GOVERNANCE
GRC & Compliance
Compliance work should help the business understand its responsibilities and keep important controls working. We help with the practical work behind policies, risk reviews, controls and audit preparation.
Areas we can help with
- Risk assessments and registers
- Policies and procedures
- Control reviews
- Compliance gap assessments
- Audit and certification preparation
MAKE THE PAPERWORK MATCH THE WORK
Policies are useful when people can actually follow them.
We focus on controls that fit the way the organization operates, so compliance does not become a separate exercise that only appears when an audit is due.
01 — Understand
Confirm the requirement and how the organization currently works.
Confirm the requirement and how the organization currently works.
02 — Check
Compare existing practices and evidence with the requirement.
Compare existing practices and evidence with the requirement.
03 — Improve
Close the gaps that matter and make responsibilities clear.
Close the gaps that matter and make responsibilities clear.
04 — Prepare
Get the documentation and evidence ready when an audit or review comes around.
Get the documentation and evidence ready when an audit or review comes around.
WHAT THIS CAN COVER
The exact requirement depends on the organization.
PCI DSS
Support for organizations working with card payment security requirements.
ISO 27001
Support for information security management and related controls.
NDPA / regulatory work
Practical support around data protection and relevant regulatory requirements.
CONTACT
Need help making sense of a compliance requirement?
Tell us what you are working toward.
Contact us