SERVICE LINE 02 / 02 · IT GRC
Technology risk is business risk.
IT GRC Services help boards, executive leadership and technology leaders govern, manage and secure technology so that it supports business objectives, manages risk, meets compliance obligations and enables sustainable digital transformation — evidenced against the standards regulators and auditors already use.
- 9Practices in the line
- 19Standards and frameworks anchored to
- 6Disciplines integrated as one system
- 2003Practising since
- ISO/IEC 38500
- COBIT 2019
- ISO/IEC 20000
- ITIL® v4
- ISO/IEC 27001
- CIS Controls
- ISO/IEC 27032
- NIST CSF 2.0
- ISO 22301
- DRII PPF
- ISO/IEC 29100
- ISO/IEC 27701
- ISO/IEC 27017
- CSA Guidance
- ISO/IEC 42010
- TOGAF® 10
- ISO/IEC 22989
- ISO/IEC 42001
- NIST AI RMF
WHY THIS LINE EXISTS
The board stopped being able to delegate this.
As organizations become increasingly digital, technology stops being a function and becomes the medium the business runs in. Regulatory scrutiny, cyber threats, cloud adoption, data protection requirements and operational resilience expectations now land on the board — and none of them can be answered with a purchase order.
What they can be answered with is a structured, standards-based approach: six disciplines governed as one system, producing the same evidence whether the question comes from an auditor, a regulator, an insurer or a customer’s procurement team.
WHAT IT ENABLES
Five things a board can act on.
THE STANDARDS BEHIND THE LINE
Nineteen published standards and frameworks sit behind nine practices, so the work produces evidence an auditor, a regulator or a customer’s procurement team already knows how to read.
| Standard | What it governs |
|---|
THE PORTFOLIO
Nine practices, from the boardroom to the build pipeline.
Each practice is anchored to its own standards and can be engaged on its own — but they interlock, so an asset inventory built for security serves privacy, and a resilience test serves the regulator. Open any practice to see what the work covers and what it changes.
9 of 9 practices
WHERE THIS LANDS IN CANADA
Ontario stopped asking nicely.
Until recently, technology governance in the Canadian public sector was a matter of good practice. Regulation 51/26 changed that for prescribed entities: a cybersecurity program, named senior accountability, recurring maturity assessments, submitted results and a hard 72-hour incident clock — all of it evidenced, none of it satisfied by a product.
That is an IT GRC problem wearing a cybersecurity label, and it is the clearest signal yet of where Canadian technology obligation is heading. The practices on this page are how organizations answer it.
WHO THE LINE SERVES
WHY THIS PRACTICE
Three reasons the work survives scrutiny.
Dr. Orlando Olumide Odejide
IT GOVERNANCE · CYBERSECURITY · PRIVACY · RESILIENCE / TORONTO, ONTARIO
Advisory work is delivered against published standards rather than proprietary methodology, because a board should be able to check the framework its assurance rests on. Where a practice includes certification readiness, that means preparing the organization to be audited by an accredited body — the certificate itself is awarded by that body, never by the practice.
START HERE
Begin with a technology risk and governance review.
A scoped assessment of where your IT governance, security, privacy, resilience and architecture arrangements stand against the standards they will be measured by — with the gaps named in priority order and the evidence set a board, an auditor or a regulator will ask for.