The challenge

What the organization was facing.

Governance, risk and compliance activity was spread across business units in disconnected spreadsheets. There was no consolidated view of enterprise risk, third-party assessments were inconsistent between units, and board reporting was assembled manually each quarter from sources that did not reconcile.

What ISC did

The approach.

  1. 01

    Defined a GRC operating model setting out who owns risk identification, acceptance, treatment and reporting across business units.

  2. 02

    Consolidated the fragmented registers into a single enterprise risk register with a consistent scoring methodology.

  3. 03

    Established a third-party risk process with tiered assessment depth based on vendor criticality and data access.

  4. 04

    Built a control testing cadence so assurance was continuous rather than annual.

  5. 05

    Implemented metrics and dashboards feeding a repeatable board reporting pack, and took on ongoing operation of the cycle.

Outcomes

What changed.

  1. 01

    A single reconciled enterprise risk view replacing disconnected business-unit registers.

  2. 02

    A consistent, risk-tiered third-party assessment process.

  3. 03

    Repeatable board reporting produced from live data rather than manual assembly.

Services used

Capabilities behind this engagement.