Home / Consulting
MyRISK Consulting · GRC assessment and re-engineering
Assess how risk work runs, then fix what fails.
Three assessments, each bounded before you sign: one broken workflow, a batch of suppliers, or a standard you have to meet by a date. Every one has named outputs, named exclusions, an acceptance test and a fixed price — and comes with the rebuild, not just the findings.
What you can book
Four engagements. Pick the one that matches what is forcing it.
Fixed-scope assessment
One workflow, report or evidence pack that failed despite the tools. We assess how the work actually runs and rebuild the part that breaks.
Bring one failed example →Third-party risk assessment
A named batch of suppliers assessed against a risk-based standard, closing with a decision for each one and the reasoning behind it.
Scope a batch →Compliance readiness assessment
A gap assessment or pre-audit against PCI DSS, ISO 27001, NIST CSF or the standard you have been asked to meet.
Name the standard and the date →Cyber risk quantification
Scenarios, exposure and the assumptions behind them, framed so the investment or acceptance decision they support can still be explained a year later.
Bring the decision you have to justify →If your problem is not one of these four, say so and we will point you somewhere useful — including somewhere that is not us.
Inside the fixed-scope assessment
We bought the platforms. The operating discipline never arrived.
GRC value recovery
The platform is used as a register and nothing else. We work out what can be recovered, what should be retired, and what needs redesigning around how the organisation actually works.
Assurance and evidence workflow
The same evidence is collected by hand for audits and customers who ask overlapping questions. We map what can be collected once and what the reuse rule has to be.
Policy-to-practice and reporting
Policies describe something nobody does, and reports are stale on arrival. We reconcile the two and rebuild the reporting line so it produces itself.
These three are what a fixed-scope assessment covers. Whichever one you arrive with, the engagement is bounded before you sign: named outputs, named exclusions, agreed acceptance criteria and a fixed price.
Independence
Consulting stands on its own commercial terms
You will never be pitched software mid-engagement. An engagement that ends without a product conversation has not failed — for you or for us.
If the assessment finds a decision class that keeps being challenged, or a rhythm nobody is running, a product conversation can open — as a separate discussion with its own reason and its own decision-maker on your side, never as the second half of work you already paid for. It is a term in the engagement letter, not a promise on a web page.
Before
Evidence chased by email each quarter. The exception approval sits in an inbox for three weeks. The report is accurate on the day it is written and stale by the meeting.
After
Evidence collected once against a named owner. The approval has a path, a signer and a clock. The report generates from the same source the work runs on.
For your reviewers
The boundaries, in writing
Where Consulting stops
- No directed capacity or staff augmentation. We rebuild workflows; we do not rent people.
- No open-ended time and materials. Bounded scope, named outputs, a fixed price.
- No independent audit opinion — we are not independent of the design we help build.
- No software pitch inside the engagement — in the proposal or anywhere else.
Bring one failed workflow, report or evidence pack
That one example is where the assessment starts. It scopes from it, with named outputs and a fixed price.