GRC, cybersecurity and AI governance

Start with one pressure point. Keep the whole risk picture connected.

Bring the requirement, control concern or AI use case already in front of you. Tier 1 defines the boundary, connects the related risks and carries the agreed work through assessment, remediation, evidence and ongoing leadership where needed.

You do not need to diagnose the service first. Start with the issue that has urgency.

Scroll to explore
02One accountable specialist
03Choose your starting point

Choose your starting point

Which question are you trying to answer?

If the question is what the firm must do or prove, start with GRC. If it is whether important controls work, start with cybersecurity leadership. If it is how people can use AI without crossing the line, start with AI governance. If it crosses all three, Tier 1 will build one connected scope.

04What useful work leaves behind

What useful work leaves behind

Useful work should leave your firm easier to govern.

A useful engagement should make the next decision easier. The exact documents depend on scope, but the work is organised around practical outcomes rather than a report that sits unread.

A prioritised risk view

A short account of the material gaps, their business effect and the order in which they should be addressed.

Named ownership

Clear responsibility across leadership, staff, IT providers and other advisers, including decisions that cannot be delegated.

Control evidence

Records that show what is configured, approved, tested or still accepted as a visible risk.

A workable cadence

A review rhythm that matches the firm, with changes, exceptions and overdue actions brought back to leadership.

05Questions

Straight answers

Common questions

Can one engagement cover GRC, cybersecurity and AI governance?

Yes. They can be scoped as one risk and control program. Tier 1 can map the obligations, set priorities, coordinate cyber and AI controls, test what is operating and maintain the evidence, while legal and other regulated advisers remain responsible for advice in their fields.

We are only a few people. Are we really a target?

Yes. Small firms can still hold valuable information and move significant payments. Good basic security reduces the opportunity for an attacker without forcing a small team into an enterprise-sized program.

Do we need an expensive certification?

Usually not to start. Most firms gain more by getting the fundamentals right first. We help you decide whether a formal standard is worthwhile based on your risks, client expectations, contracts and insurer requirements.

We already have an IT provider. Why do we need you?

General IT keeps systems running. Security governance sets priorities, tests whether controls are effective and gives leadership a clear view of risk. We work alongside your existing provider and make the boundaries visible.

How much of our time will this take?

As little as practical. We do the heavy lifting and ask for input where leadership context or a business decision is required. The aim is to take security work off your plate, not create another reporting burden.

Where should we start?

Start with a short review of the information, payments, systems and obligations that matter most. You will receive a prioritised view of the urgent gaps, the sensible next steps and which work can wait.

A quiet first step

Bring the issue already on your desk

Tell Michael what changed, who is asking and when a decision is needed. The first conversation will identify whether Tier 1 fits and the smallest responsible next step.

Book a confidential first call