Governance, risk and compliance run as a managed capability.
Most mid-market businesses do not have a governance problem on paper. They have a maintenance problem in practice. We keep the framework, the risk register, the controls and the evidence current, and we give leadership one forum where technology risk is actually decided.
- Govern
One forum, one decision log, named risk owners.
- Evidence
Controls proven continuously, not rebuilt at audit.
- Improve
Remediation sequenced by business impact.

Compliance obligations keep growing. The capacity to evidence them does not.
Four ways governance on paper fails the business in practice.
Risk held in people's heads
IT risk is discussed informally and never lands in a register anyone owns.
Controls without evidence
Policies exist on paper, but nothing proves they operate day to day.
Audit season panic
Evidence is reconstructed under pressure, pulling teams off delivery.
Framework overlap
The same control is answered four ways for four different standards.
A recurring service with a fixed monthly cadence.
The cycle repeats. Each pass closes gaps, updates the register and refreshes the evidence base, so the position you report is the position you are actually in.
Baseline
Assess current governance, risks, controls and evidence gaps.
Frame
Select the frameworks and consolidate overlapping control requirements.
Prioritise
Agree a Plan of Action and Milestones with owners and dates.
Implement
Close control gaps with technical and process remediation.
Evidence
Collect and retain proof continuously, not at audit time.
Govern
Run the IT and GRC forum, then review and refresh each cycle.
What the service includes.
- Governance framework
- Risk register & ownership
- Control implementation
- Policy & standards
- Compliance evidence
- Vendor & third-party risk
- Continuous monitoring
- Leadership reporting
Governance framework and forum
A recurring IT and GRC forum with a defined agenda, decision log and accountability, so technology risk is owned at leadership level rather than escalated by accident.
Risk management
A live risk register with business impact, likelihood, treatment decisions and named owners, reviewed on a fixed cadence and traced through to remediation.
Control implementation and assurance
Consolidated controls mapped across the standards that apply to you, with gap assessments, remediation activity and assurance that controls operate as described.
Compliance evidence and reporting
Continuous evidence collection, Plans of Action and Milestones, and reporting that answers auditors, insurers, clients and prospects without a fire drill.
Policy and standards support
Practical policies people can follow, kept current as the estate, workforce and obligations change, with awareness activity to support adoption.
Vendor and third-party risk
Assessment and monitoring of the suppliers holding your data or holding up your operations, with a proportionate review rhythm.
Map the control once. Report it many ways.
Frameworks overlap heavily. We consolidate the underlying controls into a single operational controls document, then present your position against each standard your obligations, insurers or clients require, so the same evidence serves several answers.
Custom control sets are supported too, whether the requirement comes from a contract, a cyber insurance policy, a client security review or a post-incident investigation.
See our own credentialsOpen any standard for the common questions we get asked about it: what falls in scope, how long it takes, what evidence we hold and how we support the audit.
ISO 27001 and ISO 27002
The international standard for an information security management system, with the supporting control guidance used to prepare for certification audit.
- The management system itself, the Annex A control set you select, your statement of applicability and the scope boundary agreed for certification.
- Baseline in the first month, a workable management system in three to six months, certification audit typically nine to twelve months from a cold start.
- Risk register, statement of applicability, policy set, internal audit records, management review minutes and corrective action tracking.
- We prepare the evidence pack, run the internal audit and management review, and sit with your certification body through Stage 1 and Stage 2.
AICPA SOC 2
Trust Services Criteria covering security, availability, integrity, confidentiality and privacy, commonly requested by enterprise clients.
- The systems in the service commitment, the criteria you elect beyond security, and readiness rather than the attestation itself.
- Readiness assessment in weeks, remediation over three to six months, then a Type 1 point-in-time report before a Type 2 observation window.
- Control descriptions, access reviews, change records, monitoring output and exception handling across the observation period.
- We assemble the evidence the CPA firm requests, answer sampling queries and track exceptions through to closure.
NIST CSF
A broad, outcome-based cybersecurity framework used as a common language for risk across identify, protect, detect, respond and recover.
- All six functions at the profile and target maturity you choose, applied across the estate rather than a certified boundary.
- Current and target profile inside sixty days, with maturity movement reported each quarter.
- Profile scoring, subcategory coverage, remediation plan and quarter-on-quarter maturity trend.
