Services
Each engagement is shaped to the work it serves. Below is what we do most. If your situation sits outside these practices, we still want to hear about it.
Certifications
- PMP·Project Management Professional
- PRINCE2·Projects in Controlled Environments
- Security+·CompTIA
- AZ-900·Microsoft Azure Fundamentals
- SC-300·Microsoft Identity & Access Administrator, in progress
- AIGP·AI Governance Professional, in progress
Core practice
Programme & Project Management
PMP · PRINCE2
From inception to delivery, we consult, execute and implement complex projects and programmes, operational or technological, with discipline and transparency at every stage. Every engagement starts with an honest read of where you actually are, scope, dependencies, capability, and risk, and ends with a delivery plan your teams can pragmatically run.
We specialise in both business and people management and have extensive experience building the governance frameworks, delivery cadences, and stakeholder alignment that turn ambitious roadmaps into working systems. That includes standing up PMO structures, establishing cadence where team outcomes and alignment have drifted, coaching teams through change, and giving executives reporting they can make decisions on.
We also engineer go-to-market (GTM): launch planning, marketplace readiness, and the operational rollout that carries a product from built to sold. PMP and PRINCE2 certified. Structured for enterprise procurement. Built to ship.
Where this applies
- Programme and project delivery from inception to operational handover
- Governance frameworks, delivery cadence, and PMO structures
- Go-to-market (GTM) engineering: launch planning, marketplace readiness, and operational rollout
- Stakeholder alignment and executive reporting
- Team building, development, and delivery culture
- Vendor and partner coordination across workstreams
- Recovery of delivery discipline in running programmes
Specialisation
Cybersecurity & IAM Delivery
Security+ · Microsoft Entra · Verified ID
Security is every organisation's most crucial long-term roadmap, and it is often treated as an afterthought. We specialise in planning and delivering cybersecurity initiatives across governance, compliance, and technical implementation. We train teams on and implement Zero Trust baselines, Microsoft Entra Conditional Access with verifiable credential integration, phishing-resistant authentication with passkeys (FIDO2), and incident response coordination.
We specialise in identity and access management (IAM), architecting and delivering across the Microsoft Entra ecosystem: Microsoft Entra ID, Microsoft Entra External ID, and Microsoft Entra Verified ID. We partner with Microsoft personnel and experts to carry tenant architecture and CIAM design through phased rollout and operational handover. We also lead identity provider (IdP) migrations onto Microsoft Entra ID, with SAP, Okta, Ping Identity, and AD FS estates among current and recent work. Whether you are modernising workforce awareness and authentication or building internal and external identity flows, we bring hands-on delivery experience from inside the Microsoft ecosystem.
For IAM delivery we partner with WhoIAM (whoiam.ai), a Microsoft integration partner founded by former Microsoft identity engineering leaders with over seven decades of combined experience. Grice & Company's founder programme-led the delivery of TrueCredential onto the Microsoft Security Store end-to-end. TrueCredential is WhoIAM's identity verification and verifiable credential product, built on Microsoft Entra Verified ID with identity proofing in partnership with LexisNexis Risk Solutions.
Where this applies
- Security programme governance, compliance, and incident response coordination
- Zero Trust and Microsoft Entra Conditional Access baselines
- Passwordless and phishing-resistant authentication: passkeys (FIDO2), Windows Hello for Business
- IdP migration to Microsoft Entra ID from SAP, Okta, Ping Identity, and AD FS
- Azure AD B2C to Microsoft Entra External ID migration and CIAM architecture
- Microsoft Entra Verified ID deployment with integrated identity proofing
- Microsoft marketplace and Security Store listings, from onboarding to co-sell ready
- Microsoft partner compliance: MISA requirements and SSPA audit completion
- Governance authorship: employee handbooks, AI governance, and data protection policies
Specialisation
AI Governance & Delivery
EU AI Act · NIST AI RMF · ISO/IEC 42001
Most organisations deployed AI before they governed it, and the regulators have noticed. The EU AI Act's transparency and high-risk obligations carry fines that run to millions, and meeting them takes governance that actually operates. ISO/IEC 42001 is becoming the standard buyers ask suppliers to evidence, and most organisations hold policy documentation with no realised operating mechanisms behind it.
