GRC & compliance

Compliance is not paperwork for its own sake — it is proof that you manage risk. We turn the frameworks you are measured against into a programme your team can actually run.

What is included

  • NDPA/NDPC readiness assessment and data-protection documentation
  • ISO/IEC 27001:2022 gap analysis and implementation roadmap
  • Policy suite development — information security, access control, incident response and more
  • Risk assessment and risk register setup
  • Vendor and third-party risk management process
  • Audit support and evidence preparation

How it works

  • We assess where you stand against the framework you are targeting
  • You get a gap analysis with a prioritised, costed remediation roadmap
  • We draft or remediate the documents the framework requires
  • We support implementation and evidence collection
  • We stay through the audit and help you answer the auditor

Who it is for

Fintechs and MFBs under CBN expectations, data controllers under NDPA, companies pursuing ISO 27001 certification, and any business whose enterprise customers send security questionnaires.

Common questions

Can you certify us?

We prepare you for certification and support you through the audit. The certificate is issued by an accredited certification body — anyone promising the certificate and the consulting in one package is selling you a conflict of interest.

How long does ISO 27001 readiness take?

Typically 4 to 9 months depending on your starting point and how much of the policy estate already exists.

We are a small company — is this overkill?

No. NDPA obligations apply regardless of size, and an enterprise customer’s first question is usually a security questionnaire. The programme is scoped to your size.

Free · no obligation

Start with a free Security Posture Assessment

A bounded, fixed-scope review that tells you where you stand — and what a regulator or a customer’s due-diligence questionnaire would find.

Prefer to talk first? Contact the team →

  • A scored assessment report you keep, whether or not you engage us
  • The compliance gaps we can see from outside your network
  • A prioritised list of what to fix first, and roughly what it costs
  • A clear recommendation on tier and scope — no hard sell