Governance evidence,
not technical noise.

Every InquilionGRC engagement is evidenced through a Board Governance Report: RAG-rated across sixteen governance domains, written in governance language, designed to be read and challenged by any director with no technical background. Two supporting deliverables help the board address the findings: a Risk Report to hand to the risk function and a Compliance Report to hand to management or the MSP. All three reports are delivered to the board. One assessment. One evidence base.

The extracts on this page use fictional findings for a fictional organisation.
No real client data is shown.

Independent assurance for the board. Practical deliverables for everyone who needs to respond.

Primary deliverable · Governance

Board Governance Report

For: Board directors, NEDs, trustees, audit committee members

The assurance itself. Translates Microsoft 365 configuration into governance language across sixteen governance domains. RAG-rated with configuration and benchmark scores, priority findings ordered by severity and timeframe, and board challenge questions. This is the report that goes into the board pack. It is the independent evidence that the board is governing configuration risk.

Supporting deliverable · Risk

Risk Report

For the board to share with: CFOs, COOs, risk committees, compliance officers

The company risk register derived from the assessment. Each open finding is recorded as a risk entry with its exposure, a control objective as the treatment, a severity rating and an owner with a target timeframe. Likelihood and impact scoring against the company risk matrix is left to the risk owner.

Supporting deliverable · Compliance

Compliance Report

For the board to share with: CTOs, IT directors, heads of IT, compliance officers, managed service providers

Helps disparate business units or third-party suppliers, e.g. MSPs, act on the findings under board direction. Findings are organised by the function responsible for acting on them, each with its status, severity, timeframe and the standards in scope. The Technical Schedule holds the complete control-by-control evidence base, including passing controls. InquilionGRC does not direct how to remediate.

All three deliverables are provided to the board. The board decides who else receives them and when. InquilionGRC's relationship is with the board, not with management or operational teams. That separation is what makes the assurance independent.

For PE houses, the same deliverables are framed for the investment context.

What the boardroom sees.

Report extract · Executive summary

Overall Governance Position: Amber

Configuration Score68.4%54 / 79 assessed
Benchmark Score56.3%54 / 96 total
Overall PositionAmberRemediation within agreed timeframe
54Pass
19Fail
6Warn
12Skip
5Licence-gate
0Error

Configuration score is PASS divided by PASS plus FAIL plus WARN. Benchmark score is PASS divided by all 96 controls. Licence-gated and not-assessed controls are excluded from the scores and are not failures.

The organisation's Microsoft 365 environment is partially governed. Controls exist in some domains but are inconsistently applied and not evidenced at board level. Four of the fourteen assessed domains require immediate board attention. Three meet the expected governance baseline. Seven show partial governance with specific gaps identified. The two Azure domains were not in scope for this organisation.

This assessment was conducted using read-only access. No configuration was changed. The findings reflect the state of the environment at the time of assessment and are framed for board oversight, not operational remediation.

The executive summary gives the board an immediate governance position without requiring technical interpretation. The RAG rating is supported by the domain detail that follows.

Report extract · Domain overview

Sixteen domains. One governance position.

01
Identity and Access Management
Amber
02
Data Protection
Red
03
Device Management
Amber
04
Email Security
Green
05
Information Governance
Amber
06
Insider Risk Management
Amber
07
Audit and Compliance Monitoring
Red
08
Application and Data Sharing
Red
09
Data Residency and Sovereignty
Green
10
Power Platform Governance
Amber
11
External Connectivity Governance
Red
12
Power BI Governance
Green
13
Teams Security and Voice
Amber
14
Copilot Readiness and Governance
Amber
15
Azure Configuration and Blob Storage
Out of scope
16
Defender Estate
Out of scope

Each domain is rated Red, Amber or Green from its findings. A domain may carry a Red position at a high configuration score where a single finding creates material exposure. The board can see at a glance where governance is strong, where gaps exist and where immediate attention is needed. Out-of-scope domains are stated, never silently omitted. Trend indicators are included in standing assurance engagements to show movement over time.

Report extract · Domain detail

Domain 01: Identity and Access Management Amber

Authentication controls are partially configured. Conditional access policies exist but do not consistently enforce multi-factor authentication across all access scenarios. Privileged accounts do not operate under a dedicated access tier. Third-party application permissions have been granted through OAuth consent but have not been formally reviewed or approved through a governance process.

The organisation cannot currently evidence to the board that access to its Microsoft 365 environment is governed to a standard consistent with its risk appetite or regulatory obligations.

Board challenge questions:

The governance narrative tells the board what the position is. The board challenge questions tell the board what to ask management. InquilionGRC provides the evidence. The board provides the accountability.

Report extract · Prioritised actions

What the board should ask for next.

Priority 1 (Immediate: within five working days)
The board should seek assurance from management that authentication controls are applied consistently across all access scenarios. A defined timeline for remediation should be requested, with evidence of completion reported back to the board or audit committee.
Priority 2 (Within 30 days)
Management should conduct a formal review of all third-party applications with access to organisational data and present the findings to the board. Any application consent that cannot be attributed to a business requirement should be revoked.
Priority 3 (Within 60 days)
The board should request that management implement a rolling review cycle for application permissions, external sharing configurations and guest access, evidenced and reported as part of standing governance oversight.

Actions are framed for the board, not for IT. The Compliance Report provides the operational detail required to execute remediation. InquilionGRC does not tell management how to configure. It tells the board what to ask management to evidence. Independence from delivery is absolute.

