Managed IT GRC Services

Governance, risk and compliance run as a managed capability.

Most mid-market businesses do not have a governance problem on paper. They have a maintenance problem in practice. We keep the framework, the risk register, the controls and the evidence current, and we give leadership one forum where technology risk is actually decided.

  • Govern

    One forum, one decision log, named risk owners.

  • Evidence

    Controls proven continuously, not rebuilt at audit.

  • Improve

    Remediation sequenced by business impact.

Numata specialists reviewing governance and control evidence.

Compliance obligations keep growing. The capacity to evidence them does not.

The problem
Where it goes wrong

Four ways governance on paper fails the business in practice.

  • Risk held in people's heads

    IT risk is discussed informally and never lands in a register anyone owns.

  • Controls without evidence

    Policies exist on paper, but nothing proves they operate day to day.

  • Audit season panic

    Evidence is reconstructed under pressure, pulling teams off delivery.

  • Framework overlap

    The same control is answered four ways for four different standards.

The cycle

A recurring service with a fixed monthly cadence.

The cycle repeats. Each pass closes gaps, updates the register and refreshes the evidence base, so the position you report is the position you are actually in.

  1. Baseline

    Assess current governance, risks, controls and evidence gaps.

  2. Frame

    Select the frameworks and consolidate overlapping control requirements.

  3. Prioritise

    Agree a Plan of Action and Milestones with owners and dates.

  4. Implement

    Close control gaps with technical and process remediation.

  5. Evidence

    Collect and retain proof continuously, not at audit time.

  6. Govern

    Run the IT and GRC forum, then review and refresh each cycle.

What Numata manages

What the service includes.

  • Governance framework
  • Risk register & ownership
  • Control implementation
  • Policy & standards
  • Compliance evidence
  • Vendor & third-party risk
  • Continuous monitoring
  • Leadership reporting
  • Governance framework and forum

    A recurring IT and GRC forum with a defined agenda, decision log and accountability, so technology risk is owned at leadership level rather than escalated by accident.

  • Risk management

    A live risk register with business impact, likelihood, treatment decisions and named owners, reviewed on a fixed cadence and traced through to remediation.

  • Control implementation and assurance

    Consolidated controls mapped across the standards that apply to you, with gap assessments, remediation activity and assurance that controls operate as described.

  • Compliance evidence and reporting

    Continuous evidence collection, Plans of Action and Milestones, and reporting that answers auditors, insurers, clients and prospects without a fire drill.

  • Policy and standards support

    Practical policies people can follow, kept current as the estate, workforce and obligations change, with awareness activity to support adoption.

  • Vendor and third-party risk

    Assessment and monitoring of the suppliers holding your data or holding up your operations, with a proportionate review rhythm.

Standards and frameworks covered

Map the control once. Report it many ways.

Frameworks overlap heavily. We consolidate the underlying controls into a single operational controls document, then present your position against each standard your obligations, insurers or clients require, so the same evidence serves several answers.

Custom control sets are supported too, whether the requirement comes from a contract, a cyber insurance policy, a client security review or a post-incident investigation.

See our own credentials

Open any standard for the common questions we get asked about it: what falls in scope, how long it takes, what evidence we hold and how we support the audit.

  • ISO 27001 and ISO 27002

    The international standard for an information security management system, with the supporting control guidance used to prepare for certification audit.

    Scope
    The management system itself, the Annex A control set you select, your statement of applicability and the scope boundary agreed for certification.
    Timeline
    Baseline in the first month, a workable management system in three to six months, certification audit typically nine to twelve months from a cold start.
    Evidence
    Risk register, statement of applicability, policy set, internal audit records, management review minutes and corrective action tracking.
    Audit support
    We prepare the evidence pack, run the internal audit and management review, and sit with your certification body through Stage 1 and Stage 2.
  • AICPA SOC 2

    Trust Services Criteria covering security, availability, integrity, confidentiality and privacy, commonly requested by enterprise clients.

