Solutions.

GRC-A Consulting

Governance. Risk. Compliance. Assurance.
Built to work, not to satisfy an audit and gather dust.

The problem with most risk frameworks

Ask the leadership of any South African business with a risk framework whether it's actively shaping decisions. The honest answer is usually no.

Frameworks fail not because organisations don't care, but because they're designed to produce documentation rather than management. They're reviewed once a year, understood by one person, and invisible to everyone who actually carries the risk.

We build GRC-A frameworks that work differently: integrated into operations, owned by real people, visible to leadership, and structured around the ISO 31000 standard for risk management.

What GRC-A consulting covers

Risk Framework Design

A risk management framework scoped to your organisation, including risk appetite, risk categories, assessment methodology, and governance structure. Aligned to ISO 31000:2018.

Risk Identification and Assessment

Facilitated workshops with your leadership and operational teams to identify, analyse, and evaluate the risks that matter. Not a generic list populated in isolation.

Treatment Planning

Documented treatment plans with named owners, specific actions, timelines, and residual risk ratings. Not recommendations. Commitments.

Governance and Reporting Structure

Risk reporting designed for the audience that needs it: operational summaries for management, strategic overviews for the board, and clear escalation paths between them.

Framework Implementation Support

We don't hand over a document and leave. We support the initial implementation, embedding the framework into how your organisation actually operates.

Review and Refresh

Risk landscapes change. We offer scheduled review engagements to update your register, reassess treatment progress, and respond to new risks.

ISO 31000: The Standard We Work To

ISO 31000:2018 is the international standard for risk management, published by the International Organization for Standardization. It provides principles, a framework, and a process applicable to any organisation regardless of size, sector, or risk profile.

It is not prescriptive. It defines what good risk management looks like, not exactly how to implement it. Our role is to make it operational for your specific context.

The Operational Layer: Axiom Risk

GRC-A consulting gives your organisation the framework. Axiom Risk gives it a live, accessible home.

Axiom Risk is our Airtable-based enterprise risk management platform, built to house the outputs of your GRC-A engagement and keep them active between review cycles. Risk register, treatment tracking, appetite thresholds, and governance reporting: all in one place.


Learn about Axiom Risk

Ready to build a framework that works?