Governance, Risk & Compliance

Grow properly. Operate responsibly.

We help organisations understand their responsibilities, identify gaps and put workable controls, processes and practices in place.

Good governance should help the organisation work better, not create more paperwork.

Thabiso Naleli speaking at a lectern with a laptop

GRC should make sense to the people who have to use it.

  1. A policy nobody understands does not manage risk.
  2. A risk register nobody reviews does not protect the organisation.
  3. A checklist completed once a year does not make an organisation compliant.

Understand the obligation. Understand the risk. Put the right control in place.

What we help with

Six areas of practical governance work.

Growth brings more information, customers, systems, suppliers and obligations. Where legal interpretation, certification, external audit or regulated services are required, we work within the appropriate scope or with suitable specialists.

  • 01

    Governance

    Structures, roles, policy frameworks, approvals, registers and decision-making.

    Who is responsible for what, and how do we know it is being done?

  • 02

    Compliance

    Requirements turned into registers, responsibilities, checklists, evidence and reporting: POPIA, information security, internal policies, contracts, industry requirements.

  • 03

    Risk management

    Identify and describe risks, assess them, assign owners, agree treatment, keep a register that is actually reviewed.

    Risk should help people make better decisions, not fill a spreadsheet nobody opens.

  • 04

    Information governance

    What information you hold, where it lives, who can access it, how long it is kept and how it is protected.

  • 05

    Privacy and POPIA

    Information-flow reviews, personal-information inventories, consent, retention, breach-response preparation and evidence.

    What personal information do we have, why, and how are we protecting it?

  • 06

    Information security governance

    Responsibilities, policies, access, awareness, incident processes and management oversight, including work aligned to ISO/IEC 27001 where appropriate. Naleli Innovations does not act as a certification body.

Having a policy is not the same as implementing it.

A policy says “access must be reviewed regularly”. Who reviews it, how often, where is the evidence, and who checks that it is working?

  1. Policy
  2. Responsibility
  3. Process
  4. Control
  5. Evidence
  6. Review

That is practical compliance.

How we work

From obligation to evidence.

Understand, assess, prioritise, implement, support, monitor, improve. It fits UPISM without becoming another methodology.

  1. 01

    Understand

    What requirements, risks and structures exist today?

  2. 02

    Plan

    Which gaps matter most, and which controls are needed?

  3. 03

    Implement

    Policies, processes, registers and controls in place.

  4. 04

    Support

    Help responsible people apply them.

  5. 05

    Measure

    Review evidence, progress and emerging risks.

Proportionate to the organisation.

SMEs

Responsibilities, at the right size.

Clear responsibilities, basic policies, good records, protected personal information, access control, supplier records, cyber awareness.

NGOs and community organisations

Protect the organisation, its beneficiaries and its funders.

Governance processes, policies, risk registers, compliance tracking, information handling, reporting and evidence.

Corporates and programme owners

Implementation, awareness and evidence.

Process documentation, information governance, third-party and programme risk, control monitoring, and governance development for programme participants.

Prepare before somebody asks for the evidence.

Most organisations only look for documents when a client, auditor, tender or funder asks. Readiness is built over time: requirements identified, evidence organised, responsibilities assigned, registers maintained. It does not guarantee certification, tender success or regulatory approval. It means you are better prepared.

ISO and management systems: implementation and readiness, within a clear scope.

Gap reviews, implementation planning, policies and procedures, risk processes, control tracking, awareness and evidence preparation, including information-security and privacy management systems. Implementation support, internal readiness and training are not independent certification or external audit.

Cybersecurity is not only the IT department’s problem.

Shared passwords, excessive permissions, phishing, lost devices, unclear incident processes. Some need technical specialists. Most need governance, awareness and accountability, which is where we work. And when a process gets faster, we ask what governance and risk come with the change.

Explore Digital Operations

See How We Learn

Ways to engage

Documents are not the goal. An organisation that uses them is.

  • GRC baseline review

    Your current governance, risk and compliance position.

  • Compliance implementation support

    Requirements turned into actions, responsibilities and evidence.

  • Risk management setup

    A practical risk process that gets reviewed.

  • Policy and control implementation

    Policies, processes and the controls that make them real.

  • Information governance review

    How information is created, stored, accessed, shared and kept.

  • ISO readiness and implementation support

    Management-system implementation within the agreed scope.

  • Governance and compliance awareness

    Practical learning for staff, managers or programme participants.

Do not wait until somebody asks for the evidence

Tell us where you're stuck.

Growing, taking on new clients, handling more information, facing new requirements? You do not need to solve everything at once. Start with the biggest gaps.

No presentation required. Just bring the problem.