    Scope
    The systems in the service commitment, the criteria you elect beyond security, and readiness rather than the attestation itself.
    Timeline
    Readiness assessment in weeks, remediation over three to six months, then a Type 1 point-in-time report before a Type 2 observation window.
    Evidence
    Control descriptions, access reviews, change records, monitoring output and exception handling across the observation period.
    Audit support
    We assemble the evidence the CPA firm requests, answer sampling queries and track exceptions through to closure.
  • NIST CSF

    A broad, outcome-based cybersecurity framework used as a common language for risk across identify, protect, detect, respond and recover.

    Scope
    All six functions at the profile and target maturity you choose, applied across the estate rather than a certified boundary.
    Timeline
    Current and target profile inside sixty days, with maturity movement reported each quarter.
    Evidence
    Profile scoring, subcategory coverage, remediation plan and quarter-on-quarter maturity trend.
    Audit support
    No formal audit exists, so we use the profile to answer client questionnaires, insurer questions and board assurance requests.
  • NIST SP 800-171

    Controls for protecting controlled unclassified information, including the system security plan and plan of action and milestones.

    Scope
    The environment where controlled unclassified information is stored, processed or transmitted, plus the 110 controls in scope for it.
    Timeline
    Assessment and scoring in the first month, system security plan and remediation plan within sixty to ninety days.
    Evidence
    System security plan, control-by-control assessment score, plan of action and milestones with owners and dates.
    Audit support
    We prepare for self-assessment submission and for a third-party or government-led assessment where one is required.
  • NIST AI RMF

    A risk management framework for designing, deploying and governing AI systems so they can be shown to be trustworthy.

    Scope
    Your AI use cases, the data that feeds them, human oversight and the govern, map, measure and manage functions.
    Timeline
    Use-case inventory and initial risk profile in four to six weeks, with review as new use cases are approved.
    Evidence
    AI use-case register, risk assessments, acceptable use and oversight policy, and model change records.
    Audit support
    Not certifiable. We produce the governance record clients, insurers and regulators increasingly ask to see.
  • CIS Controls v8.1

    A prioritised set of practical safeguards, useful as a technical baseline where no formal certification is required.

    Scope
    Implementation Group 1, 2 or 3 depending on your risk profile, applied to devices, identities, data and cloud services.
    Timeline
    Baseline scoring immediately, with Implementation Group 1 usually closed inside ninety days.
    Evidence
    Safeguard-level scoring, configuration output, vulnerability and patch data and remediation tracking.
    Audit support
    Self-assessed. Used as technical proof behind other frameworks and insurance questionnaires.
  • Cyber Essentials

    The UK government baseline covering five technical control areas, completed as a verified self-assessment.

    Scope
    Firewalls, secure configuration, user access control, malware protection and patch management across the whole organisation or a defined subset.
    Timeline
    Usually four to eight weeks, depending on how much patching and device configuration needs to change first.
    Evidence
    Self-assessment responses, device and patch inventory, access control records and supporting configuration screenshots.
    Audit support
    We complete the questionnaire with you and manage the certification body's clarification questions to a pass.
  • Cyber Essentials Plus

    The same baseline confirmed by independent technical testing, which needs clean documentation and evidence.

    Scope
    The certified Cyber Essentials scope, plus a sampled technical test of devices, email and browser configuration.
    Timeline
    Three months from a standing start, or within the certification window once Cyber Essentials is held.
    Evidence
    The self-assessment pack, a full device sample list and remediation records for any test failures.
    Audit support
    We prepare the sample, remediate findings during the assessment window and coordinate the assessor's retest.
  • CMMC 2.0

    Maturity levels one and two for organisations in the US defence supply chain, tracked separately or together.

