GRC Diagnosis

GRC Compliance Assessment

Identify which regulatory requirements and standards apply to your organization, where your main gaps are, and what actions to prioritize.

Focus: Applicability · Risk · Compliance · Roadmap Frameworks: ISO 27001 · NIS2 · DORA · GDPR · AI Act · ISO 42001 Deliverable: Executive report + prioritized roadmap
Request a GRC Assessment →

Compliance starts by knowing what applies to you

Many organizations accumulate requirements from clients, regulations, security standards, privacy obligations and new risks associated with the use of artificial intelligence.

The problem appears when everything is managed separately:

  • ISO 27001 on one side.
  • GDPR on another.
  • NIS2.
  • DORA.
  • AI Act.
  • ISO 42001.

The GRC Compliance Assessment provides an integrated view to determine which requirements are truly relevant, evaluate the organization's current situation, and establish a priority order.

How we work

01 — Scope

We define the organization's context: activity, sector, size, clients, geographies, technologies, data processing, providers, AI systems and contractual requirements.

02 — Applicability

We determine which regulatory frameworks and standards should be considered, depending on context: ISO/IEC 27001, NIS2, DORA, GDPR/LOPDGDD, EU AI Act, ISO/IEC 42001.

We do not automatically apply all frameworks to all organizations. The goal is to identify what genuinely applies to you and why.

03 — Gap Assessment

We analyze governance, policies, risks, security, privacy, resilience, third parties, incidents, continuity, AI and existing evidence, comparing the current situation with the required level.

04 — Prioritization

We classify gaps by criticality, risk, regulatory impact, commercial impact and implementation effort, so the roadmap doesn't become an endless task list.

05 — Roadmap

We build a phased action plan. The exact timeline will depend on each organization:

  • 0–30 days: critical actions and quick wins.
  • 30–90 days: implementation of priority controls.
  • 90–180 days: maturity, evidence and consolidation.

Areas of assessment

Governance

Roles, responsibilities and oversight.

Risk Management

Identification, assessment and risk treatment.

Information Security

Security controls, assets, access and incidents.

Privacy

Personal data processing, risks and obligations.

Third-Party Risk

Providers, contracts and external dependencies.

Business Continuity

Continuity, recovery and resilience.

AI Governance

Inventory, risks, responsibilities and controls over AI.

Compliance Evidence

Documentation and evidence to demonstrate compliance.

What you receive

  • 01. Executive Assessment Report: executive summary of the organization's status.
  • 02. Applicability Matrix: map of relevant regulations and standards.
  • 03. Gap Matrix: identified gaps and maturity level.
  • 04. Risk & Priority Matrix: risk classification and priorities.
  • 05. Compliance Roadmap: structured action plan.
  • 06. Executive Briefing: presentation of results with Management and key stakeholders.

The Assessment doesn't end with a PDF. The value also lies in interpreting the results together with the client.

Specially designed for organizations that…

  • Are not clear on which regulations apply to them.
  • Receive security questionnaires from clients.
  • Want to start ISO 27001 but don't know their current level.
  • Have growing privacy or cybersecurity obligations.
  • Work with regulated clients.
  • Are adopting AI without a formal governance system.
  • Need to present Management with a clear view of regulatory risk.

From diagnosis to implementation

The Assessment can become the starting point for specialized projects:

Do you really know which requirements apply to your organization?

Get a clear view of your main gaps, risks and priorities before starting isolated compliance projects.

Request GRC Compliance Assessment →

Initial 20–30 minute meeting · Assessment of context and project scope