IT compliance and risk management from EPX IT includes identifying IT related risks, supporting the regulatory requirements that apply to your industry, improving controls and visibility, and ongoing review. The output is practical assurance that obligations are being met, with the evidence available to demonstrate it.
IT Compliance and Risk Management
What a customer contract, an insurer’s schedule or a regulator’s guidance asks of your IT is rarely spelled out, so most businesses assume they meet it. A named Partner Consultant works through what you are held to.
Compliance problems that surface when somebody asks
Nothing appears to be wrong, because nothing has been tested, and then a request arrives with a deadline on it. What EPX IT finds when it reviews where a business stands usually falls into four groups:
- An obligation was read once, at the point it was signed, and nobody has checked since whether the business still meets it
- Policies describe controls and nobody can confirm those are the controls running today
- A customer or a professional body asks for evidence, and the answer has to be assembled from scratch under time pressure
- An insurer’s schedule sets conditions that have never been read against the business’s own IT, which becomes a problem at the point of a claim
Compliance reviews are included in your service desk agreement
EPX IT does not sell IT compliance as a separate engagement. Working through where a business stands, and auditing the documentation it already holds, is part of the service desk agreement. Work that comes out of a review is quoted separately, so what a gap costs to close is a decision taken with the figures in front of you.
That is deliberate. Compliance questions arrive with a deadline attached, and a business that has to agree a fee before anyone will look will put it off until it has no choice.
EPX IT has supported UK businesses for over 20 years, currently manages 2,500 computers for 38 fully managed partners across Staffordshire and the West Midlands, and holds Cyber Essentials Plus certification itself.

What your Partner Consultant works through with you
Compliance sits on the same business review agenda as the rest of your IT, quarterly as standard and at the rhythm you set. Your Partner Consultant with EPX IT works through your obligations one circumstance at a time:
- Which obligations actually apply, across customer contracts, your professional body, your insurer and data protection law
- What each one asks of your IT specifically, separated from what it asks of the rest of the business
- Whether the controls your own policies describe are the controls in place today
- Where the gaps are, what closing each one involves and what it would cost
- What you would be able to show if somebody asked you tomorrow
Gaps are presented by your Partner Consultant, with an escalations engineer alongside them where the work is technically complex, so what needs doing and how difficult it will be get covered in the same conversation.
Certifications EPX IT will help you complete
EPX IT advises on certification and works through it with partners who need one, which covers preparing the evidence, closing what the standard requires and taking the business through the assessment:
- Cyber Essentials, the minimum standard the government recommends, and the one most supply chain requests ask to see
- Cyber Essentials Plus, where a customer or an insurer wants the independently audited tier
- ISO 27001, a full management system, usually asked for by larger customers or in regulated procurement
ISO 27001 is a bigger commitment than either Cyber Essentials tier, and a joint effort. EPX IT provides the IT controls, the technical work and the evidence; the policies, the risk decisions and the management review stay with your leadership, where the standard puts them.
The certification audit is carried out by an accredited certification body. EPX IT will tell you whether you actually need it, because for many businesses the answer is Cyber Essentials Plus.
Which one is worth holding depends on who is asking for it, and that is one of the things a review settles.
Our cyber security and threat protection service covers the Cyber Essentials controls themselves in more detail.
Proving your IT is secure to a customer, an insurer or an auditor
Being secure and being able to show it are two separate pieces of work, and the second one is the one that arrives with a deadline. The NCSC’s supply chain guidance tells organisations to require prospective suppliers to provide evidence of their approach to security, so the request is coming from your own customers’ side of the table.
Your Partner Consultant works out what a particular questionnaire or an insurer’s schedule is asking, what EPX IT can answer directly from how your systems are built and what needs a decision from you first.
Where accountability for IT risk actually sits
Accountability sits with leadership, and it stays there when the technology is managed by somebody else. The NCSC is direct about it, saying cyber security risk “should therefore be integrated within your overall approach to risk management, and not be dealt with as a standalone topic”.
The government’s Cyber Governance Code of Practice, published with the NCSC, is built the same way. Across its 22 actions the instruction to a board is usually to gain assurance, so a director is expected to hold evidence that the work is happening rather than to carry it out.
AI use is now a compliance question
How staff use AI tools is a risk the board owns, and EPX IT handles it separately because it needs its own policy and its own monitoring. EPX AI Essentials puts the policy, the data rules and the switch-on decision in place, and AI Assured watches for unapproved AI use month to month and reports what it finds.
Where EPX IT stops, and what stays with you
EPX IT does not give legal advice. Where an obligation turns on how a contract or a regulation should be interpreted, that goes to your solicitor and EPX IT works to the answer they give. Insurance claim investigations stay with the insurer’s investigators, with EPX IT supplying what they ask for and supporting the investigation rather than carrying it out.
Is this right for your business?
IT compliance and risk management from EPX IT is a good fit if:
- Compliance expectations from customers, regulators, insurers or partners are rising and it is unclear whether your IT would stand up to scrutiny
- A security questionnaire or a supplier assurance request has arrived and answering it meant starting from nothing
- Leadership is accountable for IT risk with limited visibility of where the exposure sits or how it is being managed
- A certification is being asked of you and which one you actually need has not been settled

What an unanswered compliance question costs
The cost arrives late, and usually as lost ground. A tender goes elsewhere, a customer’s audit holds up a contract, an insurer prices the uncertainty into the premium or declines to quote, or a claim gets questioned because a condition nobody read was never met.
Reviewed regularly the position is known instead. EPX IT can tell you which obligations apply, where you meet them, where you do not and what closing the difference would cost, so a request with a deadline on it becomes a form to fill in.
Frequently asked questions
What does IT compliance and risk management include?
Is IT compliance work included or is it charged separately?
How do we answer a security questionnaire from a customer?
How do we prove our IT is secure to our insurer?
Do we need ISO 27001, or is Cyber Essentials enough?
Who is responsible for IT risk in a business?
Is this just paperwork?
Does how our staff use AI fall under our compliance obligations?
Talk to EPX IT
If you have been asked to prove something about your IT and the answer took some finding, a conversation with our team is the next step.
Our IT strategy and consultancy service covers the wider business review that a compliance review sits inside.