    Scope
    Level 1 basic safeguarding, or Level 2 aligned to SP 800-171 for controlled unclassified information.
    Timeline
    Level 1 in sixty to ninety days. Level 2 usually six to twelve months ahead of a certification assessment.
    Evidence
    System security plan, control assessment scoring, plan of action and milestones and affirmation records.
    Audit support
    We support annual self-affirmation for Level 1 and prepare the evidence set for a C3PAO assessment at Level 2.
  • PCI DSS

    Requirements for any business that stores, processes or transmits payment card data.

    Scope
    The cardholder data environment and everything connected to it, scoped to the self-assessment questionnaire type that fits your payment flows.
    Timeline
    Scoping and questionnaire selection in weeks, remediation typically three to six months where segmentation is needed.
    Evidence
    Network and data flow diagrams, segmentation proof, scan results, access records and policy set.
    Audit support
    We complete the self-assessment questionnaire and attestation of compliance, and support a QSA where your acquirer requires one.
  • GDPR (EU and UK)

    Data protection obligations for personal data, including lawful basis, subject rights and breach handling, in both EU and UK forms.

    Scope
    Processing activities, lawful basis, records of processing, transfers, processor contracts and subject rights handling.
    Timeline
    Records of processing and gap analysis in six to eight weeks, with policy and contract remediation over the following quarter.
    Evidence
    Record of processing activities, data protection impact assessments, transfer assessments, subject request log and breach register.
    Audit support
    No certification exists. We prepare the accountability file a regulator, client or insurer would ask for.
  • POPIA

    South Africa's Protection of Personal Information Act, with the security safeguards in Condition 7 mapped to controls.

    Scope
    The eight conditions for lawful processing, operator agreements and the Information Officer's duties.
    Timeline
    Processing inventory and safeguards assessment in six to eight weeks, remediation across the following quarter.
    Evidence
    Processing register, operator agreements, PAIA manual, Information Officer registration and breach notification records.
    Audit support
    We prepare the compliance file for Information Regulator engagement and for client due diligence.
  • HIPAA

    The US Security, Privacy and Breach Notification Rules for protected health information.

    Scope
    Systems touching protected health information, the administrative, physical and technical safeguards and your business associate relationships.
    Timeline
    Security risk analysis in the first month, safeguard remediation over three to six months.
    Evidence
    Security risk analysis, safeguard implementation records, business associate agreements, workforce training and breach log.
    Audit support
    We hold the documentation set an OCR investigation or a covered entity's due diligence would request.
  • FTC Safeguards Rule

    Information security programme requirements for US financial institutions and many service providers to them.

    Scope
    The written information security programme, the qualified individual role, risk assessment and service provider oversight.
    Timeline
    Programme documented inside sixty days, with continuous monitoring or penetration testing arranged thereafter.
    Evidence
    Written programme, risk assessment, monitoring and testing records, vendor oversight file and annual report to leadership.
    Audit support
    No audit regime. We produce the annual written report and the evidence behind it.
  • NY DFS Part 500

    New York financial services cybersecurity regulation, including the exemption categories for smaller entities.

    Scope
    The cybersecurity programme and policy, CISO function, access controls, third-party policy, and the exemption class that applies to you.
    Timeline
    Gap assessment in weeks, with remediation aligned to the regulation's staged compliance dates.
    Evidence
    Programme documentation, risk assessment, CISO report, incident response plan and testing records.
    Audit support
    We prepare the annual certification or acknowledgement of non-compliance and the supporting file.
  • EU NIS2 Directive

    Cyber risk management, reporting and accountability duties for essential and important entities operating in the EU.

    Scope
    Risk management measures, supply chain security, incident reporting timelines and management-body accountability.
    Timeline
    Applicability and gap assessment in six to eight weeks, remediation across two to three quarters depending on maturity.
    Evidence
    Risk management measures documentation, incident reporting procedures, supply chain assessments and management briefing records.
    Audit support
    We prepare for national competent authority supervision, which may include inspections and information requests.
  • CJIS Security Policy

    Controls for any organisation that handles criminal justice information, used to prepare for periodic CJIS audits.

