Home / Services / GRC
GRC-12 · Governance

GRC

Governance, risk and compliance

Compliance work fails in a predictable way. A consultant writes forty policies, everyone signs them, nobody opens them again, and eighteen months later an auditor asks for proof that the quarterly access review actually happened. Certification is not a document exercise. It is evidence that a control operated over a period of time, and that evidence has to be produced as you go — it cannot be assembled the week before an assessment.

Scope of work

What is included.

For organizations facing a certification deadline, an enterprise client's security questionnaire, or a regulator asking for a risk register nobody has updated in two years.

  • Framework selection and gap assessmentISO/IEC 27001, SOC 2, PCI DSS and NIST CSF mapped against what you already do, so a single control set reports to several frameworks instead of running three parallel programs.
  • Risk managementAn asset-based risk register with named owners, scored likelihood and impact, documented treatment decisions and a review cycle that survives staff turnover.
  • Policy lifecycleDrafting, approval, version control, distribution, attestation tracking and scheduled review — rather than a shared folder of PDFs nobody has opened since induction.
  • Control operation and evidenceThe recurring calendar — access reviews, restore tests, vulnerability scans, awareness training, vendor reviews — plus the evidence capture that proves each one ran on time.
  • Third-party and vendor riskSupplier tiering by the damage they could do, due diligence questionnaires, security clauses for contracts, and ongoing monitoring of the vendors inside your perimeter.
  • Audit managementInternal audit, mock assessment, auditor liaison, and finding tracking through corrective action to documented closure.
Engagement sequence

Four phases, in this order.

The order matters more than the speed. Every phase has an exit condition you sign off before the next one starts.

Scope and select

Decide which frameworks genuinely apply and define the boundary precisely. Over-scoping a certificate is the most expensive mistake in this field and the hardest to unwind later.

Assess and register

Control gap assessment plus a populated risk register with real owners and real treatment decisions — not a template with your logo on it.

Implement and evidence

Controls put into operation with the evidence mechanism built at the same moment, because evidence reconstructed afterwards rarely convinces an assessor and never convinces a good one.

Sustain and audit

Internal audit, management review and mock assessment, then we sit with you through the external audit and handle the findings.

Deliverables

What you receive.

  • Framework gap assessment with scored control status
  • Risk register with owners, treatment plans and review dates
  • Approved policy set with version control and attestation records
  • Compliance calendar and structured evidence repository
  • Internal audit report and corrective action tracker
Tools & standards

What we work with.

  • ISO/IEC 27001
  • ISO 27005
  • SOC 2
  • PCI DSS 4.0
  • NIST CSF 2.0
  • NIST 800-53
  • CIS Controls v8
  • COBIT
  • GDPR
  • HIPAA
  • Compliance automation platforms
Vendor position

We hold no exclusive reseller obligations. Recommendations are made on fit, your team's capacity to operate the thing, and local support availability — in that order.

Questions

GRC, specifically.

How is this different from your cybersecurity advisory service?

Advisory is engineering-led: find the technical gaps and close them. GRC is evidence-led: prove the controls operate, keep the register current, and carry you through an assessment. Most organizations need both, because advisory closes the holes and GRC demonstrates they stay closed. If an auditor is already booked and you can only fund one, start here.

Can you certify us?

No, and neither can any consultancy — that is worth being blunt about. Certification is issued by an accredited certification body following an independent audit. We do the gap assessment, implementation, evidence structure and mock audit, then support you through the real assessment. Any firm offering to sell you a certificate directly is selling something that is not a certificate.

Do we need a full-time compliance hire?

Below roughly 200 staff, usually not. What you need is a named owner with a few hours each week and a calendar that tells them what falls due and when. We build that, train the owner, and review quarterly. Above that size, or in regulated finance, a dedicated role starts to pay for itself.

Next step

Scope your grc engagement.

Send us the shape of your environment. You will get a written scope, a fixed price and a delivery timeline — usually within two business days.

Book an assessment Email us directly

Scoping calls are free · Reply within one business day