Report extract · Regulatory alignment

Every finding mapped to the frameworks that matter.

UK GDPREU GDPRUK NIS Regulations 2018NIS2 (benchmark)NIST CSF 2.0Cyber Essentials

The baseline frameworks above are cited in every assessment. Beyond them, findings are mapped from a maintained reference library of more than 160 primary sources across nearly forty regulators, statutes and frameworks: UK and EU data protection, financial services regulation, cyber baselines, corporate governance codes and the US and offshore regimes that apply where an organisation operates. Mapping is scoped to each organisation's sector and jurisdictions: a charity is not assessed against banking rules, and a fund administrator in Jersey sees its own regulator reflected. Regulatory mappings indicate areas of relevance and potential exposure. They do not constitute legal advice or a determination of compliance. InquilionGRC does not provide legal advice or certification. It provides the governance evidence that supports compliance conversations.

The library is maintained as regulation evolves. The engagement letter records the frameworks in scope for each client.

What the risk register receives.

The Risk Report is the company risk register derived from the assessment. Each open finding is recorded as a risk entry, ordered by severity. The extract below shows a single entry.

Risk report extract

Risk entry: Multi-factor authentication is not enforced for all users

Risk reference
RR-Q1-01 · Check D1-001
Risk and exposure
No active Conditional Access policy enforces multi-factor authentication for all users. Policies exist but none are scoped to all users with an MFA grant control in an enabled state. User accounts can be accessed with a password alone.
Control objective (treatment)
MFA enforced for all users via Conditional Access.
Rating
Critical
Owner and target
IT · 30 days

The control objective is the treatment to be achieved; the operational actions and the order of work are set out in the Compliance Report. Likelihood and impact scoring against the company risk matrix is for the risk owner to complete. Every open finding in the Board Governance Report has a corresponding entry. The risk function can act on the assurance immediately.

What management acts on.

The Compliance Report sets out the findings organised by the function responsible for acting on them. The extract below shows the same finding as it reaches the IT function.

Compliance report extract

Section 1 · Information Technology

Ref and status
D1-001 · FAIL
Severity and timeframe
Critical · 30 days
Control objective
MFA enforced for all users via Conditional Access.
Finding
No active Conditional Access policy enforces MFA for all users. Policies exist but none are scoped to all users with an MFA grant control in an enabled state. Users can authenticate with a password alone.
Standards in scope
NIST CSF 2.0 PR.AA-01; GDPR Art.32; NIS2 Art.21(2)(i); Cyber Essentials

InquilionGRC identifies what. Management decides how. That boundary is maintained in every deliverable. Findings are grouped by the function that owns them: Information Technology, then Compliance and Risk, then Commercial and Leadership. The complete control-by-control record, including passing controls, is held in the Technical Schedule at the end of the report: the evidence base, reproduced exactly as assessed. Where an organisation works with an MSP, the Compliance Report is self-contained and can be shared directly to inform remediation.

Read the complete example pack.

The extracts on this page are taken from a full example pack: all three reports, prepared end to end for a fictional organisation. The pack shows exactly what your board receives, at full length, in the language it arrives in. Request it and we will send all three.

REQUEST THE EXAMPLE REPORTS

Designed for your governance cycle.

Every report is self-contained. A new NED, trustee, insurer or auditor can pick it up and understand the organisation's Microsoft 365 governance posture from first principles. The executive summary provides the overall position. The domain overview shows where strengths and gaps sit. Material findings are framed as board actions with defined priorities and timelines, and a cumulative findings tracker shows remediation progress across assessment periods. The board sees whether governance posture is improving, stable or deteriorating.

For audit committees, the report provides the evidence layer that supports independent challenge. For insurers, it evidences the controls in place at the time of assessment. For regulators, it demonstrates active oversight rather than assumed compliance. For investment committees, it supports portfolio-level comparison, post-acquisition remediation tracking and governance evidence for co-investors or limited partners.

Framed for the investment lifecycle.

Microsoft 365 configuration is a slice of technical due diligence that is often missed. For PE houses, the same three deliverables are produced from a single assessment but framed for the investment context. How InquilionGRC works with investors covers the lifecycle, the commissioning mechanics and how the findings read for an investment committee.

Five questions every board should ask.

Any director can ask these questions without technical knowledge. The answers reveal whether governance is operating or being assumed.

1

Is our Microsoft 365 environment independently assured, or are we relying on the people who run it to tell us it is fine?

2

If something went wrong today, could we evidence what controls were in place and that we were actively overseeing them?

3

Do we know whether our configuration is getting better or worse over time, or do we only find out when something breaks?

4

Could a single compromised password give someone access to our email, documents, client data and financial systems, and do we know whether the controls preventing that are actually working?

5

When did we last ask management to show us evidence, not reassurance but evidence, that our digital controls are operating as we expect?

If your board cannot confidently answer these questions, the governance gap is already present. InquilionGRC exists to close it.

Report format, domain coverage and regulatory framework mapping evolve with the platform and the regulatory landscape. The extracts on this page use fictional findings for a fictional organisation. The reports delivered to your board reflect the most current methodology at the time of engagement.

Start with a Board Review.

A single, independent assessment across sixteen governance domains. No disruption. No jargon. Evidence where previously there was assumption.

REQUEST INFO