Govern IT Seychelles
Independent technology governance for Executives.
We are an independent technology governance advisory practice based in Seychelles. We do two things. We establish where your organisation actually stands, and then we build what is missing: the controls, processes, policies and governance structures, and the training that makes your people able to use them. Most organisations know roughly what is wrong. What they lack is the evidence to be sure, and the capacity to fix it while also running the organisation.
Start with a Preliminary Maturity Assessment, SCR 20,000 to 40,000 per domain VAT exclusive, depending on the size and scope of your organisation. It establishes your current position and gives you a ranked 90-day road map. The work of building what it recommends is scoped and quoted separately.
How we help
The questions executives bring to us
Technology is evolving rapidly, with Artificial Intelligence, rising cyber threats, more digital systems and higher governance expectations. Four of the six governance domains we assess account for most of what organisations ask us about first.
Are we innovating responsibly?
In most organisations Artificial Intelligence arrives before the rules do. Staff adopt tools that are useful, and the questions of what information goes in, who checks the output and who is accountable arrive afterwards. Our experts establish where it is already in use, on what data, under whose authority, and what must be true before it influences a decision affecting a customer or an employee.
Are we getting value from what we spend?
Technology investment is approved on a business case and then rarely measured against it. Our experts establish what is being spent, what it is delivering, how change is authorised and recorded, and where the portfolio has grown commitments the institution did not deliberately choose.
Do we know how it all fits together?
Systems accumulate faster than anyone maps them. Our experts set out how your systems, data and dependencies actually connect, where duplication and single points of failure sit, and what a realistic target state looks like, so future decisions are made against a picture rather than an assumption.
Are we investing in the right things?
Direction is either set deliberately or set by whoever is loudest: a supplier with a renewal, a department with a budget, or an incident that forces a decision. Our experts establish priorities that follow institutional objectives, and the decision rights and road map needed to hold to them.
The bigger questions
What your leadership should be able to answer
Technology sits at the centre of almost every institution. It supports operations, enables services, holds critical information, connects people and protects data. That makes these questions unavoidable.
- Are we investing in the right things?
- Are we managing the risks properly?
- Are we using our resources well?
- Are we getting value from what we spend?
- Are we innovating responsibly?
- Are we setting the right standards and processes?
- Are we improving accountability?
Without governance, technology becomes reactive.
- It only responds when something breaks.
- Projects multiply without prioritisation.
- Systems arrive without clear ownership.
- Investment decisions drift away from strategy.
- Risks stay hidden until they become incidents.
- Benefits are promised but never measured.
- Accountability blurs, and no one can say who owns the outcome.
What we assess
Six domains, scored the same way every time
Our services are modular. Take one domain, a few, or all six. Whatever the scope, the same scale is applied, which is what makes a finding defensible when somebody asks how it was reached.
IT strategy and accountability
Whether direction is set deliberately, who decides, who is responsible, and whether that is recorded anywhere a successor could follow.
Explore 02Investment and delivery
What is being spent, what it is delivering against the case made for it, and how change is approved.
Explore 03Operational resilience
Whether the institution can continue when a critical system, site or supplier becomes unavailable.
Explore 04Cybersecurity
Control coverage measured against the exposure you actually carry, not against a generic checklist.
Explore 05AI governance and literacy
Where it is used, on what information and under whose authority, and whether your people know the rules.
Explore 06Enterprise architecture
How systems and data connect, where duplication and single points of failure sit, and the target state.
ExploreThe deliverable
Evidence, not opinion
A Preliminary Maturity Assessment produces a scored profile your leadership team can read, question and act on, with a ranked plan for the next ninety days. You choose which domains it covers.
-
IT strategy and accountability Developing
-
Investment and delivery Informal
-
Operational resilience Managed
-
Cybersecurity Developing
-
AI governance Uncontrolled
-
Enterprise architecture Informal
- High exposure
- Intermediate
- Low exposure
An illustration of the governance profile. Figures are for demonstration only.
