Consulting services

We do not just advise. We deliver.

Every engagement is led by practitioners who have held the roles our clients operate in - across all three lines of defence, in some of the most complex regulated environments globally.

WHAT WE DO
We design fit-for-purpose frameworks, digitise them in the right platform, and embed them so people actually use them. Four consulting practices, each grounded in real delivery - not theory.
01 - Our practices

Four consulting practices. One delivery standard.

01

Enterprise & Operational Risk

End-to-end enterprise risk management - from strategy and policy design through to maturity assessment, risk appetite, and ongoing governance.

Risk Strategy
Risk Policy, Framework and Key Risks
Risk Appetite
Risk Maturity Assessments
Emerging and Escalating Risk
Virtual CRO
GRC Tool Implementation
Third Party Risk Management
ISO 31000COSO ERMAPRA CPS 220MaturityOne
02

Cyber & Technology Risk

Full-spectrum cyber and technology risk services - from board-level risk management and third-party cyber oversight through to technical assurance and managed security.

Cyber Risk Management
Cyber Third Party Management
Security Strategy, Transformation and Design
Governance, Risk and Compliance
Technical Security Assurance
Managed Security Services
Cyber Culture, Influencing and Awareness
CPS 234Essential EightNIST CSF 2.0MaturityOne
03

Data & AI Governance

From standing up your AI governance program through to ISO 42001 certification readiness, risk framework design, and regulatory impact assessment. Led by an ISO 42001 Lead Auditor.

AI Governance program Setup
ISO 42001 Readiness and Lead Auditor Assessment
AI Risk Framework Design
Responsible AI Policy Development
EU AI Act Impact Assessment
Data Governance Maturity
ISO 42001EU AI ActNIST AI RMFWahid AIMaturityOne
04

GRC Tool Selection & Implementation

Full six-module GRC lifecycle coverage - from independent product selection across 180+ vendors through to long-term value measurement. Tool-agnostic.

GRC Product Selection (180+ vendors)
Implementation Assurance (12-stage)
program Oversight and Governance
Improvement Audit and Benchmarking
Comprehensive ROI Assessment
ArcherSAI360ProtechtServiceNowRiskBridge
02 - Sectors we serve

Deep experience across regulated industries.

Financial Services
Banking, insurance, super, wealth management
Healthcare
Health insurance, aged care, clinical governance
Telecommunications
Enterprise telco, network infra, digital services
Government
Federal, state, and local government agencies
Logistics & Ports
Container terminals, supply chain, critical infra
Critical Infrastructure
Energy, utilities, transport, essential services
03 - Engagement models

Three ways to engage.

Advisory

Short-term, scoped engagements

Defined deliverables, outcome-priced. Typically 4–12 weeks. Risk appetite frameworks, maturity assessments, GRC selection, AI governance readiness, cyber reviews.

Embedded

Long-term, integrated into your team

Practitioner works inside your organisation, reporting to your leadership. Typically 3–12 months. GRC implementations, transformation programs, capability uplift.

Fractional

Part-time CRO, CISO, or Head of Risk

Senior practitioner operating as a fractional risk or cyber leader - board reporting, committee support, team coaching, strategic direction. Ongoing retainer.

Ready to talk?

Start with a conversation.

Whether you are evaluating GRC platforms, assessing your risk maturity, navigating AI governance, or looking for a practitioner who has done the work - we respond within one business day.