By company size

Programme-level governance, across every unit

Unify governance across business units and vendors

Governance exists, but it exists several times over — different units, different maturity, different evidence, and a vendor estate nobody can describe in one view. The work is consolidation, not certification.


Where you are

The constraints at this stage

What tends to be true when companies come to us at this size.

Every business unit runs its own programme

Each has its own controls, its own tooling and its own audit history. Nobody can answer a board question about the whole organisation without a month of collation first.

The vendor estate is the real exposure

Hundreds of third parties, each with their own access and their own subprocessors. Assessments happen at onboarding and then effectively stop, so the register describes a company you were two years ago.

AI arrived before the governance did

Models, copilots and agents are already in production across teams, acting through identities nobody inventoried, on data nobody classified for that purpose.


How the engagement works

What actually happens

The same four beats every time, scoped to what this stage needs.

Map the whole estate

Every unit, every framework, every vendor and every AI system in one picture. Most of the value at this scale is discovering what is actually in scope.

Converge on one model

A single control set and one risk taxonomy, with per-unit variation handled as documented exceptions rather than as separate programmes.

Operate it

Assessment cycles, evidence, vendor reviews and audit management run on a defined cadence with named accountability, whether that sits with your team or ours.

Report upward

Board and regulator reporting drawn from the running programme rather than assembled for the meeting, so the number in the pack is the number in the system.


Proof

Track record

Across every engagement we have run, at every size.

0+

Companies Secured

Zero

Failed Audits

4-8

Weeks to Compliance

0+

Team Certifications


What you walk away with

The artefacts

Everything below is a thing you own at the end, not a promise about the process.

  • A consolidated view of controls, frameworks and maturity across every business unit
  • One control set and risk taxonomy, with documented per-unit exceptions
  • A tiered vendor register with assessment cadence and contractual controls
  • An AI inventory covering systems, agents and the identities they act through
  • Internal audit programme and management review records
  • Board-ready reporting drawn directly from the running programme
  • Audit and certification management across the units that need it

Related

Where to go next

The problems this stage usually arrives with, and the services behind them.


Questions

What people ask at this stage

Usually not. Most enterprise engagements sit alongside an internal team — we take the programme, assurance and audit load so your people can stay on engineering and operations. Where there is no internal function, CISO Office as a Service can run the whole thing.
One target control set, with each unit assessed against it and given its own remediation path. Variation is carried as documented exceptions with owners and review dates, rather than by letting each unit keep a separate programme.
Yes — third-party risk is usually the larger exposure at this scale. That means tiering the estate by criticality, assessing to a depth that matches the tier, putting the right controls into contracts, and monitoring continuously instead of only at onboarding.
It is governance, not a separate discipline. AI systems get inventoried, risk-assessed and controlled inside the same programme, with ISO 42001 available where a certifiable management system is wanted. The identities agents act through are governed alongside human and machine access.

One assurance picture, not twelve.

Tell us how many units and frameworks are in play. We will show you where they already overlap and what consolidation actually takes.