Home / Industries / GRC value recovery

MyRISK Consulting · existing GRC and IRM platform owners

The platform exists. The operating discipline never arrived.

Workarounds, duplicate evidence, reports nobody reads, controls tested once, actions closed without proof, and adoption that depends on two or three specialists.

Why now

You bought the right thing. It is not doing the work.

The platform was selected properly, implemented by capable people and is technically fine. Two or three specialists know how to make it produce what leadership asks for. Everyone else has a spreadsheet.

That is not a software problem, and replacing the platform would not fix it. The workflow around it — who does what, when, with what evidence, and what happens when they don't — was never designed to survive normal operating pressure.

The question is not whether your platform can do this. It is why the workflow around it still fails.

What this looks like from inside

  • Evidence collected twice because nobody trusts the first copy
  • Controls tested at implementation and not since
  • Actions marked closed with no evidence attached
  • Reports produced on a cycle and read by nobody
  • Adoption that collapses when one person takes leave
  • An audit finding that names the workflow, not the tool

Where it bites first

Six workflows that commonly fail around a working platform

01

Control testing

Designed as a cycle, run as a project, and now overdue in a way the dashboard doesn't show.

02

Action closure

Findings closed on assertion rather than evidence, so the same issue returns next cycle.

03

Evidence reuse

The same evidence requested three times by three functions, each collecting it separately.

04

Supplier assurance

A questionnaire process that produces files nobody reads and decisions nobody records.

05

Committee reporting

A pack assembled by hand each cycle from a platform that was bought to assemble it.

06

Exception governance

Exceptions raised, approved, rolled over, and never revisited against the reason they were granted.

Not one of these is a cyber problem. Cyber controls may sit inside them, but the failure is operating discipline — which is why a cyber-led fix doesn't hold.

What you already have

What we will not tell you

We won't tell you your platform can't do this. In almost every case it can, and the vendor is right about that. We also won't propose replacing it, because a second implementation of an undesigned workflow produces the same result more expensively.

What we do is test one real workflow end to end against the current stack — the tool, the people, the evidence, the timing and the decision — and say where it breaks and what a working version costs.

The assessment is fixed-scope

  • One named workflow, agreed before it starts
  • Acceptance criteria written up front, not at the end
  • A stated effort range and a start window
  • Named outputs and named exclusions
  • A decision at the end — implement, hand back, or stop

The proof

A before-and-after operating pattern

Action closure workflow · sanitisedExample

What the assessment documents

  • The workflow as it actually runs, traced against one real recent instance rather than the process map
  • Each handoff, and where the evidence stops travelling with the item
  • The step where the decision is made, and whether anyone recorded why
  • What the platform is already capable of and is not configured to do
  • What depends on a named individual rather than a role
  • The redesigned pattern, and what it requires from whom to hold

The output includes the parts that are working. A diagnosis that finds everything broken has usually not been done carefully.

Who this is for, and who it isn't

Three signals that send you somewhere else

No sponsor or funded scope

A diagnosis nobody has authorised produces a document. We would rather tell you what needs to exist first.

A resourcing request

If what's needed is a person for six months, this is not that. Fixed-scope assessment is not staff augmentation, and pretending otherwise fails both sides.

No access

The assessment traces one real workflow. Without access to what actually happened — even redacted — there is nothing to trace.

Trace, Essentials and Core each open as a separate conversation, with their own reason and their own fit to work out. An assessment does not assume you will buy one of them afterwards, and it does not promise you will.

For your reviewers

The boundaries, in writing

What this is not

  • Not a claim that your platform is inadequate. In most cases it is capable and correctly chosen.
  • Not a platform replacement proposal by default. Replacement is a finding we may or may not reach, never the starting position.
  • Not open-ended professional services. Scope, outputs, exclusions and the end decision are written before work starts.
  • Not a guaranteed path into a MyRISK product. The assessment closes on its own terms and is priced as its own piece of work.

Name one workflow that still fails.

Not the whole programme — one workflow, and the output it was supposed to produce. That's enough to say whether an assessment would find anything worth paying for.