Kimberg Institute of Governance, Risk and Compliance

Turning Risk Insight into Governance Capability.

Organizations should understand their exposure before they invest in controls, frameworks, or technology. We diagnose where you actually stand, show you what matters most, and help you build the capability to prove it.

8Assessment Domains
5Industry Scenarios
CISA · CRISC · CFSACertifications

Kimberg Capability Scale

Where most
orgs sit
Where governance
should be
0 Absent1 Ad Hoc2 Defined3 Managed4 Assured5 Adaptive
A mature-sounding process can still carry high residual risk. We score capability and risk separately — on purpose.
GOV-01CYB-04DAT-08TPR-02ASN-05

The Problem

Most organizations start in the wrong place.

The common instinct is to ask, “Which framework should we implement?” That question skips the one that actually matters: what requirements, risks, and expectations apply to this organization, right now — and what would it take to prove your controls actually work?

Capability, risk exposure, and evidence quality are three different things. An organization can have mature processes and still carry significant residual risk.

How We Work

A repeatable path from diagnosis to durable capability.

Every engagement moves through the same six stages — a client value ladder, not a menu of disconnected services.

01

Diagnose

Understand where you actually stand.

02

Prioritize

Identify what matters most, and why.

03

Remediate

Fix the gaps in a staged, owned roadmap.

04

Implement

Build the governance capability itself.

05

Validate

Prove the capability actually operates.

06

Monitor

Sustain it with continuous assurance.


Who We Serve

Built for organizations without a mature internal GRC function.

SaaS & Technology

Enterprise deals blocked by a security questionnaire or SOC 2 requirement.

Healthcare & Health-Tech

PHI exposure, legacy systems, and HIPAA risk analysis gaps.

Retail & E-Commerce

PCI scope drift and seasonal policy bypass under peak load.

Professional Services

Client confidentiality commitments outpacing internal controls.

Financial Services

OSFI B-13 and PCMLTFA obligations across a growing institution.

Not sure where you fit?

The GRC Health Check scopes to your organization’s real profile — not a generic checklist.

Start Your GRC Health Check

The Kimberg Ecosystem

One body of knowledge, applied through several disciplines.

The Institute is the foundation. Each discipline below draws on the same underlying methodology — applied to a different mode of work.

Kimberg GRC Advisory

Assessments, remediation, and continuous assurance engagements.

Kimberg GRC Academy

Training and coaching for teams, executives, and boards.

Kimberg Research

Benchmark reports and regulatory intelligence.

Kimberg Frameworks

Toolkits and templates built from real engagement methodology.

Kimberg AI Governance

Readiness and governance for organizations adopting AI.

Kimberg Publications

The book series underlying the Institute’s methodology.

Know where you stand before you invest another dollar in controls.