Governance that holds up when someone asks a hard question.
We design and audit risk frameworks for boards and audit committees who'd rather find the gap themselves than have a regulator find it for them.
Governance & compliance, engineered to survive scrutiny
Five focused engagements, each built for boards that need evidence, not assurance theatre.
King IV governance gap review
A structured assessment of your current governance framework against King IV principles, with a prioritised remediation plan the board can actually action.
Risk committee design
We help boards establish or restructure risk committees with clear mandates, reporting lines and escalation triggers.
FICA and AML compliance advisory
Policy design, staff training and periodic testing to keep your compliance programme audit-ready, not just filed away.
POPIA and data governance review
A practical assessment of data handling practices against POPIA requirements, focused on real operational risk over box-ticking.
Independent audit committee support
We sit as independent advisors to audit committees needing a voice free of management influence on specific decisions.
Registrations & standing
What underwrites the advice — not marketing, paperwork.
Our governance reviews are structured directly against King IV's outcomes-based principles.
Registered as an accountable institution under the Financial Intelligence Centre Act.
Nireston Heritage Capital (Pty) Ltd, registered with the Companies and Intellectual Property Commission.
The usual way, and the way we do it
Three points where the difference actually shows up in a board pack.
- Reporting — Named findings, board-ready, with recommendations
- Independence — No product sales, no audit-firm cross-referrals
- Continuity — Same senior team across the review and remediation phase
- Reporting — Generic scorecards with colour-coded risk ratings
- Independence — Advisory bundled with audit or insurance sales
- Continuity — Junior staff rotate mid-engagement
Frequently asked questions
What boards and audit committees typically want clarified before engaging.
No — we work alongside them, focused specifically on governance and risk framework design, not financial statement audit.
We recommend every two years, or immediately following a material incident, acquisition, or new board appointment.
Yes — most engagements conclude with a formal presentation to the audit or risk committee.
Yes, though the framework is scaled — a private manufacturer doesn't need the same reporting cadence as a listed entity.
Have your framework tested before the regulator does.
A confidential gap review can begin within two weeks.