Skip to main content

Our Services

GRC services built around how your organisation actually works.

From ISO 27001 and security governance to risk, audit readiness and supplier assurance, our services are designed to create sustainable capability rather than temporary compliance.

Service portfolio

Eight practice areas, one connected method.

Each area sets out the problem it addresses and the support typically provided. Scope is agreed before any work begins.

01

ISO 27001 & ISMS

For organisations building, rebuilding or strengthening an information security management system.

Gap assessment; scope and context; risk methodology; Statement of Applicability; policies and controls; implementation support; internal audit; management review; certification-readiness support.

02

Security Governance & Operating Model

For organisations that need clearer accountability, decision-making and oversight.

Governance framework; committee structure; roles and responsibilities; policy hierarchy; metrics and reporting; exception management; annual operating calendar.

03

Risk Management & Control Assurance

For organisations that need risk information that supports action rather than administration.

Risk framework; risk appetite support; risk register design; control library; risk and control assessments; issue tracking; assurance planning; management reporting.

04

Internal Audit & Readiness

For teams preparing for certification, client assessment, regulator review or internal scrutiny.

Audit planning; evidence review; interviews and testing; findings; root-cause analysis; remediation plan; readiness assessment; closure validation.

05

Third-Party Risk & Supplier Assurance

For organisations that rely on suppliers, cloud services and outsourced operations.

Supplier tiering; due diligence questionnaires; evidence assessment; contracting controls; onboarding; monitoring; issue remediation; exit and offboarding controls.

06

Identity, Access Governance & Segregation of Duties

For organisations seeking stronger control over access and conflicting permissions.

Joiner-mover-leaver design; access reviews; role design; privileged access governance; segregation-of-duties analysis; exception workflow; evidence and reporting.

07

Secure Delivery & Resilience Governance

For organisations embedding security into change, technology delivery and operational resilience.

DevSecOps governance; security gates; ownership; incident governance; business continuity alignment; IT disaster recovery oversight; lessons-learned and improvement tracking.

08

Fractional Information Security Management & Training

For organisations that need flexible leadership, coordination and capability-building.

Security programme leadership; policy ownership; risk reporting; audit coordination; supplier assurance; executive updates; tailored awareness and role-based training.

Engagement formats

Five ways to work with us.

Deliverables, assumptions and exclusions are recorded before work begins.

  • Focused assessment
  • Defined implementation project
  • Assurance review
  • Retained advisory support
  • Fractional information security management
Governance documentation and a control register prepared for review

ISO/IEC 27001 Consulting

Build an ISMS that works before, during and after certification.

We help organisations design, implement, improve and assure information security management systems (ISMS) that reflect real risks, produce credible evidence and support independent certification.

Who this is for

  • Organisations seeking ISO/IEC 27001 certification for the first time.
  • Businesses responding to client, investor or supply-chain assurance requirements.
  • Teams with an existing ISMS that has become document-heavy, unclear or difficult to operate.
  • Organisations preparing for surveillance, recertification or transition-related activity.
  • Leadership teams that need independent readiness insight before external audit.

What support includes

Readiness and gap assessment

Assess current arrangements against ISO/IEC 27001 requirements, identify evidence gaps and produce a prioritised roadmap.

ISMS design and build

Define scope, context, interested parties, governance, risk methodology, objectives, documentation and operational processes.

Risk assessment and treatment

Establish a repeatable method, assess information security risks and connect treatment decisions to applicable controls.

Control implementation and evidence

Translate selected controls into ownership, procedures, records, monitoring and traceable evidence.

Internal audit and management review

Plan and conduct independent internal assurance, prepare management inputs and track corrective action.

Certification readiness

Test whether the ISMS is sufficiently embedded and support teams in preparing for Stage 1 and Stage 2 audit activity.

Delivery journey

01

Scope and diagnose

Understand the organisation, certification objective, boundaries, obligations, current maturity and timeline.

02

Prioritise and design

Agree the roadmap, responsibilities, risk method, policy structure and control approach.

03

Implement and evidence

Support owners to operate processes, complete actions and create evidence over an appropriate period.

04

Audit and improve

Conduct internal audit, support management review and validate corrective actions.

05

Prepare and support

Organise evidence, brief stakeholders and support the organisation through external audit preparation.

Frequently asked questions

Certification decisions rest with an independent certification body. We prepare, implement and assess readiness — nothing more is claimed.

How we describe certification

Masterpiece GRC Consulting is not a certification body and does not guarantee a certification outcome, regulatory approval or audit result. Support is consultancy support: it prepares an organisation for an independent assessment, and the certification decision rests entirely with the certification body.

Not sure which service fits?

Not sure which service fits the problem?

Describe the outcome, audit, risk or obligation you are dealing with. We will help define the right scope before work begins.