Section 02
Go beyond policies that exist only on paper.
The scope is matched to the firm's obligations, clients, insurer, operating model and risk profile.
Obligation and risk mapping
Identify applicable privacy, professional, contractual and assurance requirements, then connect them to material business risks.
Client and insurer assurance
Make questionnaire, tender and renewal answers match the controls that are operating and the evidence the firm can retain.
Privacy and data governance
Set ownership and controls around confidential information, personal information, suppliers, retention and approved AI use.
Essential Eight and ISO 27001
Choose a useful target, implement the required controls and pursue formal certification only when the business case supports it.
Payment and incident governance
Set decision, verification, escalation and response controls around high-value transfers, account compromise and data breaches.
