ServicesA full resume of GRC services.
Hands-on work across the governance, risk and compliance lifecycle - scoped to what you need, delivered by the person you hire.
01
GRC program buildout
Stand up or mature an IT governance, risk and compliance function that the business can actually run.
What's included
- IT risk register and IT control register design and upkeep
- Control ownership, narratives, and walkthrough standards
- Policy design: cybersecurity, disaster recovery, change management
- GRC tool selection and rollout (AuditBoard)
- Control and evidence-collection automation
Frameworks and tools
NISTCOSOISOAuditBoard
DeliverablesRisk and control registers, policy set, GRC operating model, tooling roadmap
02
SOX 404, J-SOX and ITGC
End-to-end IT general controls work for public companies and companies preparing to go public.
What's included
- Scoping of in-scope applications and infrastructure
- Walkthroughs, narratives, and process flows
- Design and operating effectiveness testing
- Deficiency evaluation: deficiency, significant deficiency, material weakness
- Coordinating external-auditor reliance to cut duplicate testing
Frameworks and tools
SOX 404(a)/(b)J-SOXITGCPCAOB
DeliverablesScoping memo, test workpapers, deficiency assessments, remediation roadmap
03
Audit and certification readiness
Get ready before the real audit, so auditors get consistent, credible answers up front.
What's included
- SOC 1 and SOC 2 readiness assessments
- SOX and NIST readiness assessments
- Audit evidence execution and validation
- External auditor and regulator liaison
- Standardized control narratives and walkthroughs with control and app owners
Frameworks and tools
SOC 1SOC 2SOXNIST
DeliverablesReadiness gap report, evidence plan, remediation tracker
04
IT risk and change governance
Risk-informed oversight of production changes and projects, so gaps are caught before go-live.
What's included
- Risk review of production and change requests
- Access, segregation of duties (SOD), and logging reviews
- User access reviews and QA across in-scope applications
- Pre-go-live risk and control guidance for SDLC changes
- Application and control inventory with legacy / high-risk flags
Frameworks and tools
SODChange managementAccess reviewsSDLC
DeliverablesChange approval criteria, access review results, application risk inventory
05
Cloud and third-party risk
Governance for the systems and vendors you do not run yourself.
What's included
- Cloud governance reviews and adoption guardrails
- Hands-on AWS and Azure configuration assessments (IAM, logging, network)
- Shared-responsibility and control-ownership mapping
- Vendor risk program gap assessments and remediation plans
- SOC 1 / SOC 2 report reviews, including user-entity controls
Frameworks and tools
NIST 800-145NIST 500-322FedRAMPCSAAWSAzure
DeliverablesCloud governance roadmap, vendor risk program plan, SOC report reviews
06
Regulatory remediation and transactions
Independent validation and hands-on support when the stakes are high.
What's included
- Consent order validation testing and remediation
- Validation of consumer redress
- IPO readiness and first-year SOX support
- M&A due diligence on IT controls
- GRC for post-acquisition integrations
Frameworks and tools
Reg EConsent ordersIPO readinessDue diligenceModel Audit Rule
DeliverablesValidation reports, steering committee updates, integration control plan