Frameworks we work with.

We're framework-fluent but vendor-agnostic. The right framework depends on your industry, regulator, and stage. These are the ones we work with most:

COSO ERM 2017

Cross-industry ERM. The default starting framework for most large enterprises.

ISO 31000

International ERM standard. Useful when working across geographies or with non-U.S. counterparties.

NIST CSF 2.0

U.S. cyber risk framework. The 2024 update materially strengthened the Govern function — most programs haven't caught up.

FFIEC CAT

U.S. financial-institution cyber assessment tool. Examiner-aligned.

Basel III / IV

Bank credit, market, and operational risk. Capital calculations and stress testing.

SR 23-4

Interagency TPRM guidance. The current U.S. baseline for bank third-party risk.

NYDFS Part 500

New York DFS cybersecurity requirements. Some of the strictest U.S. state-level cyber rules.

SOX-ITGC

Sarbanes-Oxley IT general controls. Public-company audit infrastructure.

HIPAA / HITECH

U.S. healthcare data protection. Baseline for any healthcare engagement.

SR 11-7

Federal Reserve model risk guidance. The lineage of most modern AI / model-risk governance.

Platforms we implement.

We don't sell platform licenses or take vendor commissions. We're independent.

GRC

ServiceNow IRM · Archer · MetricStream · LogicGate · AuditBoard

TMS & Treasury

Kyriba · GTreasury · FIS Quantum · Trovata · ION

EHR

Epic · Cerner (Oracle Health) · Athenahealth · Allscripts

TPRM Tools

OneTrust · ProcessUnity · Aravo · BitSight · SecurityScorecard

Cloud Security

AWS Security Hub · Microsoft Defender · Wiz · Lacework · Prisma Cloud

SIEM & SOC

Splunk · Sentinel · Sumo Logic · Chronicle · CrowdStrike

Want to talk about a specific framework or platform?

60-minute call with a practitioner who has implemented it.