Governance that defines ownership, evidence and control.
Governance and risk are not decorative compliance language. CollectiveIS uses them to define ownership, authority, evidence, escalation and decision-making across technology services — for its clients and for itself.
Control design, risk support and audit readiness.
Risk and control design
- Enterprise and operational risk identification and risk registers.
- Technology and financial-system control design.
- Governance frameworks, policies, standards, procedures and registers.
- Incident governance, decision logs and corrective-action tracking.
- POPIA-aligned information handling and accountability.
Assurance and evidence
- Supplier and third-party assurance and contract-control review.
- Audit-readiness evidence packs and management reporting.
- Control-gap assessment against defined frameworks.
- ISO 9001, ISO/IEC 27001 and ISO/IEC 20000-1 implementation support — stated as implementation support, never as a premature certification claim.
- Evidence retention, closure records and continual-improvement registers.
CollectiveIS provides technical assurance, control assessment, evidence preparation and audit support. It does not issue statutory external-audit opinions unless work is delivered through an appropriately registered audit firm under the correct engagement.
Deliverables that survive management, audit and procurement review.
| Deliverable | Control or evidence produced |
|---|---|
| Risk register and treatment plan | Owned risks, ratings, treatments, target dates and review cycle. |
| Policy, standard and procedure set | Approved documents with version control, ownership and review dates. |
| Control matrix | Controls mapped to systems, owners, frequency and testing evidence. |
| Audit-readiness evidence pack | Indexed evidence aligned to the audit scope, with gaps and remediation status. |
| Supplier assurance file | Third-party assessments, contract-control reviews and remediation monitoring. |
| Incident governance record | Decision logs, communications, corrective actions and closure evidence. |
Six control points applied to every engagement.
Authorisation
Written instruction, legal basis and defined scope before work begins; no testing or evidence work without documented authority.
Competence
Named, competent delivery ownership; specialist partners engaged under written agreements where the scope requires it, with their role disclosed.
Evidence
Documented methods, records, test results and acceptance criteria for every deliverable.
Security
Least-privilege access, POPIA-aligned information handling and audit logging across the engagement.
Commercial
Approved scope, assumptions, exclusions, client dependencies and change control stated in writing.
Service level
Defined support obligations, severity classes, escalation routes and reporting once a service is in operation.
Stated boundaries, so responsibility is never ambiguous.
- Assurance work depends on access to accurate client documentation, systems and personnel.
- Frameworks are implemented and assessed; certification itself is issued only by accredited certification bodies.
- Legal interpretation and statutory audit remain with the client’s appointed legal and audit advisers.
- Forensic evidence handling follows the controlled intake on the Digital Forensics and Data Lifecycle page.
