Services · Core module
GRC & Audit
Covers policy authoring, control mapping, evidence collection, auditor liaison, vendor-risk reviews, and board reporting.
- Replaces
- Compliance Manager
- Where it sits
- Included in Managed, Complete
Scope
What we own.
Every line is work an engineer carries, reports on monthly, and hands over documented if the retainer ends.
- Policy set authoring and maintenance
- Control mapping and implementation tracking
- Evidence collection and auditor liaison
- Vendor and third-party risk reviews
- SOC 2, HIPAA or ISO 27001 program ownership
- Risk register reporting
Related
The rest of the retainer.
Modules combine. Most engagements run three or four together.
Talk through GRC & Audit.
Bring the systems, the role this has to cover, and the deadline. We come back inside 48 hours with a written scope.