    Scope
    Systems and personnel with access to criminal justice information, including screening, training and advanced authentication.
    Timeline
    Assessment in the first month, remediation typically three to six months before the audit window.
    Evidence
    Control assessment, personnel screening and training records, access logs and incident response documentation.
    Audit support
    We prepare for the triennial CJIS audit and remediate findings against the auditor's timetable.
  • Essential Eight

    Australia's mitigation strategy baseline, assessed against the maturity level appropriate to the business.

    Scope
    The eight mitigation strategies at Maturity Level 1, 2 or 3 across applications, patching, macros, hardening, privilege and backup.
    Timeline
    Maturity assessment immediately, with Maturity Level 1 usually reached inside ninety days.
    Evidence
    Maturity scoring per strategy, patch and configuration output, privilege review and backup restoration testing.
    Audit support
    Self-assessed, with the maturity report used for tender responses and client assurance.
  • Cyber Fundamentals

    A practical, framework-neutral security baseline for businesses that need a defensible starting point rather than certification.

    Scope
    Core identity, device, data, backup and awareness controls, sized to the business rather than to a certification boundary.
    Timeline
    Baseline in the first month, with the core control set in place within one quarter.
    Evidence
    Control checklist, configuration output, backup testing and awareness training completion.
    Audit support
    No audit. It exists to answer client and insurer questions credibly and to lead into a formal framework later.
  • Cyber insurance readiness

    The technical and governance conditions in your policy, evidenced so a claim cannot be declined for lack of due care.

    Scope
    Every warranty and condition in the policy or renewal questionnaire, mapped to a control and an owner.
    Timeline
    Mapped before renewal, with gaps closed inside the renewal window where the market allows.
    Evidence
    Questionnaire answers with supporting proof, multi-factor and backup evidence, and incident response testing records.
    Audit support
    Tested at claim time, so we keep dated evidence for each warranted control rather than a point-in-time snapshot.
  • FSCA Joint Standard 2 of 2024

    Cybersecurity and cyber resilience requirements for South African financial institutions supervised by the FSCA and Prudential Authority.

    Scope
    Governance and board accountability, risk management, resilience and recovery capability, and third-party arrangements.
    Timeline
    Gap assessment in six to eight weeks, remediation planned against the standard's compliance dates.
    Evidence
    Cyber strategy and governance records, risk assessments, resilience testing, incident register and reporting to the board.
    Audit support
    We prepare the file for supervisory review and for internal or external audit of the standard.
  • Custom and contractual control sets

    Client security reviews, tender requirements, internal policy or post-incident commitments, built as their own control set.

    Scope
    Whatever the contract, tender or remediation undertaking actually requires, expressed as controls with owners.
    Timeline
    Set up in two to four weeks once the source document is supplied, then maintained on the standard cycle.
    Evidence
    The control set, per-clause evidence and a status report written for the counterparty who asked.
    Audit support
    We respond to client audits, questionnaires and site visits against the agreed control set.

Scope is agreed up front. Most businesses track two or three standards, plus the contractual and insurance requirements that apply to them.

The platform

Assessment work that runs to a published schedule.

The service is built on a purpose-built compliance platform we operate on your behalf. You do not have to learn it, licence it or staff it. What it means in practice is that assessments, evidence collection and documentation happen on a defined cadence, and the position you report is current rather than reconstructed.

  • Baseline in under an hour

    The first assessment is a guided baseline rather than a month-long discovery exercise, so remediation starts while the picture is still fresh.

  • Scheduled data collection

    Data on users, devices, networks and the Microsoft 365 estate is collected automatically for recurring assessments, including configuration and vulnerability scanning.

  • Consolidated controls

    Requirements from every standard in scope are merged into one operational controls document, so a control is answered once and reported everywhere.

  • Dynamic remediation plans

    Findings become a Plan of Action and Milestones with priority, owners, resources and dates, tracked through to closure with supporting evidence.

