Assurance · GRC
GRC · The framework kept true
Assurance Consulting·GRC

The framework, kept true.

A policy set and an obligations register are the two documents every organization has and almost nobody re-tests. They are approved once, filed, and quietly go out of date — the same failure as an untended risk register, with the same consequence when somebody finally asks for evidence.

GRC is a management service, so your business commissions it — usually the Chief Compliance Officer or General Counsel. That is the opposite of internal audit one page over, and it has a consequence worth reading before you buy.

What actually breaks

Approved once, filed forever.

A policy set is written, approved and published. An obligations register is built for a certification and signed off. Both are accurate the week they land. Then a business unit is sold, a regulation changes, a system migrates, and a retention rule is quietly never enforced because nobody built the job that enforces it.

The documents still exist and still look authoritative. What has quietly stopped being true is the mapping between them and the organization — and mappings do not announce their own decay.

The comparison

Bought as a project. Delivered as a product.

Neither column is a caricature. The left is how this work is bought almost everywhere, including by people who dislike it.

How this is normally bought
A policy refresh project every few years
An obligations register built for one certification
Gaps discovered during an audit or an incident
A GRC platform implementation sold as governance
How it works here
Rationalized once, then re-tested quarterly — including review dates that have lapsed
Every obligation mapped to an owner and the evidence that demonstrates it
The obligations you cannot currently evidence, named — usually the least comfortable page in the deliverable
Implementation is Solution work, and we say so — what we sell is keeping the register true afterwards
The schedule

A baseline, then a quarterly loop.

Both GRC services share the shape: rationalize once, then keep it true on a printed cadence.

Baseline
Rationalize

Every policy or obligation in force, deduplicated, with an owner and a review trigger on each.

Partner gate
Baseline
Stand it up

The register lives in Clarus, not in a folder somebody owns.

Every quarter
Re-test

What changed, what lapsed, what was approved and never communicated.

Partner gate
Renewal
No second baseline

From $24,000 a year for the policy framework; $30,000 for obligations.

Why it repeats

Management’s service, not the committee’s.

Your business commissions this, which is the opposite of internal audit one page over — and the reason we cannot then audit what we maintain.

2
services — policies, and obligations
4
re-tests a year on each
1
baseline, ever
0
platform implementations — that is Solution work

Methodology 2026.2 — bumps when a box, a gate or a testing standard changes — never for a copy edit. Read it at working depth on the method page.

Assurance · GRC

Also hereOne product, two doors
  • 01Controls Framework, kept alive — key controls rationalized, baselined and monitored continuously, reported quarterly. Entered from GRC when the framework is ISO or SOC 2, and from finance when it is SOX
  • 02It is one product, not two — same unit, same formula, same rhythm. The framework you are held to is a scope choice, and we would rather say that than sell you the same work twice under different names
  • 03Price publishes when the box locks, like everything else here
Named once, sold onceSame house rule as the rest

Why these two, and not a platform.

Implementing a GRC platform is a build, and builds are Signify Solution work. What Impact does is narrower and, we would argue, the part that actually decays: keeping the register true after the project team has gone. If you need the platform stood up first, we will say so and point you across.

Where the boundary runs →