Governance, Risk & Compliance
Governance, Risk & Compliance · Capability

Enterprise risk & integrated assurance

A structured, auditable approach to enterprise, operational and project risk aligned to ISO 31000 and COSO, with internal audit and combined assurance linked directly to risks, controls and actions.

ISO 31000 and COSO answer different questions about risk, and a mature programme needs both. ISO 31000 gives you the principles and process for identifying, assessing and treating risk across the organisation with the flexibility to adapt to your size and sector; COSO's Enterprise Risk Management framework is more structured, tying risk explicitly to governance, internal control and strategic performance, which is why it's the reference point regulators and auditors reach for first. Building your risk register and controls against both means the same evidence satisfies whichever lens is being applied.

Internal audit and assurance activity plug directly into that same risk and control structure rather than running as a separate exercise with its own findings log. Every audit finding, control test and assurance activity links back to the specific risk and control it evidences, so combined assurance — the practice of coordinating internal audit, risk management and compliance rather than each producing an independent, overlapping report — becomes something the system supports structurally instead of something assembled manually at reporting time.

Part of Governance, Risk & Compliance

We implement XGRC®, the 4Sight alliance's governance platform from Strategix — a single, auditable foundation that unifies governance, risk, compliance, cybersecurity, safety and ESG instead of managing each in a separate spreadsheet or system. Adopt the module that solves your most pressing problem today, then combine more over time on the same platform, without migrating data or rebuilding processes.

Also part of Governance, Risk & Compliance
Questions we hear about Governance, Risk & Compliance
How is this different from tracking risk and compliance in spreadsheets?

A spreadsheet answers one question at a time and has no audit trail. XGRC keeps risks, controls, obligations and evidence linked to each other on one platform, so an auditor sees a live, defensible record instead of a reconstruction exercise — and a control failure in one area shows up against the risks and obligations it actually affects.

Do we need all the modules, or can we start with one?

Start with whichever problem is most pressing — often cybersecurity governance (MSXCyber) or safety and quality (SHEQX) — and add modules later on the same platform without migrating data or rebuilding processes. That staged approach is how the platform is designed to be adopted.

Which frameworks and standards does this map to?

ISO 27001 for information security, ISO 9001 for quality, ISO 14001 for environmental management, ISO 45001 for health and safety, and ISO 31000 with COSO for enterprise risk. Which of these actually bind you depends on your sector, lenders and customers — the same assessment work we do for ESG reporting applies here.

What is MAIA and is it safe to use with sensitive governance data?

MAIA is governed AI embedded within XGRC, built so decision-makers can ask questions of risk registers, policies and audit records and get instant answers — through controlled, audited AI integrations with a complete interaction audit trail. Every query and answer is logged, which is the point: it's an audited channel into your governance data, not an open AI tool pointed at it.

Platforms: XGRC · MSX · MSXCyber · SHEQX