Governance, Risk and Assurance

Governance that defines ownership, evidence and control.

Governance and risk are not decorative compliance language. CollectiveIS uses them to define ownership, authority, evidence, escalation and decision-making across technology services — for its clients and for itself.

Capability areas

Control design, risk support and audit readiness.

Risk and control design

  • Enterprise and operational risk identification and risk registers.
  • Technology and financial-system control design.
  • Governance frameworks, policies, standards, procedures and registers.
  • Incident governance, decision logs and corrective-action tracking.
  • POPIA-aligned information handling and accountability.

Assurance and evidence

  • Supplier and third-party assurance and contract-control review.
  • Audit-readiness evidence packs and management reporting.
  • Control-gap assessment against defined frameworks.
  • ISO 9001, ISO/IEC 27001 and ISO/IEC 20000-1 implementation support — stated as implementation support, never as a premature certification claim.
  • Evidence retention, closure records and continual-improvement registers.

CollectiveIS provides technical assurance, control assessment, evidence preparation and audit support. It does not issue statutory external-audit opinions unless work is delivered through an appropriately registered audit firm under the correct engagement.

What clients receive

Deliverables that survive management, audit and procurement review.

DeliverableControl or evidence produced
Risk register and treatment planOwned risks, ratings, treatments, target dates and review cycle.
Policy, standard and procedure setApproved documents with version control, ownership and review dates.
Control matrixControls mapped to systems, owners, frequency and testing evidence.
Audit-readiness evidence packIndexed evidence aligned to the audit scope, with gaps and remediation status.
Supplier assurance fileThird-party assessments, contract-control reviews and remediation monitoring.
Incident governance recordDecision logs, communications, corrective actions and closure evidence.
Engagement controls

Six control points applied to every engagement.

Authorisation

Written instruction, legal basis and defined scope before work begins; no testing or evidence work without documented authority.

Competence

Named, competent delivery ownership; specialist partners engaged under written agreements where the scope requires it, with their role disclosed.

Evidence

Documented methods, records, test results and acceptance criteria for every deliverable.

Security

Least-privilege access, POPIA-aligned information handling and audit logging across the engagement.

Commercial

Approved scope, assumptions, exclusions, client dependencies and change control stated in writing.

Service level

Defined support obligations, severity classes, escalation routes and reporting once a service is in operation.

Limitations and dependencies

Stated boundaries, so responsibility is never ambiguous.

  • Assurance work depends on access to accurate client documentation, systems and personnel.
  • Frameworks are implemented and assessed; certification itself is issued only by accredited certification bodies.
  • Legal interpretation and statutory audit remain with the client’s appointed legal and audit advisers.
  • Forensic evidence handling follows the controlled intake on the Digital Forensics and Data Lifecycle page.
Governance support

Discuss governance, risk or audit-readiness support.

CollectiveIS will confirm the appropriate scope, evidence requirements and next step.

Request a Capability Meeting