News & Resources

The Strategic Value of Defining Compliance Objectives in Your Organisation

In today's complex regulatory landscape, compliance is no longer just a tick-box exercise — it's a strategic enabler. One of the foundational r...

Tone at the Top: The Catalyst for Compliance Culture

In the realm of effective compliance management, few factors weigh as heavily as “Tone at the Top”. This principle — embedded in IS...

Tone in the Middle: Embedding Compliance Where It Matters Most

While "Tone at the Top" sets the vision for compliance, "Tone in the Middle" ensures it is translated into reality. Managers — from department ...

Comparative Analysis-CMS-GACP-ABMS

In today's regulatory and ethical landscape, organisations require a robust and adaptable compliance management framework to remain resilient, account...

Internal Control Effectiveness (ICE) Methodology in Risk Controls

Over the years of Risk Training, Advisory and Consulting, one specific challenge that stood out for me is that risk registers are not using a methodol...

Internal Control Effectiveness (ICE) Methodology in Practice

In the previous articles we have been unpacking various risk-based methodologies, such as the P2ST2 and the Internal Control Methodology. Based on thi...

How to Structure the Resource Analysis for a Business Impact Analysis (BIA)

One of the processes within the Business Continuity Management System (BCMS) is the development of a Business Impact Analysis (BIA). I have experience...

The importance of implementing a BCMS based on ISO 22301 in order to ensure the ...

The COVID-19 Pandemic has changed the global business environment. During the various global implementation of managing the pandemic, we were the audi...

Can ISO 31000:2018 be Internationally Certified?

ISO 31000:2018 (Risk Management - Guidelines) cannot be internationally certified by a Certification Body (CB). Here's why. ISO 31000:2018 is a guidel...

What is and how to conducts an Adequacy and effectiveness perspective rating

In the context of combined assurance, the statement emphasizes the importance of evaluating and rating controls within an organization using both inte...

The Top-Down and Bottom-Up Approaches in Enterprise Risk Management (ERM)

Over the years that I was involved in Risk Management, I have been fortunate to serve on several high-level Risk and Strategy committees, from Governm...

Common mistakes in a structured risk register

Every time my company, Crest Advisory Africa (Pty) Ltd, are appointed to review the risk process which includes the Risk Management Framework, The Ris...

Get Directions