Several frameworks, one program
We keep you ready for audit and check that each control still works, for every framework that applies to you. A framework added later joins the program already running.
GRC as a service (GRCaaS)
GRC as a service suits companies whose customers, auditors and board keep asking for proof after the audit. We keep three things current on one retainer: governance decisions, your risk register (the running list of your security risks, each with a named owner) and audit readiness.
Work that recurs
A project has no reason to schedule any of them. Each one only makes sense if someone is still there to repeat it.
We keep you ready for audit and check that each control still works, for every framework that applies to you. A framework added later joins the program already running.
Every risk has a named owner and every change is recorded, so the register keeps matching the business.
Cyber posture packs (a summary of your security position) with risk heat maps, so your board can see where exposure sits and which decisions are waiting. On the enterprise tier, we also report to your board directly.
Suppliers are tiered by risk and evaluated as an active program, not only reviewed when an audit puts them in scope. See third-party risk management.
A project writes your cryptographic standard (how you use encryption) and your secure development standard (how your team writes safe code) once. A retainer reopens both twice a year, so the review sits on a calendar rather than on someone's memory.
Your executives talk through ransomware and data breach scenarios in a Blue Team tabletop exercise. Leadership teams change, and a plan last year's team rehearsed is new to their successors, so the exercise recurs.
Need only one part? Compliance as a service keeps audit evidence current, and risk management as a service does the same for the risk register and board packs. GRC as a service runs both, with governance decisions, as one program. Working on one framework first? See what ISO 27001, SOC 2, NIST CSF 2.0 and ISO/IEC 42001 each ask of you.
Project or program
The choice turns on what keeps running once the report arrives.
GRC consulting takes you from gap assessment through audit, then leaves a calendar of work that recurs. Someone has to run that calendar. If nobody is charged with it once the project closes, the risk register drifts away from the business.
In NIST's Cybersecurity Framework (CSF) 2.0, governance does not stop once policy is written: strategy and policy are set, communicated and monitored, and the results are used to adjust the strategy. A project can write the policy. The monitoring and adjusting come afterward.
GRC as a service runs that loop as one retainer program. It keeps governance decisions, the living risk register and audit readiness together for the term. The aim is lower risk and an audit position you can defend.
If you need one audit and nothing after, a scoped project serves you better. The five checks below help you tell which one you need.
In NIST's Cybersecurity Framework (CSF) 2.0, the Govern Function covers how an organization's cybersecurity risk management strategy, expectations and policy are set, communicated and monitored.
Its Oversight category (GV.OV) uses the results of risk management activities to improve and adjust the strategy.
Project against retainer
The same GRC work, compared after the auditor signs off.
| Area | One-off GRC project | GRC as a service |
|---|---|---|
| How it is bought | A fixed scope aimed at one audit or report | A retainer with committed monthly hours |
| Risk register | Current only while your own team maintains it | Kept live, with owners and changes recorded |
| Control evidence | Gathered for one audit window | Validated across the whole retainer term |
| Suppliers | Reviewed if they were in scope | Tiered and evaluated as an active program |
| Board reporting | A closing report | Board-ready cyber posture packs with risk heat maps |
| An incident | Outside the project's scope | Escalation coordination and hands-on response |
Making the call
Take them in order. Each answer narrows the choice.
List every customer, regulator and board member who asks for security evidence. One request points to a project. Requests that keep coming point to a program.
Find the calendar of recurring GRC work and put a name beside each item that actually ran this year. Every blank is work nobody is running.
Fill the roles listed below before signing, or the program will report on risks nobody treats.
The enterprise tier includes direct reporting to your board and incident escalation coordination (making sure an incident reaches the right people in your company). The mid-market / growth tier includes continuous automated compliance monitoring: automated checks that your controls keep producing evidence. The tier table for managed security and compliance services sets the two side by side.
Set the term so the program covers your next audit, board review and major customer renewal.
Your side of the table
Accountability for risk stays inside your company on either tier. These are the people who carry it.
How owners turn each risk into a decision is covered under risk management.
What this does not include. We are a consultancy, not an auditor, a certification body or a CPA firm. We cannot issue an ISO/IEC 27001:2022 certificate or a SOC 2 report, and no consultant can promise an audit result. What we work on is how ready you are when the audit starts.
FAQ
Term, hours, frameworks and audits. For anything else, ask us directly.
GRC as a Service (GRCaaS) is governance, risk and compliance work run as one retainer program. At SecWiz it keeps a living risk register, validates controls for your frameworks, manages third-party risk, reviews cryptographic and secure development standards twice a year and runs executive tabletops, for a term of at least 6 months and 12 months by default.
A project is scoped to one audit or report, then hands the recurring work to your team, so the register, policies and evidence age unless someone maintains them. GRC as a service keeps that material current across a retainer term with committed monthly hours, and adds board reporting, supplier risk work and rehearsed incident escalation.
A SecWiz GRC retainer runs 12 months by default and 6 months at minimum. Boards and auditors judge governance by whether it has held, and a policy adopted last month, a risk treated last week or a new staff habit has no track record yet. A company that needs one audit and nothing after is better served by a scoped project.
It depends on the tier: around 20 to 25 committed fractional executive hours a month on the mid-market / growth tier, which also carries continuous automated compliance monitoring, or around 40 to 50 dedicated hours a month on the enterprise tier, which includes direct board-level reporting and incident escalation coordination. The hours size the commitment and are not a task list.
A SecWiz GRC program can hold ISO/IEC 27001:2022, SOC 2, NIST CSF 2.0 and ISO/IEC 42001:2023, in whatever mix applies to your company. Where several apply, they run as one program sharing a living risk register instead of a project per framework. NIST CSF 2.0 has no certificate, so there the work tracks outcomes.
No. SecWiz is a consultancy, not an auditor, and no consultant can promise an audit result. An accredited certification body issues an ISO/IEC 27001:2022 certificate, and a licensed CPA firm issues a SOC 2 report. A retainer works on the state you arrive in: current evidence, a register that matches the business, and owners who can explain their controls.
Let's talk
Tell us your frameworks and who asks you for evidence. The first conversation covers whether a project or a retainer suits you. We reply within one working day.