The problem with most risk frameworks
Ask the leadership of any South African business with a risk framework whether it's actively shaping decisions. The honest answer is usually no.
Frameworks fail not because organisations don't care, but because they're designed to produce documentation rather than management. They're reviewed once a year, understood by one person, and invisible to everyone who actually carries the risk.
We build GRC-A frameworks that work differently: integrated into operations, owned by real people, visible to leadership, and structured around the ISO 31000 standard for risk management.
What GRC-A consulting covers
Risk Framework Design
A risk management framework scoped to your organisation, including risk appetite, risk categories, assessment methodology, and governance structure. Aligned to ISO 31000:2018.
Risk Identification and Assessment
Facilitated workshops with your leadership and operational teams to identify, analyse, and evaluate the risks that matter. Not a generic list populated in isolation.
Treatment Planning
Documented treatment plans with named owners, specific actions, timelines, and residual risk ratings. Not recommendations. Commitments.
Governance and Reporting Structure
Risk reporting designed for the audience that needs it: operational summaries for management, strategic overviews for the board, and clear escalation paths between them.
Framework Implementation Support
We don't hand over a document and leave. We support the initial implementation, embedding the framework into how your organisation actually operates.
Review and Refresh
Risk landscapes change. We offer scheduled review engagements to update your register, reassess treatment progress, and respond to new risks.
ISO 31000: The Standard We Work To
ISO 31000:2018 is the international standard for risk management, published by the International Organization for Standardization. It provides principles, a framework, and a process applicable to any organisation regardless of size, sector, or risk profile.
It is not prescriptive. It defines what good risk management looks like, not exactly how to implement it. Our role is to make it operational for your specific context.
The Operational Layer: Axiom Risk
GRC-A consulting gives your organisation the framework. Axiom Risk gives it a live, accessible home.
Axiom Risk is our Airtable-based enterprise risk management platform, built to house the outputs of your GRC-A engagement and keep them active between review cycles. Risk register, treatment tracking, appetite thresholds, and governance reporting: all in one place.
Learn about Axiom Risk