Skip to content
GOVERNANCE

GRC & Compliance

Compliance work should help the business understand its responsibilities and keep important controls working. We help with the practical work behind policies, risk reviews, controls and audit preparation.

Areas we can help with

  • Risk assessments and registers
  • Policies and procedures
  • Control reviews
  • Compliance gap assessments
  • Audit and certification preparation
MAKE THE PAPERWORK MATCH THE WORK

Policies are useful when people can actually follow them.

We focus on controls that fit the way the organization operates, so compliance does not become a separate exercise that only appears when an audit is due.

01 — Understand
Confirm the requirement and how the organization currently works.
02 — Check
Compare existing practices and evidence with the requirement.
03 — Improve
Close the gaps that matter and make responsibilities clear.
04 — Prepare
Get the documentation and evidence ready when an audit or review comes around.
WHAT THIS CAN COVER

The exact requirement depends on the organization.

PCI DSS

Support for organizations working with card payment security requirements.

ISO 27001

Support for information security management and related controls.

NDPA / regulatory work

Practical support around data protection and relevant regulatory requirements.

CONTACT

Need help making sense of a compliance requirement?

Tell us what you are working toward.

Contact us