Skip to main content
Assuresec Limited
Search the site Switch light or dark theme

GRC Advisory & Certification

Build governance that stands up to scrutiny.

We help you design, implement and certify management systems that turn compliance obligations into operating discipline, embedding a culture of resilience, not just a checklist of controls.

Who it's for

  • CEOs, CFOs and CISOs facing regulator or customer pressure
  • Risk and compliance teams building or maturing a programme
  • Organisations preparing for their first certification audit

Problems we solve

  • Unclear which standards and laws actually apply to you
  • Policies that exist on paper but are not followed
  • Certification timelines that keep slipping
  • No single owner for risk and compliance

What is included

Everything under GRC Advisory & Certification

ISO/IEC 27001 (information security)

Design, implement and certify an information security management system.

ISO 22301 (business continuity)

Plan for disruption and prove you can keep critical services running.

ISO/IEC 20000 (IT service management)

Run IT as a reliable, measurable service.

ISO/IEC 27701 (privacy information management)

Extend your ISMS to manage personal data responsibly.

ISO 9001 (quality management)

Build consistent processes that satisfy customers.

ISO 45001 (occupational health and safety)

Reduce workplace risk with a structured safety system.

PCI DSS (cardholder data)

Protect payment card data and prepare for assessment.

SOC 2 (cloud service trust)

Build and evidence the controls your customers ask about.

COBIT (IT governance)

Align IT governance with business objectives.

SWIFT CSP (payment security)

Meet the SWIFT Customer Security Programme controls.

Data Protection Impact Assessments (DPIA)

Assess and reduce privacy risk before launching new processing.

NDPA and GDPR readiness

Comply with Nigeria's Data Protection Act 2023 and, where it applies, the GDPR.

Choose a standard to see the roadmap

Information security management. Typical path:

  1. Gap assessment: compare your current controls with ISO/IEC 27001 and Annex A.
  2. Implementation: scope the ISMS, run risk assessment, write policies and apply controls.
  3. Internal audit: test the system and fix findings before the external audit.
  4. Certification support: prepare evidence and support you through the audit by an accredited certification body.

Payment card data security. Typical path:

  1. Gap assessment: define cardholder-data scope and compare with the PCI DSS requirements.
  2. Implementation: segment networks, harden systems and document controls.
  3. Internal audit: validate controls and evidence.
  4. Compliance support: prepare for your assessment and attestation.

Service organisation controls. Typical path:

  1. Gap assessment: map controls to the Trust Services Criteria you choose.
  2. Implementation: close gaps and automate evidence collection.
  3. Readiness review: a dry run of the audit.
  4. Audit support: coordinate with your independent auditor.

Data protection readiness. Typical path:

  1. Data mapping: find what personal data you hold and why.
  2. Gap assessment and DPIA: compare with NDPA 2023 and, where relevant, GDPR.
  3. Implementation: notices, consent, retention, breach response and data-subject rights.
  4. Ongoing support: optional DPO as a service.

Our approach

How we deliver GRC Advisory & Certification

  1. 1

    Analyse

    Gap assessment against the chosen standard and your regulatory duties.

    Typical deliverable: Gap assessment report

  2. 2

    Plan

    Agree scope, owners, risk method and a realistic implementation timeline.

    Typical deliverable: Implementation roadmap

  3. 3

    Execute

    Write policies, implement controls and train your people.

    Typical deliverable: Policy set and control evidence

  4. 4

    Report

    Internal audit and management review to prove the system works.

    Typical deliverable: Internal audit report

  5. 5

    Monitor

    Support through the certification audit and continual improvement.

    Typical deliverable: Audit support and improvement plan

Benefits

  • Cross-border expertise across Africa and other continents
  • Tailored solutions, from SMEs to multinationals
  • Experienced, certified practitioners
  • A clear roadmap from gap assessment to certification-ready
  • Policies and controls your people can actually follow
  • Evidence prepared the way auditors expect

Typical deliverables

  • Gap assessment report
  • Risk assessment and treatment plan
  • Policy and procedure set
  • Internal audit report
  • Certification-readiness summary

Outcomes

  • Faster, calmer certification audits
  • Demonstrable compliance for regulators and customers
  • A management system that keeps working after the audit

FAQ

Frequently asked questions

How long does ISO/IEC 27001 take?
It depends on your size, scope and starting point. Many organisations need between six and twelve months. A gap assessment gives you a realistic timeline for your situation.
Do you issue the certificate?
No. Certificates are issued by independent, accredited certification bodies. We prepare you for the audit and support you through it. Keeping advisory and certification separate protects the credibility of your certificate.
Do we need to follow more than one standard?
Often, yes. Many requirements overlap, so we design one management system that satisfies several standards and regulations at once.

Enquire about GRC Advisory & Certification

Tell us what you need

Share a few details and a specialist will reply within one working day.

Let us assure your next move

Tell us about your organisation and we will recommend the right path to compliance, within one working day.