Governance, risk and compliance

Measure your compliance. Prove it.

Compliance Manager at the centre, regulations around it: NIST, GDPR, Swiss nFADP, FINMA, ISO 27001, NIS2, DORA, AI Act. I turn requirements into measured controls, action plans and evidence.

Compliance Manager

Assessments, scores, improvement actions and evidence, directly in your Microsoft 365 tenant.

Frameworks

NIST CSF and 800-53, ISO 27001 / 27002, CIS: choose the baseline your auditors understand.

Regulations

GDPR and nFADP for data, FINMA for Swiss finance, NIS2 and DORA for resilience, AI Act for AI.

Accreditation

French interministerial instructions (II 901, IGI 1300), RGS: preparing a strict accreditation.

Governance

Policies, RACI, committees, indicators: living compliance, not a binder.

Responsible AI

AI baseline assessment, risk mapping, AI Act alignment and internal framework.

What I do for you

Compliance

Audit

Compliance review

  • Definition and choice of your baseline
  • Audit activation and evidence collection
  • Review of findings, report, optional remediation
Regulatory

Regulatory assessment

  • GDPR, nFADP, FINMA, NIS2, DORA: gap analysis
  • Short, medium and long-term action plan
  • Executive summary for leadership
Programme

Compliance programme

  • Quantified objective (for instance from 40 to 80%) and trajectory
  • Governance, committees, indicators
  • CISO and DPO support
AI

AI governance

  • AI baseline assessment in Compliance Manager
  • Risk mapping and usage framework
  • AI Act alignment and documentation

The method, applied

Six steps, one thread.

From a measured starting point to an objective defended in committee.

One control implemented serves several frameworks at once.

Classify your AI usages by risk level.

Method

  1. 01Scoping

    Understand the need, the stakes and the constraints. Set the scope, the actors and the expected results.

  2. 02Audit

    Observe the current state without assumptions: configurations, usage, documents, interviews and tool-based measurements.

  3. 03Analysis

    Confront the findings with frameworks and your objectives. Measure the gaps, qualify the risks, prioritise.

  4. 04Design

    Design the target and the path to reach it: architecture, governance, budget, licences, milestones.

  5. 05Transcription

    Translate the target into operational documents your teams and vendors can execute without me.

  6. 06Delivery

    Present, get stakeholder sign-off, transfer knowledge and support the implementation.

Where is our compliance score?

Compliance ManagerISO 27001
Start
40%
Today
63%
Objective
80%
Next actionEndpoint encryption · +6 points

Illustrative example

Workshops and knowledge transfer

Dense, practical sessions that make your teams autonomous.

Compliance Manager: getting started and steering GDPR and nFADP mapping in Microsoft 365 Preparing an ISO 27001 audit with Microsoft tools NIS2 and DORA: what concretely changes

Watch

What is moving on this topic

An automatic selection of recent articles from trusted sources, filtered to keep only what touches this specialty.

Loading the watch…

The CT Conseil briefing

Get this watch every week

One edition a week: the deadlines you must not miss, what is moving on Entra, Purview, Defender and compliance, and one practical tip. No advertising, one-click unsubscribe. Editions are written in French.

Gauge my level in 5 questions

Five questions to locate your compliance maturity. No judgement, only leads.

Two minutes, no tricks. You leave with a level and concrete leads.

Question 1 of 5

When an auditor asks for evidence…

How I work, concretely.

Six steps, named deliverables, a roadmap that holds.

Method