SERVICES

Governance, Risk & Controls

We support risk and control assessments, organise the evidence for internal audit and readiness reviews, and help teams assign, prioritise and track remediation across technology, information security, data and operations.

Services

Focus areas

  • Internal audit support

    Planning, evidence assessment, control testing, work-programme support, findings development and follow-up for internal assurance work.

  • Readiness and gap assessment

    Reviews against agreed criteria from ISO/IEC 27001 or ISO 9001, or relevant NIS2- and DORA-related requirements. This is readiness support, not certification or legal advice.

  • Remediation and action management

    Clear actions with owners, priorities, evidence requirements and closure support for control and audit findings.

When this work is useful

  • Control ownership or evidence is unclear.
  • Audit or assessment findings remain open.
  • A management system or regulatory-readiness programme lacks structure.
  • Controls exist on paper but are not evidenced consistently.
  • Remediation is delayed, duplicated or difficult to report.
  • Incident or investigation findings require control changes.

Typical work product

  • Risk and control matrices
  • Control-test plans and evidence records
  • Gap and maturity assessments
  • Internal-audit documentation and findings
  • Readiness reports
  • Remediation roadmaps
  • Action registers and reporting packs
  • Closure and follow-up evidence

How the work is structured

  1. Define

    Agree the requirements, scope, owners and evidence expectations.

  2. Map

    Map the risks, controls, responsibilities and available evidence.

  3. Assess

    Test the controls against the agreed criteria and record gaps, limitations and priorities.

  4. Improve

    Set actions, evidence requirements, reporting and follow-up.

Contact

Start with the matter.

Describe what the matter is about, the timing, the jurisdiction and the decision, deadline or work product you need support with. We agree the next step before any sensitive information is exchanged.