About

Governance built from practice, not theory.

The Kimberg Institute exists because most organizations don’t need another framework binder — they need someone who has actually sat across the table during an audit, a breach response, and a board risk conversation, and can tell them what matters first.


Founder

Kay Kimberg Fonguh

Kay is a Technology Risk Specialist and GRC consultant with over a decade of experience in information security, cyber risk, and regulatory compliance, primarily within financial services. He holds CISA, CRISC, and CFSA certifications, with expertise spanning Corporate Governance, ISO 27001, NIST, SOC 2, PCI DSS, SOX, GDPR, HIPAA, PIPEDA, OSFI B-13, PCMLTFA, and AML compliance.

His background includes hands-on technology risk and governance roles across financial services and energy organizations, giving the Institute’s methodology a foundation in what actually holds up under regulatory scrutiny — not just what looks complete on paper.

CISA
CRISC
CFSA

Methodology

An original body of frameworks.

The Institute’s work draws on an original, published body of governance research — the Kimberg Theory of Responsibility (KTR) and the Kimberg Responsibility Framework (KRF) — alongside the practical, field-tested Kimberg GRC Health Check™ methodology used in every engagement.

This isn’t framework re-packaging. Each tool was built, tested, and refined against real organizational stress-testing before it became part of how the Institute delivers work.

Read the Research

Work with someone who has been in the room.