Services / Governance, Risk & Compliance
Governance, Risk & Compliance
Our fastest-growing practice — 12+ modules across compliance, risk, audit and resilience. Buy one, or let a vCISO orchestrate them all.
5.1
Compliance & Certifications
ISO/IEC 27001:2022
- Gap assessment
- Documentation & Annex A control implementation
- Internal audit & certification-audit support
SOC 2 (Type I / Type II)
- Trust Services Criteria mapping
- Readiness assessment
- Support through the third-party audit
GDPR / HIPAA
- Readiness assessments for personal and health data
- Control design & evidence
UK Cyber Essentials
- Baseline certification for UK operations or UK clients
Our own posture, stated plainly: ROUNDBOX is actively preparing for ISO 27001:2022, SOC 2 Type II, HIPAA and UK Cyber Essentials. We describe our services as aligned with these frameworks — never as “certified” — until certification is achieved.
5.2
Risk & Governance
vCISO / CISO as a Service
Recurring executive security leadership without the executive payroll. Board reporting included.
Risk Assessment & Management
Risk register, matrix, treatment plans and quarterly review cadence.
Policies & Governance Frameworks
Information-security policy suite built for your regulator, not a template.
Third-Party / Vendor Risk
Supplier risk assessment and monitoring. Orbis Shield TPRM — Partner Preview
5.3
Audit & Continuous Monitoring
- Internal compliance audits (pre-certification)
- Continuous controls monitoring
- Periodic compliance reporting for boards and regulators
5.4
Continuity, Resilience & People
- Business continuity & disaster recovery plans (BCP/DR)
- Security awareness training
- Phishing simulations and human-risk maturity measurement