Skip to main content

Services

Governance, risk, compliance, cybersecurity, data protection and AI governance, delivered as advisory work sized to your organisation.

Our services

Each service page sets out what the work covers, how we approach it and who it suits.

  • Governance, Risk & Compliance (GRC)

    Governance frameworks, risk management and compliance programmes.

    • Governance frameworks and operating models
    • Roles, responsibilities and accountability
    • Risk management frameworks, registers and risk appetite

    View this service: Governance, Risk & Compliance (GRC)

  • ISO & Compliance Readiness

    Preparation for ISO 27001, ISO/IEC 42001 and related standards.

    • Gap assessment against the requirements of the standard
    • Scoping of the management system
    • Risk assessment and risk treatment

    View this service: ISO & Compliance Readiness

  • Data Protection & Privacy

    UK GDPR and Data Protection Act 2018 obligations and privacy programmes.

    • Data mapping and records of processing
    • Lawful basis and privacy notice review
    • Data protection impact assessments

    View this service: Data Protection & Privacy

  • AI Governance & Responsible AI

    Governance over how AI is selected, implemented, used and monitored.

    • Inventory of AI use and classification by risk
    • AI governance policy and lines of accountability
    • Responsible AI principles turned into working controls

    View this service: AI Governance & Responsible AI

  • Technology Risk & IT Controls

    Technology risk assessment and the IT controls that manage it.

    • Technology risk assessment
    • Design of IT general controls: access, change, operations and backup
    • Control documentation and ownership

    View this service: Technology Risk & IT Controls

  • SOC 2 & Controls Readiness

    Preparing your controls and evidence for a SOC 2 assessment.

    • Scoping against the Trust Services Criteria
    • Readiness assessment and gap analysis
    • Control design and documentation

    View this service: SOC 2 & Controls Readiness

  • Audit, Assurance & Regulatory Readiness

    Support with audits, assurance activity and regulatory readiness.

    • Audit preparation and coordination
    • Support for internal audit activity
    • Assurance mapping across regulatory and framework requirements

    View this service: Audit, Assurance & Regulatory Readiness

Frameworks we advise on

The standards and regulations our advice is built around. We help you prepare for them, and we do not issue certificates.

Advisory and readiness support only. Independent bodies carry out assessments and issue any certificate.

Our approach

A structured approach to governance, risk and compliance

Five steps, from understanding where you are to keeping controls effective as things change.

  1. Step 1: Assess

    Understand your organisation, obligations, systems and existing controls.

  2. Step 2: Identify

    Find the gaps and risks that matter, and rank them by their effect on you.

  3. Step 3: Design

    Design proportionate controls, policies and documentation to close those gaps.

  4. Step 4: Implement

    Support your team in putting the controls and processes into practice.

  5. Step 5: Monitor & Improve

    Review how controls perform, track change and keep improving over time.

Not sure which service you need?

Describe what you are trying to achieve and we will tell you where we can help.