The framework, kept true.
A policy set and an obligations register are the two documents every organization has and almost nobody re-tests. They are approved once, filed, and quietly go out of date — the same failure as an untended risk register, with the same consequence when somebody finally asks for evidence.
GRC is a management service, so your business commissions it — usually the Chief Compliance Officer or General Counsel. That is the opposite of internal audit one page over, and it has a consequence worth reading before you buy.
Approved once, filed forever.
A policy set is written, approved and published. An obligations register is built for a certification and signed off. Both are accurate the week they land. Then a business unit is sold, a regulation changes, a system migrates, and a retention rule is quietly never enforced because nobody built the job that enforces it.
The documents still exist and still look authoritative. What has quietly stopped being true is the mapping between them and the organization — and mappings do not announce their own decay.
Bought as a project. Delivered as a product.
Neither column is a caricature. The left is how this work is bought almost everywhere, including by people who dislike it.
A baseline, then a quarterly loop.
Both GRC services share the shape: rationalize once, then keep it true on a printed cadence.
Every policy or obligation in force, deduplicated, with an owner and a review trigger on each.
Partner gateThe register lives in Clarus, not in a folder somebody owns.
What changed, what lapsed, what was approved and never communicated.
Partner gateFrom $24,000 a year for the policy framework; $30,000 for obligations.
Management’s service, not the committee’s.
Your business commissions this, which is the opposite of internal audit one page over — and the reason we cannot then audit what we maintain.
Methodology 2026.2 — bumps when a box, a gate or a testing standard changes — never for a copy edit. Read it at working depth on the method page.
Assurance · GRC
- 01Controls Framework, kept alive — key controls rationalized, baselined and monitored continuously, reported quarterly. Entered from GRC when the framework is ISO or SOC 2, and from finance when it is SOX
- 02It is one product, not two — same unit, same formula, same rhythm. The framework you are held to is a scope choice, and we would rather say that than sell you the same work twice under different names
- 03Price publishes when the box locks, like everything else here
Why these two, and not a platform.
Implementing a GRC platform is a build, and builds are Signify Solution work. What Impact does is narrower and, we would argue, the part that actually decays: keeping the register true after the project team has gone. If you need the platform stood up first, we will say so and point you across.
Where the boundary runs →Part of the Signify family
Solve · Build · Teach · Sustain. Four properties, one design language — consulting, software, interactive learning and sustained advisory, built in Philadelphia since 2019.
Premium management consulting across strategy, cybersecurity, audit, GRC and regulatory readiness. Every engagement partner-led.
signifysolution.comConsulting, new age. Seven practitioner-built products — the tools that stay behind at clients as running value.
signifyhive.comPlay, test, think. Games, assessments, simulations and Points of View — learn the work by doing it.
signifyinsights.com You are hereConsulting, sustained. Time-boxed, and scope-boxed engagements at transparent rates. Clear pricing. Explicit scope.
signifyimpact.com