Governance, Risk & Compliance
Risk and control, managed as one system and reported as one.
We help organisations design the frameworks, libraries and routines that turn risk appetite and regulatory obligations into owned controls, tested evidence and reporting the audit committee can rely on.
Nuralta · Strategy, GRC and performance advisory
What it is
Governance that holds together from board to control owner
Our GRC work covers the enterprise risk management framework and risk appetite, risk and control self-assessment, control libraries, policy and compliance management, the register of regulatory obligations, and support for internal audit. We then implement the result on Corporater, or on the GRC platform you already run. How we implement, integrate and support Corporater is set out on the Corporater solution page.
It is for chief risk officers, heads of internal audit, compliance functions and CFOs, and for the audit and risk committees they report to, in regulated industries and in government and semi-government entities alike.
The problem
Registers that describe risk without managing it
Many organisations hold a risk register, a control matrix, a policy library and a list of regulatory obligations, each kept by a different team, in a different format, updated on a different cycle. None of them quite refers to the others.
The result is familiar: assessments that repeat the previous year, controls with no clear owner, obligations that cannot be traced to a control, and committee packs assembled by hand the week before the meeting. The effort is real; the assurance it produces is thin.
How we work
From risk appetite to evidence
Set the framework and appetite
We agree the risk taxonomy, scoring method and appetite statements with management and the board, so every later assessment is measured against the same scale.
Build one control library
Risks, controls, policies and regulatory obligations are linked in a single library, with each control assigned to a named role and a testing method.
Run the assessment cycle
We design risk and control self-assessments that owners can complete without a workshop, and that internal audit can rely on and challenge.
Implement on the platform
The framework is configured on Corporater, or on the GRC platform you already run, with workflows, reminders and evidence capture, rather than left in documents and spreadsheets.
Report to the committee
Risk profile against appetite, control effectiveness, open issues and compliance status, in a pack the audit committee can read in one sitting.
What you end up with
What remains after we leave
- A risk framework and appetite statement approved by the board.
- A control library that traces every key risk and obligation to an owned control.
- An assessment and testing cycle your teams can run on their own.
- A GRC platform configured around your framework, not a generic template.
- Audit-committee reporting drawn from the same data the owners maintain.
Related services
Where GRC connects to the rest of the cycle
Enterprise Performance Management
Measurement, reporting and management information built around the questions leaders ask.
Read moreStrategy Management
From strategic objectives to KPIs, initiatives and performance reviews that drive decisions.
Read moreManaged Support
Corporater and SAP-integrated solutions kept running and improving after go-live, under agreed service levels.
Read moreAnalytics Advisory
Management and committee reporting, mainly on SAP Analytics Cloud, from your Corporater and SAP data.
Read moreNext step
Start with the framework you have
Most engagements begin with a short review of your current risk register, control matrix and committee reporting. We will tell you plainly what to keep and what to rebuild.