HLD Group
Compliance & GRC policy
Compliance programme, audits, and control ownership.
Last updated: 24 July 2026
Version 1.0 · Review cycle: 365 days · View all frameworks
1. Purpose
This policy establishes how HLD Group governs its information security and compliance programme, including the roles, structures, and processes that ensure legal, regulatory, and contractual obligations are identified and met, and that our management system is maintained and improved.
2. Scope
This policy applies to the governance of security, privacy, and compliance across HLD Group, and to the personnel and bodies responsible for oversight, policy, and assurance.
3. Governance structure
- Executive leadership and, where applicable, the board provide oversight and approve the security and compliance strategy
- The CISO owns the information security management system and reports risk and compliance status
- A security steering group coordinates priorities, exceptions, and material risks
- Policy owners maintain individual policies and standards within their domains
4. Compliance obligations management
HLD Group maintains a register of legal, regulatory, and contractual obligations relevant to its operations, mapped to the controls and policies that satisfy them. Obligations are monitored for change so that the programme adapts as law and contracts evolve.
5. Policy framework
- Policies are documented, approved, versioned, and communicated to those they apply to
- Policies are reviewed at least annually and on significant change
- Exceptions are governed consistently, with justification, compensating controls, and expiry
- Personnel acknowledge applicable policies and complete required training
6. Assurance, audit, and certification
- Internal reviews and independent audits assess control design and effectiveness
- Certifications and attestations are maintained as required by the business and customers
- Findings are tracked to closure with owners and dates
- Evidence is retained to substantiate compliance to auditors and customers
7. Continuous improvement
The management system operates on a plan-do-check-act cycle. Metrics, audit findings, incidents, and risk trends feed management review, which drives corrective action and improvement.
8. Framework alignment
- ISO/IEC 27001:2022 (information security management system), clauses 4 to 10
- SOC 2 Trust Services Criteria CC1.x (control environment) and CC2.x (communication and information)
- ISO/IEC 27014 (governance of information security)
- NIST Cybersecurity Framework (Govern function)
9. Roles, exceptions, and review
The CISO owns this policy under executive oversight. Exceptions require documented approval. This policy is reviewed at least annually.
Related frameworks
For contractual attestations or audit packs, contact [email protected].