Services

Three ways to work with us.

Each sits on the same client value ladder — diagnose, then prioritize, then remediate. Start wherever fits your organization today.

Entry Diagnostic

GRC Quick Check™

$500 – $750

A low-friction answer to “where do we stand?” — before committing to a full assessment.

  • Short discovery questionnaire
  • Focused review of shared documents
  • 1–2 hour turnaround engagement
  • GRC Exposure Snapshot™ deliverable
  • Top 5 priorities, ranked
Learn More
Flagship Diagnostic

GRC Health Check™

Priced by segment & scope

A structured, risk-based diagnostic across all eight governance domains, stress-tested against your industry.

  • Governance, Risk, Compliance, Cybersecurity
  • Data & Privacy, Third-Party Risk, Resilience, Assurance
  • Scenario-driven stress-test layer
  • 12-section Executive Assessment Report
  • 30 / 90-day / 12-month roadmap
Start Your GRC Health Check
Follow-On Engagement

Remediation & Advisory™

Scope & outcome based

Once we know what's actually wrong, we fix it — fixed-fee packages, project work, or ongoing advisory.

  • Policy & risk register development
  • Control implementation
  • Framework implementation sprints
  • Incident response & continuity programs
  • Continuous Assurance Subscription
Talk to Us

Specialized Extensions

Deeper work in a specific area.

Each of these draws on the same Health Check methodology, focused on one domain in depth — typically the right next step once a Health Check identifies where the real exposure sits.

Cybersecurity Readiness Assessment

How prepared are you to prevent, detect, respond to, and recover from cybersecurity threats — mapped against NIST CSF, ISO/IEC 27001, or CIS Controls as applicable.

Pre-Audit Readiness Review

A mock audit dry-run ahead of a real one — likely findings, evidence gaps, and a preparation plan before the deadline arrives.

Third-Party Risk Assessment

Vendor criticality, due diligence, concentration risk, and fourth-party exposure — per-vendor, or as a full TPRM program.

AI Governance Readiness Assessment

Are you capable of using AI responsibly, mapped against the EU AI Act, NIST AI RMF, and ISO/IEC 42001.

Not sure which is the right starting point?

The discovery conversation is free — we'll tell you honestly which service fits, even if that's the smallest one.