Governance, risk and compliance

Turn obligations into controls your firm can own, operate and prove.

A client questionnaire, insurer renewal, audit or confirmed obligation can expose the gap between what a firm says and what it can show. Tier 1 maps the requirement, prioritises the gap, coordinates implementation and builds evidence for a defensible answer.

Bring the requirement or deadline. Tier 1 supports controls and evidence but does not replace legal or other regulated advice.

Scroll to explore
02Tier 1

Section 02

Go beyond policies that exist only on paper.

The scope is matched to the firm's obligations, clients, insurer, operating model and risk profile.

Obligation and risk mapping

Identify applicable privacy, professional, contractual and assurance requirements, then connect them to material business risks.

Client and insurer assurance

Make questionnaire, tender and renewal answers match the controls that are operating and the evidence the firm can retain.

Privacy and data governance

Set ownership and controls around confidential information, personal information, suppliers, retention and approved AI use.

Essential Eight and ISO 27001

Choose a useful target, implement the required controls and pursue formal certification only when the business case supports it.

Payment and incident governance

Set decision, verification, escalation and response controls around high-value transfers, account compromise and data breaches.

03Tier 1

Section 03

Assess, prioritise, implement and evidence

Tier 1 reviews the current state, produces a short prioritised plan, works alongside the people who need to implement it and makes sure the evidence is ready when a client, insurer or auditor asks.

Translucent sheets aligned on a dark grid with a single amber marker.
04Tier 1

Section 04

Make each assurance answer defensible

A client questionnaire, insurer renewal or audit can expose the gap between a policy statement and daily operation. Tier 1 connects the answer to current scope, ownership, configuration and evidence.

Trace the requirement

Identify the source, scope and exact obligation before turning a broad question into technical work.

Check operation

Confirm that the control applies to the intended users and systems and that exceptions are known rather than hidden.

Retain useful evidence

Keep approvals, settings, reports, tests and review records that support the answer without collecting material for its own sake.

State the limit

Describe gaps, exclusions and planned work accurately so the firm does not overstate maturity or create avoidable commitments.

05Official guidance
06Questions

Straight answers

Common questions

Which framework should we use?

Start with the obligations, client expectations and risks that actually apply. Essential Eight can provide a useful technical baseline, while ISO 27001 can support broader management and assurance needs. The framework should serve the business case, not become the project by default.

Can Tier 1 complete our cyber insurance application?

Tier 1 can review the security questions, test whether the stated controls are operating and organise supporting evidence. Leadership remains responsible for the application, and coverage questions should be confirmed with the insurer or broker.

Does an assessment guarantee compliance or insurance cover?

No. An assessment provides a point-in-time view against an agreed scope. It does not replace legal or insurance advice, guarantee certification or bind an insurer. Its value is a clearer gap view, defensible evidence and a practical plan.

Can you help implement the findings?

Yes. Tier 1 can coordinate owners and providers, review completed work and maintain the evidence. The scope can also stop after the assessment if your internal team or existing provider will deliver the plan.

A quiet first step

Bring the issue already on your desk

Tell Michael what changed, who is asking and when a decision is needed. The first conversation will identify whether Tier 1 fits and the smallest responsible next step.

Book a confidential first call