Governance, Risk & Compliance
Passing audits and managing risk are not the same thing. Most GRC programmes are designed to do the former. We build ones that do both.
Who this is for: Organisations that have a compliance function but no risk management programme connected to it.
The problem: GRC programmes built around audit cycles produce documentation that satisfies reviewers but does not reduce real risk.
The outcome: A working risk, policy, and governance framework mapped to the regulations that actually apply to you.
The problem
GRC programmes built around compliance calendars and audit cycles tend to produce documentation that satisfies external reviewers but does not reflect how the organisation manages risk day to day. Controls exist on paper. Accountability sits with no one. The next audit passes. The risk does not change.
The failure usually starts with the risk assessment. Generic risk matrices with generic threats produce generic controls. When the risk register does not name real threats specific to your sector, geography, and operations, the controls it generates will not address the risks that matter most to your organisation.
For organisations operating across UK and Nigerian markets, the complexity increases. Different regulatory regimes, different supervisory authorities, different reporting obligations. Building separate compliance programmes for each jurisdiction wastes resource and creates inconsistency. Getting the two wrong creates risk in both.
Ownership is another common gap. A GRC programme without a named owner for each control tends to drift, because reviews slip and nobody notices until an auditor asks a question nobody can answer confidently. Governance that exists only in a policy document, and not in how decisions actually get made, is not governance.
Third-party risk is frequently the weakest part of an otherwise reasonable GRC programme. Organisations assess their own controls carefully and then hand sensitive data or system access to suppliers with no equivalent scrutiny. A single unassessed vendor can undo the rest of the programme.
What we do
FortressPoint builds GRC programmes for enterprises across UK and Nigerian markets. We start with a risk assessment that names your actual threats, by sector, geography, and technology profile. The controls we build are proportionate to those risks, not to a generic risk matrix.
We design governance structures that put accountability in the right places and keep it there. Policies your team will follow because they reflect actual operating procedures, not theoretical best practice. Risk registers that get reviewed because they say something useful about the threats your organisation currently faces.
We align the programme to the regulatory requirements that apply to your operations. In Nigeria that means NDPA 2023, CBN cybersecurity frameworks, NCC guidelines, and other sector-specific obligations where they apply. In the UK that means UK GDPR, NCSC guidance, and relevant sector regulation. For dual-market organisations we build one framework that covers both.
We build the third-party risk management process alongside the rest of the programme, not as a separate add-on. Supplier assessment questionnaires, risk rating methodology, and contractual security clauses are designed to work with your procurement process rather than sit beside it as an extra step nobody follows.
Governance work includes defining who owns each risk and each control, how escalation actually works when something goes wrong, and what gets reported to the board and how often. A GRC programme that a board cannot understand at a glance is not doing its job.
Who this is for
What you get
Why FortressPoint
We understand both UK and Nigerian regulatory environments in depth. Most GRC consultancies are strong in one market. The dual-market expertise we bring means you build one programme, not two.
We are direct about what you need and what you do not. GRC programmes that generate administrative overhead without reducing real risk are common. We build lean frameworks that your team can operate without dedicated compliance resource.
Every engagement produces something your organisation owns and can maintain. We do not build dependency on continued consultancy to run a GRC programme. We build capability.
We treat GRC, ISO 27001, and NDPA 2023 or UK GDPR compliance as one connected set of controls rather than three separate projects, because in practice they overlap heavily. That means less duplicated documentation and a lower total cost across the programmes your organisation actually needs.
Common questions
A GRC consultant assesses your organisation’s risks, designs the policy and control framework that addresses them, sets up the governance structure that assigns ownership and accountability, and helps you demonstrate compliance with the regulations that apply to you. The output is a working risk management system, not just a set of documents.
GRC is the broader discipline of governance, risk management, and compliance. ISO 27001 is a specific, certifiable standard for an information security management system, which sits inside a well-built GRC programme. Most organisations need GRC as the foundation and use ISO 27001 certification as formal, external proof that part of it works.
Cost depends on your organisation’s size, the number of regulatory frameworks in scope, and how much of a risk and policy framework already exists. A risk assessment is the usual first step and gives you a scoped, costed view of the rest of the programme rather than a generic estimate.
No, in most cases one well-designed programme can cover both, because the underlying disciplines, risk assessment, policy, controls, and governance, are the same. What changes between jurisdictions is which specific regulations apply, which we map into the same framework rather than building two parallel structures.
Third-party risk assesses the risk your suppliers and vendors introduce through the access or data you give them, rather than risk that originates inside your own organisation. It requires its own assessment process, because a supplier’s security posture is outside your direct control and needs to be evaluated and monitored rather than assumed.
If you need to build a GRC programme or bring an existing one up to the standard your regulators expect, contact us.