- No formal audit exists, so we use the profile to answer client questionnaires, insurer questions and board assurance requests.
NIST SP 800-171
Controls for protecting controlled unclassified information, including the system security plan and plan of action and milestones.
- The environment where controlled unclassified information is stored, processed or transmitted, plus the 110 controls in scope for it.
- Assessment and scoring in the first month, system security plan and remediation plan within sixty to ninety days.
- System security plan, control-by-control assessment score, plan of action and milestones with owners and dates.
- We prepare for self-assessment submission and for a third-party or government-led assessment where one is required.
NIST AI RMF
A risk management framework for designing, deploying and governing AI systems so they can be shown to be trustworthy.
- Your AI use cases, the data that feeds them, human oversight and the govern, map, measure and manage functions.
- Use-case inventory and initial risk profile in four to six weeks, with review as new use cases are approved.
- AI use-case register, risk assessments, acceptable use and oversight policy, and model change records.
- Not certifiable. We produce the governance record clients, insurers and regulators increasingly ask to see.
CIS Controls v8.1
A prioritised set of practical safeguards, useful as a technical baseline where no formal certification is required.
- Implementation Group 1, 2 or 3 depending on your risk profile, applied to devices, identities, data and cloud services.
- Baseline scoring immediately, with Implementation Group 1 usually closed inside ninety days.
- Safeguard-level scoring, configuration output, vulnerability and patch data and remediation tracking.
- Self-assessed. Used as technical proof behind other frameworks and insurance questionnaires.
Cyber Essentials
The UK government baseline covering five technical control areas, completed as a verified self-assessment.
- Firewalls, secure configuration, user access control, malware protection and patch management across the whole organisation or a defined subset.
- Usually four to eight weeks, depending on how much patching and device configuration needs to change first.
- Self-assessment responses, device and patch inventory, access control records and supporting configuration screenshots.
- We complete the questionnaire with you and manage the certification body's clarification questions to a pass.
Cyber Essentials Plus
The same baseline confirmed by independent technical testing, which needs clean documentation and evidence.
- The certified Cyber Essentials scope, plus a sampled technical test of devices, email and browser configuration.
- Three months from a standing start, or within the certification window once Cyber Essentials is held.
- The self-assessment pack, a full device sample list and remediation records for any test failures.
- We prepare the sample, remediate findings during the assessment window and coordinate the assessor's retest.
CMMC 2.0
Maturity levels one and two for organisations in the US defence supply chain, tracked separately or together.
- Level 1 basic safeguarding, or Level 2 aligned to SP 800-171 for controlled unclassified information.
- Level 1 in sixty to ninety days. Level 2 usually six to twelve months ahead of a certification assessment.
- System security plan, control assessment scoring, plan of action and milestones and affirmation records.
- We support annual self-affirmation for Level 1 and prepare the evidence set for a C3PAO assessment at Level 2.
PCI DSS
Requirements for any business that stores, processes or transmits payment card data.
- The cardholder data environment and everything connected to it, scoped to the self-assessment questionnaire type that fits your payment flows.
- Scoping and questionnaire selection in weeks, remediation typically three to six months where segmentation is needed.
- Network and data flow diagrams, segmentation proof, scan results, access records and policy set.
- We complete the self-assessment questionnaire and attestation of compliance, and support a QSA where your acquirer requires one.
GDPR (EU and UK)
Data protection obligations for personal data, including lawful basis, subject rights and breach handling, in both EU and UK forms.
- Processing activities, lawful basis, records of processing, transfers, processor contracts and subject rights handling.
- Records of processing and gap analysis in six to eight weeks, with policy and contract remediation over the following quarter.
- Record of processing activities, data protection impact assessments, transfer assessments, subject request log and breach register.
- No certification exists. We prepare the accountability file a regulator, client or insurer would ask for.
POPIA
South Africa's Protection of Personal Information Act, with the security safeguards in Condition 7 mapped to controls.
- The eight conditions for lawful processing, operator agreements and the Information Officer's duties.
- Processing inventory and safeguards assessment in six to eight weeks, remediation across the following quarter.
- Processing register, operator agreements, PAIA manual, Information Officer registration and breach notification records.
- We prepare the compliance file for Information Regulator engagement and for client due diligence.
HIPAA
The US Security, Privacy and Breach Notification Rules for protected health information.
- Systems touching protected health information, the administrative, physical and technical safeguards and your business associate relationships.
