-whip simulation
Five business days to the annual meeting. Eight named institutional holders own 41% of the float; ISS and Glass Lewis route most of the rest. You have ten moves to land. Pick the ones that move the holders you can actually move — and skip the ones that look like work but are not.
The Acquisition Dossier — 7-day M&A diligence sim
$1.4B target. Seven business days of diligence before the LOI lapses. Ten possible review actions; seven hidden red flags buried across the target. The board recommendation you write today is the document the minutes record two years from now — when one of those flags becomes a 10-K item or a class-action complaint.
The Regulator’s Interview — SEC enforcement deposition sim
You are seated in the SEC enforcement field office for a “voluntary” interview. Counsel is present. Ten questions across friendly openers, memory probes, restating, impeachment, and the concession trap. The traps are rarely in the hostile questions. Three scores moving silently: cooperation, accuracy, discipline.
The Material-Weakness Memo — SOX 404 disclosure sim
Three weeks to the 10-K. The auditor calls: material weakness in revenue cut-off. Seven rounds across investigative scope, Item 9A clause assembly, restatement, NT-10K, market sequencing, and the audit-committee meeting. Three hidden scores: SOX 404 conclusion, investor confidence, class-action probability.
The Ransom Decision — a 7-phase ransomware sim
2:14am. The actor wants $14M in BTC within 72 hours. Seven phases, seven commitments — and every phase locks in a decision before the truth that matters most is visible. OFAC, insurance, backups, the payment itself. The mechanic is the lesson.
The Model Did Something — an AI incident under uncertainty
An AI claims model may be harming people and nobody knows why. Eight phases, scarce attention, four advisors who are each reliable about one thing and wrong about another, and a debrief that scores your judgement rather than your luck.
The Disclosure Window — SEC Item 1.05 simulation
3:47am, the CISO calls. The SEC’s four-business-day clock just started. Twelve checkpoints across ninety-six hours. Facts arrive, decisions lock paths, the room shrinks. Two scores move all night — regulatory exposure and stakeholder trust.
The Activist Letter — a 14-day proxy timeline
An activist letter dropped this morning with four demands. Top holders are reading it; proxy advisors are circling. Fourteen days, four parallel stakeholder tracks, one move per day. Some moves close the door behind them — read carefully.
The Use-Case Gate — an AI governance committee sim
Eight AI proposals on the committee’s agenda. Approve, reject, or conditional with the right conditions — not the conditions that just sound governance-flavoured. Two scores move in opposite directions all day; the easy way out in either direction is the trap.
The Earnings Hot Seat — Reg FD under live Q&A
Eight named analysts — friendly, hostile, naive, sharp. Three answers each, four metrics moving at once. Some questions reward rich specificity; others are Reg FD traps where the same kind of answer ends careers.
The Prompt Lab — prompting for internal auditors
Seven real audit tasks, four prompts each. Pick the one a careful auditor would actually send — the tempting answers are the wrong ones. A genuinely hard one.
Term Match — a terminology memory game
Flip cards to pair each term with its definition across cybersecurity, GRC, internal audit and strategy — and reveal a fact with every match.
Mind the Gap — a transformation-sequencing game
Get a change program across the valley between vision and value. Sequence the moves, mind your momentum, and don’t let the big bets fire before their foundations.
Five Moves Ahead — a competitive-strategy war-game
Out-think an adaptive rival across five moves. Read its temperament, refuse the price war, and compound value — or watch it read you first.
The War Room — an incident-command sim
Take command of a major outage and move a finite team across recovery, customers, the regulator clock and staff — round by round, before something breaks.
Agree the Finding — an audit negotiation
Present a real finding to a department head who pushes back. Hold your credibility without losing the room — every reply moves two meters.
Build & Defend — design a control set, then get attacked
Spend a finite budget on the controls you choose, then watch a real attack sequence test your design — and see what held and what got through.
Classify the Use Case — EU AI Act Sorter
Sort real AI systems into prohibited, high-risk, limited and minimal — then see where the Act actually puts each one, and the Article that decides it.
Which Is Riskier? — a calibration drill
Pairwise calls on residual risk. Find out where your instinct is sound and where the scary words are skewing your judgment.
The Breach Room — a C-suite tabletop
Run a massive US data breach as the board. Drag the right decisions onto the table and learn, round by round, where boards hold the line.
Build a Business Analysis CoE
Pick a 20-question quick scan or a 50-question deep dive across the eight domains of a high-performing Business Analysis CoE — scored, with a strong-practice blueprint for where to invest next.
How governed is your AI & automation?
Pick a 20-question quick scan or a 50-question deep dive across the eight domains a real AI risk assessment must reach — mapped to recognized frameworks. Get a maturity score, a radar chart and exactly where your gaps are.
Rate the Risk
Read the context for each area, then set the risk level — Low to Critical. The scary ones are often fine; the boring ones are sometimes on fire. Rate the residual risk.
Are you EU AI Act-ready?
Pick a 20-question quick scan or a 50-question deep dive mapped to the EU AI Act — risk classification, prohibited practices, the high-risk obligations, transparency, GPAI duties, conformity and post-market monitoring. Scored, with exactly where your gaps are.
The Practitioner's Scramble
Read the clue, then tap the ringed letters in order to spell the term. Four packs across governance, risk, audit and security — forty terms in all.
The Practitioner's Crossword
Four full puzzles from the language of cyber, GRC and internal audit. Fill the grid, check yourself, then come back for a different set of answers.
GRC Maturity Assessment
Pick a 20-question quick scan or a 50-question deep dive across the eight domains of a mature GRC program — scored, benchmarked, and pointed at your biggest gaps.
Are You Actually DORA-Ready?
Pick a 20-question quick scan or a 50-question deep dive across the eight domains of DORA readiness — governance, ICT risk, incident reporting, resilience testing and third-party risk. Scored, with exactly where your gaps are.
Auditing the Machine
Take the lead auditor’s chair on an AI loan-decisioning model. Scope it, risk-rank it, test it for real, and defend your opinion to the board.
Tabletop: Friday-Night Ransomware
You're the incident commander. Branching decisions, a nervous board, and a debrief that scores your calls.
Remediation Board: GDPR
A fintech DPO sim across three difficulty levels: triage eight live GDPR findings, build a risk-led plan under budget, then survive the quarter’s real-world events.
Remediation Board: US Privacy
The fintech remediation board for US privacy: triage eight live CCPA/CPRA findings across three levels, then survive the quarter’s enforcement events.
Remediation Board: Saudi PDPL
The fintech remediation board for Saudi PDPL: triage eight live findings across three levels, then survive the quarter’s SDAIA-driven events.
S/4HANA Cutover Sim
Run the final week before go-live and keep the controls intact under pressure.
Phishing Triage: 60 Seconds
Six inboxes, a ticking clock. Quarantine, escalate or release — and watch your false-positive rate.
Inbox Under Siege
The flagship. A working email client, the hour before a payment run, and eight messages — some written by an AI adversary. Inspect, verify, and decide what to trust.