Capability
Governance, Risk and Compliance
Governance is what stops security from being a series of projects. It is the routine that keeps controls in place after the consultant leaves.
At a glance
- Technical compliance support, not legal advice
- Risk register with owners and review dates
- Evidence produced as work happens
- Questionnaire and audit preparation
Risk and policy
A risk assessment identifies what could realistically go wrong, how likely it is, what it would cost, and what treatment is proportionate. The output is a register with owners, ratings, treatment decisions and review dates — including risks the organisation deliberately accepts, recorded as accepted.
Technical policies support that: acceptable use, access control, change management, incident response, vendor management, data handling and, increasingly, AI usage. Policies are only useful if they describe what actually happens, so we write them against real practice rather than importing templates.
- Risk assessment and maintained register
- Technical policy set aligned to practice
- Change management with approval and rollback
- Vendor and third-party assessment
- AI and data governance boundaries
Controls and evidence
Most compliance failures are evidence failures. Access is reviewed but not recorded; restores succeed but are not logged; onboarding is consistent but undocumented. We build evidence collection into operations so it costs almost nothing, rather than reconstructing it under deadline.
- Control mapping and gap analysis
- Access review records with reviewer and date
- Restore test logs and patch compliance reporting
- Training completion and incident records
- Remediation tracked to closure
Assessments and questionnaires
Client security questionnaires and insurer applications ask specific technical questions. We help you answer them accurately — including answering 'no' with a dated remediation plan where that is the truth. Overstating a control creates contractual and insurance exposure that far exceeds the discomfort of an honest answer.
We are not a certifying body and do not issue attestations. What we provide is the technical work and evidence that lets you or an assessor reach a defensible conclusion.
Keep exploring
Related Oakville services
Most engagements combine several of these. Follow the thread that matches the problem you are trying to solve.
Questions
Frequently asked questions
- Do you provide legal or privacy advice?
- No. We handle technical controls, configuration and evidence. Legal interpretation, breach notification decisions and policy language belong with your counsel or privacy advisor.
- How is this different from an audit?
- An audit assesses the current state independently. GRC support is the ongoing work of designing, implementing and maintaining controls and evidence. Where we do both for one client, the audit is performed by engineers separate from the operational team.
- Where should we start?
- A gap analysis against the requirements you actually face. It usually takes two to four weeks and tells you what remediation will involve before you commit budget.
Make compliance a routine, not a scramble
Controls implemented, evidence collected as work happens, and a register someone actually owns.