- Security risk analysis in the first month, safeguard remediation over three to six months.
- Security risk analysis, safeguard implementation records, business associate agreements, workforce training and breach log.
- We hold the documentation set an OCR investigation or a covered entity's due diligence would request.
FTC Safeguards Rule
Information security programme requirements for US financial institutions and many service providers to them.
- The written information security programme, the qualified individual role, risk assessment and service provider oversight.
- Programme documented inside sixty days, with continuous monitoring or penetration testing arranged thereafter.
- Written programme, risk assessment, monitoring and testing records, vendor oversight file and annual report to leadership.
- No audit regime. We produce the annual written report and the evidence behind it.
NY DFS Part 500
New York financial services cybersecurity regulation, including the exemption categories for smaller entities.
- The cybersecurity programme and policy, CISO function, access controls, third-party policy, and the exemption class that applies to you.
- Gap assessment in weeks, with remediation aligned to the regulation's staged compliance dates.
- Programme documentation, risk assessment, CISO report, incident response plan and testing records.
- We prepare the annual certification or acknowledgement of non-compliance and the supporting file.
EU NIS2 Directive
Cyber risk management, reporting and accountability duties for essential and important entities operating in the EU.
- Risk management measures, supply chain security, incident reporting timelines and management-body accountability.
- Applicability and gap assessment in six to eight weeks, remediation across two to three quarters depending on maturity.
- Risk management measures documentation, incident reporting procedures, supply chain assessments and management briefing records.
- We prepare for national competent authority supervision, which may include inspections and information requests.
CJIS Security Policy
Controls for any organisation that handles criminal justice information, used to prepare for periodic CJIS audits.
- Systems and personnel with access to criminal justice information, including screening, training and advanced authentication.
- Assessment in the first month, remediation typically three to six months before the audit window.
- Control assessment, personnel screening and training records, access logs and incident response documentation.
- We prepare for the triennial CJIS audit and remediate findings against the auditor's timetable.
Essential Eight
Australia's mitigation strategy baseline, assessed against the maturity level appropriate to the business.
- The eight mitigation strategies at Maturity Level 1, 2 or 3 across applications, patching, macros, hardening, privilege and backup.
- Maturity assessment immediately, with Maturity Level 1 usually reached inside ninety days.
- Maturity scoring per strategy, patch and configuration output, privilege review and backup restoration testing.
- Self-assessed, with the maturity report used for tender responses and client assurance.
Cyber Fundamentals
A practical, framework-neutral security baseline for businesses that need a defensible starting point rather than certification.
- Core identity, device, data, backup and awareness controls, sized to the business rather than to a certification boundary.
- Baseline in the first month, with the core control set in place within one quarter.
- Control checklist, configuration output, backup testing and awareness training completion.
- No audit. It exists to answer client and insurer questions credibly and to lead into a formal framework later.
Cyber insurance readiness
The technical and governance conditions in your policy, evidenced so a claim cannot be declined for lack of due care.
- Every warranty and condition in the policy or renewal questionnaire, mapped to a control and an owner.
- Mapped before renewal, with gaps closed inside the renewal window where the market allows.
- Questionnaire answers with supporting proof, multi-factor and backup evidence, and incident response testing records.
- Tested at claim time, so we keep dated evidence for each warranted control rather than a point-in-time snapshot.
FSCA Joint Standard 2 of 2024
Cybersecurity and cyber resilience requirements for South African financial institutions supervised by the FSCA and Prudential Authority.
- Governance and board accountability, risk management, resilience and recovery capability, and third-party arrangements.
- Gap assessment in six to eight weeks, remediation planned against the standard's compliance dates.
- Cyber strategy and governance records, risk assessments, resilience testing, incident register and reporting to the board.
- We prepare the file for supervisory review and for internal or external audit of the standard.
Custom and contractual control sets
Client security reviews, tender requirements, internal policy or post-incident commitments, built as their own control set.
- Whatever the contract, tender or remediation undertaking actually requires, expressed as controls with owners.
- Set up in two to four weeks once the source document is supplied, then maintained on the standard cycle.
- The control set, per-clause evidence and a status report written for the counterparty who asked.
- We respond to client audits, questionnaires and site visits against the agreed control set.
Scope is agreed up front. Most businesses track two or three standards, plus the contractual and insurance requirements that apply to them.
Assessment work that runs to a published schedule.
