Governance, Risk & Compliance (GRC)
Governance frameworks, risk management and compliance programmes.
- Governance frameworks and operating models
- Roles, responsibilities and accountability
- Risk management frameworks, registers and risk appetite
Governance, risk, compliance, cybersecurity, data protection and AI governance, delivered as advisory work sized to your organisation.

Each service page sets out what the work covers, how we approach it and who it suits.
Governance frameworks, risk management and compliance programmes.
Preparation for ISO 27001, ISO/IEC 42001 and related standards.
UK GDPR and Data Protection Act 2018 obligations and privacy programmes.
Governance over how AI is selected, implemented, used and monitored.
Cybersecurity governance and vulnerability management programmes.
View this service: Cybersecurity Governance & Vulnerability Management
Technology risk assessment and the IT controls that manage it.
Preparing your controls and evidence for a SOC 2 assessment.
Support with audits, assurance activity and regulatory readiness.
The standards and regulations our advice is built around. We help you prepare for them, and we do not issue certificates.
Advisory and readiness support only. Independent bodies carry out assessments and issue any certificate.
Our approach
Five steps, from understanding where you are to keeping controls effective as things change.
Understand your organisation, obligations, systems and existing controls.
Find the gaps and risks that matter, and rank them by their effect on you.
Design proportionate controls, policies and documentation to close those gaps.
Support your team in putting the controls and processes into practice.
Review how controls perform, track change and keep improving over time.
Describe what you are trying to achieve and we will tell you where we can help.