Services and PRICING

Professional IT Risk, Control & Assurance Services

GNAW Resources provides independent IT risk, control, and assurance support to organisations seeking clarity, confidence, and practical outcomes.

Our services are designed to scale,  from focused reviews for smaller organisations to comprehensive assurance and advisory support for complex environments.

Our Pricing Approach

We believe in transparent, fair pricing aligned to the scope and complexity of the work.

Every engagement is tailored to your organisation’s size, risk profile, and regulatory requirements. The pricing below provides clear guidance while allowing flexibility for bespoke or evolving needs, though individual circumstance might demand changes in these prices.

Professional IT Risk, Control & Assurance Services

GNAW Resources provides independent IT risk, control, and assurance support to organisations seeking clarity, confidence, and practical outcomes.

Our services are designed to scale,  from focused reviews for smaller organisations to comprehensive assurance and advisory support for complex environments.

Let's Talk

Not sure which option is right for you?

We’re happy to discuss your requirements and recommend the most appropriate approach.

👉 Request a Quote
👉 Book an Introductory Call

Example Service packages

Size and complexity of orgainisation will impact worklaod and prices, prices here look at one in scope ERP.

🔹 Foundation Tier

Baseline Assurance Review

From £1,200 – £2,500

Designed for organisations seeking a clear understanding of their current IT risk and control position.

Includes:

Initial discovery and scoping call

High-level IT risk and control review

Gap analysis against recognised good practice

Summary report with prioritised recommendations

Typical delivery: 2-3 weeks
Best suited to: Start-ups, small organisations, or first-time assurance reviews


🔹 Core Tier

Operational Assurance

From £3,000 – £6,000

A more in-depth assessment supporting audit readiness, governance improvement, or control validation.

Includes:

Detailed control assessment and walkthroughs

Evidence review and documentation analysis

Alignment with relevant frameworks (e.g. SOC 2, ISO standards, internal audit criteria)

Written assurance report with clear findings

Follow up review and discussion session

Typical delivery: 4-6 weeks
Best suited to: Growing organisations, audit preparation, compliance initiatives

 

🔹 Advanced Tier

Strategic Risk & Audit Support

From £8,500+

Assurance and advisory support for complex or regulated environments.

Includes:

End-to-end risk and control assurance

Stakeholder interviews and system reviews

Third-party or supplier risk considerations (where applicable)

Executive-level reporting and insight

Time-boxed ongoing advisory support

Typical delivery: Project-based
Best suited to: Mature organisations, regulated sectors, board-level assurance needs

 

 

🔹 Day Rates & Bespoke Engagements

For short-term support, specialist input, or highly tailored work, services can also be delivered on a day-rate basis.

Consulting Day Rates

Standard consulting: £550 – £700 per day

Senior / specialist advisory: £800 – £1,200 per day

 

Minimum engagement periods may apply.



🔹 Ongoing & Retained Support

 

Continuous Assurance & Advisory

From £1,500 per month

Ideal for organisations that require ongoing access to assurance expertise without maintaining an in-house function.

Includes:

 

Monthly advisory support hours

On-call risk and control guidance

Review of documentation and control changes

Quarterly summary reporting

What Influences Pricing?

Final pricing is shaped by several factors, including:

Organisational size and complexity

Number of systems or services in scope

Regulatory and compliance requirements

Delivery timelines and urgency

Level of stakeholder engagement required

We aim to be clear and upfront about costs before work begins.

 

Transparency Notice

Pricing is indicative and non-binding. All engagements are confirmed via written agreement prior to commencement.

 

Dedicated Experts

Expertise in IT SOX compliance, ITGCs, and security controls across global enterprises, specialising in audit preparation, cloud migration governance, and IT risk management