What InquilionGRC does
InquilionGRC assesses how Microsoft 365 is configured and translates the findings into governance language that any director can read, challenge and act on. Every engagement produces three deliverables from a single read-only assessment:
Board Governance Report. The primary deliverable. RAG-rated across sixteen governance domains, written for the boardroom, with challenge questions and prioritised actions.
Risk Report. Translates findings into risk register language for the CFO, COO or risk committee.
Compliance Report. Identifies what needs addressing, in which domain and at what priority, with enough technical context for the IT function or the MSP to scope remediation under board direction.
The output is not a technical audit. It is independent evidence that the board is governing configuration risk. InquilionGRC does not deliver, configure, manage or remediate anything. Independence from delivery is structural and absolute.
Sixteen governance domains
Fourteen Microsoft 365 domains, plus two Azure domains where they are in scope. Where a domain cannot be assessed at the client's licence tier, it is reported as outside assessment scope rather than passed.
Identity and Access Management
Data Protection
Device Management
Email Security
Information Governance
Insider Risk Management
Audit and Compliance Monitoring
Application and Data Sharing
Data Residency and Sovereignty
Power Platform Governance
External Connectivity Governance
Power BI Governance
Teams Security and Voice
Copilot Readiness and Governance
Azure Configuration and Blob Storage
Defender Estate
Who it serves
For boards, investors and technology professionals
Boards and organisations
Standing assurance that begins with a baseline and builds a governance record over time. The board sees whether its Microsoft 365 posture is improving, stable or deteriorating.
PE houses and portfolio businesses
Technical due diligence for PE houses, family offices and holding companies. One target, one assessment, one cost. Findings framed for investment committee review.
Managed service providers
The MSP keeps the client relationship, signs the partner agreement and invoices its own client at its own price. InquilionGRC provides the evidence layer above it and does not rebrand, so the assurance stays independent of the party that delivers remediation.
NHS Data Security and Protection Toolkit
DSPT independent assessment
For the 2025/26 cycle the DSPT assesses the larger and higher-risk NHS organisation categories against the National Cyber Security Centre's Cyber Assessment Framework. It is outcomes-based and evidence-heavy, and for most organisations a large share of that evidence is Microsoft 365 configuration: identity, access, data protection, audit and information governance.
InquilionGRC applies the same read-only assessment to the Microsoft 365 and Azure estate behind a DSPT assertion, organised across the five CAF objectives, so the board publishes evidence rather than a self-attested claim. Anything outside that estate is reported as outside assessment scope, never passed.
NHS England's Strengthening Assurance programme formally recognises DSPT independent assessment providers and expects independent assessment for higher-risk organisation categories. InquilionGRC is not on NHS procurement frameworks; engagements are delivered with an accredited delivery partner, typically the organisation's existing MSP.
Who it is for
NHS organisations. Trusts, ICBs and CSUs assessed against the CAF-aligned toolkit.
MSP partners. Providers with NHS clients who want to add an independent assurance line without delivering it themselves.
NHS suppliers. Organisations that supply the NHS through a procurement framework and are assessed the way the NHS assesses.
Visit inquilion.com
Full details on the methodology, the engagement models, the return on investment, deliverable previews and everything boards and investors need to understand how InquilionGRC works. The referral scheme is there too, for anyone making an introduction.
Go to inquilion.com