Governance

A programme you can actually run.

Framework alignment, gap analysis, evidence models and a remediation plan sized to the team that has to deliver it rather than to the team the framework imagines you have.

Framework alignmentGap analysisEvidence models
Where programmes stall

The gap analysis is rarely the hard part.

Finding out where you fall short takes weeks. Living with the answer takes years, and that is where most programmes quietly stop. A plan with two hundred actions and no owners is not a plan, it is a description of how far behind you are.

Sequenced, not listed

Some controls unlock others. Ordering the work properly can cut the effort substantially before anyone has done anything.

Evidence designed in advance

Deciding what proof a control will produce, before the control is implemented, saves the scramble that happens at audit time.

Honest about capacity

A remediation plan that assumes headcount you do not have will be abandoned by the second quarter, and everyone involved knows it on day one.

Beyond the first framework

Once you answer to two regimes, the arithmetic changes.

Two frameworks asking for the same control should not create two programmes. Most of the overlap is real, and treating it as real is the difference between a manageable year and an impossible one.

This is the problem ControlGraph is being built to hold structurally, and it is the problem we work through by hand in the meantime. Either way the principle is the same, which is that a control stated once should answer everywhere it is asked.

01

Understand the obligation

What you are actually required to do, stripped of interpretation.

02

Assess honestly

Current state without the optimism that creeps into self assessment.

03

Plan to capacity

Work sequenced against the people and budget that exist.

04

Prove and sustain

Evidence that keeps working after the consultants leave.

What you are left holding

A programme, not a document.

The gap analysis is the easy part. What matters is whether anyone can still run this in eighteen months.

01

An honest gap analysis

Where you actually stand, without the optimism that creeps into self assessment when the person assessing has to live with the answer.

02

An evidence model

What proof each control should produce, decided before the control is built rather than scrambled for the week an auditor arrives.

03

A plan sized to the team you have

Sequenced so the work that unlocks other work comes first, and scoped to real capacity rather than the capacity the framework imagines.

04

Something you can take upstairs

A short account of the position, the plan and what it needs, in language that survives being forwarded.

Questions we get asked

Before you get in touch

The questions that come up most often, answered the way we would answer them on a call.

Which framework should we align to?

Usually the one you are obliged to, and after that the one your customers keep asking about. Where you answer to more than one, the overlap between them is real and treating it as real is what makes the year manageable.

We failed an audit. Where do we start?

With the findings, honestly read. A failed audit is an unusually clear list of what to do next, and organisations that treat it that way tend to come out of the next one in a much better position.

Do you write the policies for us?

We will draft them, but they have to describe what your organisation actually does. A policy copied from a template creates a gap between the document and the practice, and that gap is where most findings live.

How do we keep this going after you leave?

That is the part we design for first. Evidence that is produced as a by product of normal work keeps working. Evidence that depends on somebody remembering to collect it does not.

Facing a framework, an audit, or both?

The most useful first conversation is usually about the deadline and the team, not the standard.