Frequently Asked Questions
Straight answers for evaluators
The questions procurement, security and risk teams ask us most often.
It depends on scope, but our phased methodology is designed to deliver a working foundation quickly and extend from there. An assessment engagement defines a realistic timeline for your organisation before any implementation commitment is made.
Yes. Migrating existing risk registers, obligation lists, policy libraries and incident histories into the platform is a standard part of our implementation, including data cleansing so the new environment starts trustworthy.
ITSM platforms excel at service workflows. A dedicated GRC platform adds the risk and compliance data model: obligations, controls, assessments, attestations and their relationships. We integrate the two so each does what it does best.
Hosting and data residency arrangements are confirmed per engagement against your regulatory requirements. Talk to us about your obligations and we will confirm the available options in writing.
Yes. Most clients begin with one or two solution areas, commonly risk management and policy or incident management, and extend module by module as value is proven.
Yes. Our managed GRC service provides platform administration, configuration changes, reporting development and user support under defined SLAs, or we can enable your internal team to self-manage.
AI capability operates within the platform permission model and the vendor data handling commitments. We document the AI data position in the solution design so your security and privacy teams can assess it before anything is enabled.
Advisory engagements are fixed-price. Implementation investment depends on modules, integrations and data migration scope, and is defined following assessment. Managed services are a predictable monthly investment based on scope and SLAs.