The service is built on a purpose-built compliance platform we operate on your behalf. You do not have to learn it, licence it or staff it. What it means in practice is that assessments, evidence collection and documentation happen on a defined cadence, and the position you report is current rather than reconstructed.
Baseline in under an hour
The first assessment is a guided baseline rather than a month-long discovery exercise, so remediation starts while the picture is still fresh.
Scheduled data collection
Data on users, devices, networks and the Microsoft 365 estate is collected automatically for recurring assessments, including configuration and vulnerability scanning.
Consolidated controls
Requirements from every standard in scope are merged into one operational controls document, so a control is answered once and reported everywhere.
Dynamic remediation plans
Findings become a Plan of Action and Milestones with priority, owners, resources and dates, tracked through to closure with supporting evidence.
Policies generated for you
Policy and procedure manuals are produced against the standards you have selected, tailored to your business rather than lifted from a template pack.
Evidence and attestation tracking
Compliance evidence is produced on demand, and policy acknowledgement and training completion are tracked across the workforce on one dashboard.
Reported in business language, backed by proof.
Leadership should not have to interpret a control catalogue. Each cycle produces a plain report on what improved, what is exposed and what needs a decision.
- Technical Assessment Report
- Technical Risk Analysis Report
- Technical Risk Treatment Plan
- Plan of Action and Milestones (POA&M)
- Auditor's checklist
- Policy and procedure manuals, with supporting evidence
- Risks retired against plan
- Control coverage by framework
- Evidence completeness
- Remediation velocity
- Third-party risk position
- Audit and client questionnaire readiness
Priced as a monthly service with a fixed term.
Managed IT GRC is proposed on a twelve month agreement, billed monthly in advance, with a one-off onboarding fee covering baseline assessment, framework setup and platform configuration. Pricing is scoped to your users, environment and the standards in scope.
Onboarding
Baseline assessment, framework selection, controls consolidation and platform configuration.
Managed service
Recurring assessments, risk register upkeep, policy and vendor cycles, reporting and the governance forum.
Standalone or bundled
Runs on its own alongside your current IT arrangement, or bundled with managed IT and cyber for a single accountable partner.
Built for businesses that have to prove it.
- A regulator, insurer, client or investor asks for evidence.
- Risk decisions need an owner and a forum, not an inbox.
- An audit, certification or funding round is on the horizon.
Clear boundaries keep the position honest.
We are not your certification body and we do not issue audit opinions. We prepare, govern and evidence, then work alongside your chosen auditor or certifier. Legal advice, financial audit and licence resale are scoped separately.

Governance, risk visibility and cyber resilience in a regulated business.
A regulated financial services organisation moved IT risk out of fragmented technical activity and into a structured governance rhythm, then expanded into broader managed security services.
Read the case studyManaged IT GRC, answered.
Is Managed IT GRC the same as an audit?
No. An audit tells you where you stood on a given day. Managed IT GRC is an ongoing service that maintains the framework, risk register, controls and evidence between audits, so the audit becomes a confirmation rather than a scramble.
Which frameworks do you work to?
We map to the frameworks your obligations and clients require, including ISO 27001, Cyber Essentials, NIST CSF, SOC 2 readiness and sector or jurisdictional privacy law. Controls are consolidated once and reported against each framework, rather than maintained separately.
Do we need Numata to run our IT as well?
No. Managed IT GRC works alongside an internal team or a third-party provider. Where we also run operations, remediation moves faster because governance decisions and delivery share the same plan.
What do we get each month?
A maintained risk register, a controls position against your chosen frameworks, a Plan of Action and Milestones with owners and dates, policy updates, vendor risk status and a leadership report written in plain business language.
Do we need to buy compliance software?
No. The service runs on a compliance platform we licence, configure and operate on your behalf. You get the assessments, dashboards, policies and reports without buying tooling or training people to use it.
How is it priced?
As a monthly service on a twelve month agreement, billed monthly in advance, with a one-off onboarding fee for the baseline assessment, framework setup and configuration. It can run standalone or bundled with managed IT and cyber services.
How long before this is useful?
A baseline assessment, risk register and prioritised remediation plan are typically in place within the first sixty days, with the governance forum running from the first full cycle.
Start with the obligations
you already have to meet.
We baseline your governance position, build the risk register and remediation plan, then run the cycle with your leadership team.