What you receive
- Governance profile with maturity ratings for the domains in scope
- One-page summary written for your leadership team
- Full assessment report, 10 to 12 pages
- Ranked exposure register, highest consequence first
- Prioritised 90-day action plan, with owners and effort estimates
- Sixty-minute findings presentation to your executive team
- Thirty-day follow-up call
Scored on a five-level scale against recognised frameworks, selected to suit the domains in scope. These commonly include COBIT 2019, ISO/IEC 38500, ISO/IEC 27001, TOGAF, NIST and DORA, and we are not limited to them. The same scale is applied every time, so a later assessment stays comparable to the first. Presentation to an oversight or audit committee is quoted separately.
Focused
Most engagements begin with one or two domains, chosen where you need support most. Nothing you do not need is included, or charged for. Where a domain sits in the band depends on the size and scope of your organisation, not on which domain you choose. SCR 20,000 to 40,000 per domain, VAT exclusive
Full six-domain
A complete picture across all six domains, for organisations that want the whole position assessed at once. Priced as six domains with a discount for taking it all at once, which is why we quote it rather than ask you to multiply. Quoted on request
That is the price of the assessment. It tells you where you stand and what to do in the next ninety days. Building what it recommends, the policies, processes, structures and training, is a separate engagement, scoped and quoted against what you need. We will always tell you if the answer is that you do not need us for it.
The work itself
Then we build it with you
An assessment that ends at a report has done half the job. Standards only work when they are built into how the institution operates every day, and that is the larger part of what we do. Five reinforcing mechanisms, each of which we will develop with you and hand over as yours.
- 01 Clear direction Assess the current maturity state, acknowledge the gaps, set the priority objectives and build the road map.
- 02 Formal processes Repeatable routines that make good governance the default, giving consistency, accountability and proper oversight.
- 03 Governing documents Policies, procedures, frameworks and guidelines. The explicit rules, formally approved, that everyone works to.
- 04 Committees and structures Leadership holds ultimate accountability for technology. A steering group reviews, guides and decides.
- 05 Continuous awareness Everyone understands their role and responsibilities, so governance becomes culture rather than paperwork.
Governance is not something on paper. It must be lived, practised and reinforced across the institution.
How this is bought
This work is scoped and quoted separately from the assessment, at a fixed fee agreed in writing before anything begins. It is priced against what you actually need, so it is not published as a figure. Take one mechanism or all five, in one domain or across several.
Keeping it separate is deliberate. It is what allows the assessment to stay independent, and it means you are never handed findings that happen to recommend more of our own work. You are free to take the road map and have anyone else build against it.
Our experts
Where our expertise comes from
Our experts have worked inside large, regulated institutions, where every technology decision has to stand up to scrutiny. We bring those same standards to organisations that need the rigour without the overhead. We sell no technology and take no commission from anyone, so nothing shapes our advice except your situation.
- CGEIT Certified in the Governance of Enterprise IT, awarded by ISACA. An independent credential in exactly this discipline.
- TOGAF The Open Group’s enterprise architecture standard, so an architecture engagement produces something you can maintain after we leave.
- CISM Certified Information Security Manager, awarded by ISACA. Security as a management and accountability question.
- AI governance Policy, use registers, risk assessment and adoption decisions, aligned to ISO/IEC 42001:2023. A specialism, not an add-on to a security offer.
- Strategic planning Translating technology questions into decisions your leadership team can take, record and stand behind.
- Regional network Experience and an active professional network across large, regulated, multi-stakeholder institutions in Africa.
Insights
Practical guidance for executives
Short, specific guidance on governing technology properly. Free to read, in full, with nothing to sign up for.
Your staff are already using Artificial Intelligence. What leadership should ask first.
The three questions that establish exposure before any policy is written.
BriefingWhat an Artificial Intelligence acceptable-use policy needs to contain
What belongs in it, what is padding, and what makes it enforceable.
BriefingThree questions to ask a technology supplier before signing
How to evaluate a proposal without becoming a technical specialist.
Next step
Take the first step
Most engagements start with a short discussion about what your institution is trying to achieve and where technology is getting in the way. From there we agree a clear scope and a fixed price before any work begins.