Grice & Company builds those mechanisms for you: AI system inventory and classification against the Act's risk tiers. Risk and impact assessment. Acceptable use policy written in a way that is legible and implementable for everyone in your organisation. Third-party AI terms, vendor review, and the contractual provisions that govern what a supplier may do with your data. Human oversight design. Incident handling and post-deployment monitoring.
This is governance run as a delivery programme rather than issued as a written opinion. We offer the same unified and informed discipline we bring to identity and cybersecurity, applied to the systems making decisions inside your organisation.
If you have not yet implemented or deployed AI systems in your organisation, we suggest starting with our consultancy. We will set out your regulatory obligations as we develop the plan that carries your implementation to its desired outcome. All engagements include training and knowledge transfer for the people who operate the systems and the people affected by them.
Where this applies
- AI system inventory and classification against EU AI Act risk tiers
- AI risk and impact assessments
- Acceptable use policy design and rollout
- Third-party AI terms, vendor review, and contractual data provisions
- Human oversight design
- Incident handling and post-deployment monitoring
- EU AI Act readiness and ISO/IEC 42001 alignment
Engagement
Crisis & Special Situations
Hands-on under pressure
Some problems do not wait for a roadmap. When a programme is failing, a team is fracturing, a deadline is collapsing, or an organisation faces a moment that fits no playbook, you need someone who can walk in, assess clearly, stabilise quickly, and lead the way end-to-end.
We provide hands-on crisis management, change leadership, and steady command for organisations navigating high-stakes, time-critical, or ambiguous circumstances.
Whether it is a stalled transformation, an operational breakdown, a leadership gap, a security incident, or a complex problem no one has been able to untangle, we bring calm, structure, and decisive forward motion. Engagements begin with a rapid, thorough situation assessment completed within days, followed by a stabilisation plan with named owners, honest dates, and an established reporting rhythm. We work with the people you have, protect the relationships that matter, and leave the structures and solutions behind when we go.
We embed alongside you. We assess. We act. We own the outcome with you.
Where this applies
- Situations that need discretion, clear judgement, and steady hands
- Complex, cross-functional problems that need a single accountable owner
- Programmes and projects in distress or off-track
- Operational crises that need rapid stabilisation
- Organisational change and transition under pressure
- Security and cyber incident response coordination
- Interim leadership during gaps or transitions
First stop
Consultancy
Where engagements begin
Every engagement we commit to begins the same way: with conversation, collective immersion, and thinking. Consultancy is that thinking and immersion offered as a service. You bring a problem, a plan, an ambition, or a situation still taking shape, and we apply structured analysis and hard-won delivery experience to it until it makes sense.
Our roadmaps are deliberately tailored, effective, and direct. We listen first. We ask the questions that surface what is actually going on. We analyse the moving parts, the constraints, the risks, and the options. Then we give you our honest read, in writing, with a recommended path and the reasoning behind it. If a roadmap is needed, we build one you can run, with us or without us.
There is no minimum size and no obligation beyond the conversation. Some clients take the roadmap and execute themselves. Others step from consultancy into formal delivery with our practices, under a statement of work (SoW), a programme charter, or PRINCE2 Project Initiation Documentation (PID), whichever governance artefact your organisation runs on.
Consultancy is the first stop: a place to borrow our minds before you commit your resources.
Where this applies
- Structured analysis of problems, plans, and opportunities
- Platform and vendor evaluations
- Programme scoping, roadmap definition, and business cases
- Independent review of plans, estimates, and delivery risk
- Compliance milestone preparation
- Framing ambiguous situations into decisions
- Roadmaps you can execute with us or without us
- Subject-matter expert (SME) briefings drawn from our network and beyond
- A defined route into our delivery practices when execution is the goal
Anything else
If it needs a plan, we will build one.
The practices above are where we are most often hired. The door stays open beyond them. We have helped clients plan international moves, plan business ideas, build and fund new companies, develop learning plans, and untangle small operations. Every plan deserves discipline. Every problem deserves attention.
