Home / Industries / GRC value recovery
MyRISK Consulting · existing GRC and IRM platform owners
The platform exists. The operating discipline never arrived.
Workarounds, duplicate evidence, reports nobody reads, controls tested once, actions closed without proof, and adoption that depends on two or three specialists.
Why now
You bought the right thing. It is not doing the work.
The platform was selected properly, implemented by capable people and is technically fine. Two or three specialists know how to make it produce what leadership asks for. Everyone else has a spreadsheet.
That is not a software problem, and replacing the platform would not fix it. The workflow around it — who does what, when, with what evidence, and what happens when they don't — was never designed to survive normal operating pressure.
The question is not whether your platform can do this. It is why the workflow around it still fails.
What this looks like from inside
- Evidence collected twice because nobody trusts the first copy
- Controls tested at implementation and not since
- Actions marked closed with no evidence attached
- Reports produced on a cycle and read by nobody
- Adoption that collapses when one person takes leave
- An audit finding that names the workflow, not the tool
Where it bites first
Six workflows that commonly fail around a working platform
01
Control testing
Designed as a cycle, run as a project, and now overdue in a way the dashboard doesn't show.
02
Action closure
Findings closed on assertion rather than evidence, so the same issue returns next cycle.
03
Evidence reuse
The same evidence requested three times by three functions, each collecting it separately.
04
Supplier assurance
A questionnaire process that produces files nobody reads and decisions nobody records.
05
Committee reporting
A pack assembled by hand each cycle from a platform that was bought to assemble it.
06
Exception governance
Exceptions raised, approved, rolled over, and never revisited against the reason they were granted.
Not one of these is a cyber problem. Cyber controls may sit inside them, but the failure is operating discipline — which is why a cyber-led fix doesn't hold.
What you already have
What we will not tell you
We won't tell you your platform can't do this. In almost every case it can, and the vendor is right about that. We also won't propose replacing it, because a second implementation of an undesigned workflow produces the same result more expensively.
What we do is test one real workflow end to end against the current stack — the tool, the people, the evidence, the timing and the decision — and say where it breaks and what a working version costs.
The assessment is fixed-scope
- One named workflow, agreed before it starts
- Acceptance criteria written up front, not at the end
- A stated effort range and a start window
- Named outputs and named exclusions
- A decision at the end — implement, hand back, or stop
The proof
A before-and-after operating pattern
What the assessment documents
- The workflow as it actually runs, traced against one real recent instance rather than the process map
- Each handoff, and where the evidence stops travelling with the item
- The step where the decision is made, and whether anyone recorded why
- What the platform is already capable of and is not configured to do
- What depends on a named individual rather than a role
- The redesigned pattern, and what it requires from whom to hold
The output includes the parts that are working. A diagnosis that finds everything broken has usually not been done carefully.
Who this is for, and who it isn't
Three signals that send you somewhere else
No sponsor or funded scope
A diagnosis nobody has authorised produces a document. We would rather tell you what needs to exist first.
A resourcing request
If what's needed is a person for six months, this is not that. Fixed-scope assessment is not staff augmentation, and pretending otherwise fails both sides.
No access
The assessment traces one real workflow. Without access to what actually happened — even redacted — there is nothing to trace.
Trace, Essentials and Core each open as a separate conversation, with their own reason and their own fit to work out. An assessment does not assume you will buy one of them afterwards, and it does not promise you will.
For your reviewers
The boundaries, in writing
What this is not
- Not a claim that your platform is inadequate. In most cases it is capable and correctly chosen.
- Not a platform replacement proposal by default. Replacement is a finding we may or may not reach, never the starting position.
- Not open-ended professional services. Scope, outputs, exclusions and the end decision are written before work starts.
- Not a guaranteed path into a MyRISK product. The assessment closes on its own terms and is priced as its own piece of work.
Name one workflow that still fails.
Not the whole programme — one workflow, and the output it was supposed to produce. That's enough to say whether an assessment would find anything worth paying for.