Service

Policy, Governance & Compliance

The structures larger organisations take for granted.

Small governance meeting reviewing policy documents

Overview

As organisations grow, customers, funders and partners start asking harder questions: what are your policies, how is data handled, who is accountable, how are risks managed. We help build proportionate governance, policies and procedures that reflect how the organisation genuinely works, supported by practical risk, data protection and cybersecurity governance. We provide business advisory support and do not provide legal advice.

What this includes

Capabilities

  • Policy development and review
  • Procedures and internal controls
  • Governance frameworks and accountability
  • Data protection and information management
  • Cybersecurity governance and risk
  • Risk registers and management routines
  • Cyber Essentials and compliance readiness
  • AI use policies and responsible AI governance

Outcomes

What changes for the organisation.

  • A consistent, current policy set
  • Clear ownership and decision-making
  • Documented handling of data and information
  • Risk identified and reviewed on a routine basis
  • Stronger position in tenders, audits and due diligence
  • Governance proportionate to the size of the organisation

How we work

Understand → Assess → Recommend → Implement → Review

  1. 01

    Understand

    We start with the business, not the solution. How work arrives, how it is delivered, where it slows down and what leadership actually needs.

  2. 02

    Assess

    We assess processes, systems, commercial activity, governance and capacity, and identify where the real constraints sit.

  3. 03

    Recommend

    We set out proportionate, prioritised recommendations with realistic sequencing, cost and effort, not a wish list.

  4. 04

    Implement

    Where appropriate we deliver the work: processes, systems, policies, CRM, automation, procurement activity and project support.

  5. 05

    Review

    We review what changed, what is being used, what is measurable and what should happen next.

Start with a conversation about the business problem.

We will talk through where the organisation is, what is slowing it down and whether we are the right people to help.