  • Policies generated for you

    Policy and procedure manuals are produced against the standards you have selected, tailored to your business rather than lifted from a template pack.

  • Evidence and attestation tracking

    Compliance evidence is produced on demand, and policy acknowledgement and training completion are tracked across the workforce on one dashboard.

Evidence

Reported in business language, backed by proof.

Leadership should not have to interpret a control catalogue. Each cycle produces a plain report on what improved, what is exposed and what needs a decision.

Standard documentation set
  • Technical Assessment Report
  • Technical Risk Analysis Report
  • Technical Risk Treatment Plan
  • Plan of Action and Milestones (POA&M)
  • Auditor's checklist
  • Policy and procedure manuals, with supporting evidence
What we report on
  1. 01Risks retired against plan
  2. 02Control coverage by framework
  3. 03Evidence completeness
  4. 04Remediation velocity
  5. 05Third-party risk position
  6. 06Audit and client questionnaire readiness
Commercial model

Priced as a monthly service with a fixed term.

Managed IT GRC is proposed on a twelve month agreement, billed monthly in advance, with a one-off onboarding fee covering baseline assessment, framework setup and platform configuration. Pricing is scoped to your users, environment and the standards in scope.

  • One-off

    Onboarding

    Baseline assessment, framework selection, controls consolidation and platform configuration.

  • Monthly

    Managed service

    Recurring assessments, risk register upkeep, policy and vendor cycles, reporting and the governance forum.

  • Included

    Standalone or bundled

    Runs on its own alongside your current IT arrangement, or bundled with managed IT and cyber for a single accountable partner.

Fit

Built for businesses that have to prove it.

  • A regulator, insurer, client or investor asks for evidence.
  • Risk decisions need an owner and a forum, not an inbox.
  • An audit, certification or funding round is on the horizon.
Boundaries

Clear boundaries keep the position honest.

We are not your certification body and we do not issue audit opinions. We prepare, govern and evidence, then work alongside your chosen auditor or certifier. Legal advice, financial audit and licence resale are scoped separately.

Proof

Governance that changed what the business could see.

Governance and risk committee reviewing a risk register and control dashboards
Case study
Case study · Managed IT GRC

Governance, risk visibility and cyber resilience in a regulated business.

A regulated financial services organisation moved IT risk out of fragmented technical activity and into a structured governance rhythm, then expanded into broader managed security services.

Read the case study
FAQs

Managed IT GRC, answered.

Is Managed IT GRC the same as an audit?

No. An audit tells you where you stood on a given day. Managed IT GRC is an ongoing service that maintains the framework, risk register, controls and evidence between audits, so the audit becomes a confirmation rather than a scramble.

Which frameworks do you work to?

We map to the frameworks your obligations and clients require, including ISO 27001, Cyber Essentials, NIST CSF, SOC 2 readiness and sector or jurisdictional privacy law. Controls are consolidated once and reported against each framework, rather than maintained separately.

Do we need Numata to run our IT as well?

No. Managed IT GRC works alongside an internal team or a third-party provider. Where we also run operations, remediation moves faster because governance decisions and delivery share the same plan.

What do we get each month?

A maintained risk register, a controls position against your chosen frameworks, a Plan of Action and Milestones with owners and dates, policy updates, vendor risk status and a leadership report written in plain business language.

Do we need to buy compliance software?

No. The service runs on a compliance platform we licence, configure and operate on your behalf. You get the assessments, dashboards, policies and reports without buying tooling or training people to use it.

How is it priced?

As a monthly service on a twelve month agreement, billed monthly in advance, with a one-off onboarding fee for the baseline assessment, framework setup and configuration. It can run standalone or bundled with managed IT and cyber services.

How long before this is useful?

A baseline assessment, risk register and prioritised remediation plan are typically in place within the first sixty days, with the governance forum running from the first full cycle.

Start with the obligations
you already have to meet.

We baseline your governance position, build the risk register and remediation plan, then run the cycle with your leadership team.