Services / Governance & Supply
Governance, Risk, Compliance & SoD
Controls that live in a policy document are not controls. We design the risk and control matrix, translate it into system roles, and prove enforcement with evidence your auditors and your board can both read.
- Practice
- Governance & Supply
- Best fit
- Best fit ahead of an audit, alongside an ERP go-live, or after an incident that a control should have caught.
- Industries
- Manufacturing · Distribution · Healthcare · Education · Retail · Professional Services
What’s included
Scope, stated before we start
Six work-streams that make up a standard engagement. Anything outside them is priced separately and named in the proposal — never absorbed quietly.
Risk & control matrix
Process-level risks mapped to preventive and detective controls, with owner, frequency and evidence source stated for each one.
Segregation-of-duties design
A conflict matrix across create/approve/pay, master-data maintenance and reconciliation, mapped down to actual ERP permissions rather than job titles.
Role redesign & remediation
Rebuilt role definitions that remove conflicts, plus documented compensating controls where headcount makes full separation genuinely impossible.
Continuous control monitoring
Automated exception reports — duplicate vendors, out-of-policy approvals, bank-detail changes, backdated entries — routed to owners on a schedule.
Policy & delegation of authority
Approval thresholds and a delegation-of-authority schedule written so that what the policy says and what the system enforces are the same thing.
Audit readiness pack
Control descriptions, walkthrough evidence, access-review records and a remediation tracker — assembled once and maintained, not rebuilt each audit.
Outcomes
What changes when this is done properly
These are the three differences clients describe six months after go-live — not feature claims.
- SoD conflicts identified and closed at permission level
- Exceptions monitored continuously, not sampled annually
- Audit evidence assembled before it is requested
Not sure this is the right service? Discover is a fixed-price, two-to-three week assessment that answers the question with evidence — and it is usable whether or not you appoint us. Start there instead →
Who it’s for
Industries where this comes up most
Each links to how the service is shaped for that sector — the requirements differ more than vendors admit.
Our approach
The same four phases, applied to this scope
Reused deliberately. A consistent method is what makes a fixed price honest and a date holdable.
01
Discover
Process mapping before software selection.
We walk the floor and the ledger. Two to three weeks of structured interviews and document tracing produce a current-state process map, a data-quality baseline, and a written list of the decisions your systems cannot currently answer.
02
Design
One target architecture, agreed on paper.
Chart of accounts, item and customer master rules, approval hierarchies, integration contracts and reporting model are designed together — not discovered during build. You sign off a blueprint, not a demo.
03
Deliver
Configure, migrate, test, train — in that order.
Iterative configuration with fortnightly conference-room pilots. Data migration runs three times before go-live: trial, dry run, and cutover, each reconciled to the closing trial balance. Users train on their own data.
04
Sustain
Hypercare, then measurable adoption.
Four to eight weeks of hypercare with named owners and a burn-down of issues. Then a governance rhythm: master-data stewardship, monthly close review, and a Power BI adoption dashboard that shows whether the system is actually being used.
Related case study
Product costing the shop floor actually recognises
Standard costs that had drifted for years rebuilt against real routings and consumption, with shop-floor capture on rugged terminals and variance reported per production order.
Our board finally reads the same numbers we do. Month-end reporting dropped from eleven working days to four, and nobody rebuilds a spreadsheet to get there.
Then we design compensating controls and document them: independent review of a defined exception report, dual authorisation on high-value payments, and periodic reperformance. Auditors accept designed compensation; they do not accept silence.
We design and remediate. We are not your statutory auditor, which is precisely why we can rebuild the roles and controls rather than only reporting on them.
COSO for the control framework, ISO 27001 for information security, and the specific requirements of your regulator or group policy. We map to what you are actually held to, without ceremony.
Four to six months to design, remediate and generate a period of evidence. Starting six weeks out gets you a documented plan and honest disclosure — better than nothing, but not the same thing.
More in Governance & Supply
Delivered by the same team
Master Data Governance
One customer, one item, one vendor — with rules and stewards that keep it that way.
MDMProcess Reengineering
Fix the process before you automate it — otherwise you buy a faster version of the problem.
BPRSOPs & Policies
Documentation people actually use — role-based, versioned, and tied to the system.
SOPNext step
Talk to someone who has implemented GRC & SoD before
Not a sales call. A working conversation with the person who would run the engagement, and a straight answer on scope, sequence and cost.