GRC & Compliance Readiness

Governance, Risk and Compliance Readiness

We help you work out which requirements genuinely apply to your organization, build the registers, policies and evidence habits behind them, and track remediation until you are ready for external scrutiny.

Readiness work is consulting. It prepares you for an examination, certification audit or customer review carried out by an independent party. We do not issue certifications or audit opinions.

When this helps

Situations we are usually called into

  • A customer contract or security questionnaire requires evidence you cannot currently produce.
  • You have been asked for a SOC 2 report or ISO 27001 certificate and need to know what that actually involves.
  • Policies exist as documents nobody follows, with no register linking them to real controls.
  • Vendor reviews happen by email and there is no record of what was assessed or accepted.
  • Remediation actions are tracked in scattered spreadsheets with no owners or due dates.

Scope & deliverables

What the engagement covers

Applicability and gap assessment

Establish what applies to you before buying tooling or writing policy.

  • Framework and obligation applicability analysis
  • Scope definition covering systems, people and locations
  • Gap assessment against the selected criteria
  • Prioritized readiness roadmap with effort estimates

Risk and control registers

A single source of truth linking risks, controls, owners and evidence.

  • Risk register with assessment method and treatment decisions
  • Control register mapped to the criteria you are targeting
  • Named control owners and operating frequency
  • Evidence expectations recorded per control

Policies and evidence operations

Documents your team can actually follow, and the routine that produces evidence.

  • Policy and procedure drafting or rewriting
  • Approval, publication and acknowledgement workflow
  • Evidence request lists and collection calendar
  • Readiness review of collected evidence before external testing

Vendor risk and remediation tracking

Third-party oversight and a plan that closes rather than accumulates.

  • Vendor inventory with criticality and data categories
  • Due-diligence questionnaire and review workflow
  • Review of vendor assurance reports you receive
  • Remediation tracker with owners, dates and status reporting

What you receive

  • Applicability and scope memo explaining what applies and why
  • Gap assessment with prioritized readiness roadmap
  • Risk register and control register with named owners
  • Policy set drafted or updated for your operating reality
  • Evidence request list, collection calendar and readiness review notes
  • Vendor risk workflow and a live remediation tracker with status reporting

What SOC 2, ISO 27001 and NIST actually are

A SOC 2 report is issued only by an independent CPA firm that performs an examination against the AICPA Trust Services Criteria; our role is readiness preparation and evidence discipline before that examination. ISO/IEC 27001 certification is issued by an accredited certification body after auditing your information security management system; we prepare the management system and evidence but cannot certify you. NIST publications such as the Cybersecurity Framework and SP 800-53 are voluntary guidance in most private-sector contexts and become mandatory only where a contract, regulator or sector rule imposes them. We will tell you plainly which of these applies to you and which does not.

How we work

A five-step engagement

  1. Step 01

    Determine applicability

    Review your contracts, sector, data and customer demands to establish which criteria you should target and in what scope.

  2. Step 02

    Assess gaps

    Compare current practice against the criteria, document evidence that already exists and rank the gaps.

  3. Step 03

    Build the programme

    Stand up risk and control registers, draft or rewrite policies and assign owners with operating frequencies.

  4. Step 04

    Operate and collect

    Run the evidence calendar, review what is produced and correct controls that are not operating as written.

  5. Step 05

    Prepare for external review

    Perform a readiness review, close remaining gaps and coordinate with your chosen auditor or certification body.

Working together

What we need from you, and how we handle your data

Your responsibilities

  • Assign an executive sponsor able to approve policy and settle ownership disputes.
  • Make control owners available; readiness fails when evidence has no owner.
  • Share contracts, customer requirements and regulator correspondence that drive applicability.
  • Select and engage the CPA firm or certification body; the examination or certification audit is theirs, not ours.

Data handling

  • We work with documentation, registers and evidence samples rather than bulk production data.
  • Evidence is exchanged through a channel agreed in writing, and personal data is redacted wherever a redacted sample suffices.
  • Registers and policies remain your property and are handed over in editable form.
  • Retention of our working copies is time-limited and stated in the engagement letter.

How we use enquiry information is set out in our privacy policy.

FAQ

GRC & Compliance Readiness: common questions

Can MarkKings Group issue our SOC 2 report?

No. A SOC 2 report is issued by an independent CPA firm following an examination. We prepare you for it: scope, controls, policies, evidence and remediation. Keeping those roles separate is also what makes the report credible to your customers.

Can you certify us to ISO 27001?

No. Certification is issued by an accredited certification body after it audits your management system. We help you build and operate that management system and prepare the evidence.

How long does readiness take?

It depends on your starting point, scope and how quickly owners act. Organizations with documented processes often need a few months; those starting from scratch usually need longer, particularly because Type II style examinations require evidence across an observation period.

Do we need a compliance tool?

Not necessarily. Tooling helps once controls and owners exist, and wastes money before that. We will tell you when your registers and calendar are enough and when automation genuinely earns its cost.

Which framework should we target?

Whatever your buyers, regulators or contracts actually require. Many technology companies are asked for SOC 2, international buyers often ask for ISO 27001, and some organizations only need to answer a customer questionnaire well. We assess applicability before recommending anything.

Will you help answer customer security questionnaires?

Yes. Once registers and evidence exist, questionnaire responses become straightforward, and we can prepare a reusable response set with accurate wording.

Discuss compliance readiness

Tell us what your customers are asking for and we will map what applies, what is missing and what it takes to be ready.

Stay Updated. Stay Ahead.

Subscribe to receive the latest business insights, technology updates, company news, and useful ideas delivered to your inbox.

We respect your privacy. Unsubscribe at any time.