Governance, Risk & Compliance
Compliance work fails in one of two ways: a binder of policies nobody follows, or a scramble three weeks before the auditor arrives. Astra builds management systems that survive contact with the business — assessed against the standard you are held to, documented so an auditor can follow it, and operated by your own people once we hand over.
- Information security
- ISO 27001
- Quality management
- ISO 9001
- Cyber security framework
- RBI
- Housing finance directions
- NHB
What you get
Outcomes, not activity.
- Certification without theatreISO 27001, 9001, 14001 and 45001 implementations that start from how your organisation actually works, then close the distance to the standard.
- Regulator-readyInformation system audits and gap assessments aligned to the RBI cyber security framework and NHB directions for banks, NBFCs and housing finance companies.
- A risk register that gets usedAsset identification, threat and vulnerability assessment, and a treatment plan with owners and dates — reviewed on a cycle rather than written once.
- Documentation that holds upPolicies, procedures, registers and records prepared to the evidence standard your certification body or regulator expects.
- Your team can run itAwareness training and internal audit capability are part of the engagement, so the management system does not depend on us being in the room.
How it runs
A defined sequence, agreed up front.
You know what happens in each stage, who is involved, and what lands at the end of it before the engagement starts.
- 01
Gap analysis
We map what exists against every clause and control of the applicable standard or circular, and rate each gap by risk and effort.
- 02
Scope and design
Boundaries, roles and the management system framework are agreed, including the risk assessment methodology and the templates your team will maintain.
- 03
Risk assessment and treatment
Critical information assets are identified and assessed against realistic threat scenarios; the treatment plan sets out controls, owners and timelines.
- 04
Implement and train
Controls, policies and procedures are rolled out with awareness sessions for the people expected to follow them, and a single point of contact in each in-scope function.
- 05
Internal audit and certification
We run the internal audit, help close findings, prepare the management review, and support you through the external certification audit.
Deliverables
What lands on your desk.
Written for two audiences: the engineers who have to fix it and the executives who have to fund it.
- Clause-by-clause gap assessment with a prioritised remediation plan
- Statement of applicability, risk register and risk treatment plan
- Full policy and procedure set, mapped to the standard
- Internal audit report and management review pack
- Awareness training for staff and control owners
- Support through the external certification or regulatory audit
Related
Often engaged alongside
Next step
Scope a grc & compliance engagement.
Half an hour with a practitioner. You will leave knowing what the work involves, roughly how long it takes, and what it would find.

