01Standards
Policy-driven oversight
Your MSP works to the standards you set, not just the bare minimum in a framework. DDQs, board-approved standards, and client commitments stay visible in day-to-day delivery.
Fig is a governance-led security and resilience platform for corporate risk teams. Continuous monitoring, supplier oversight, evidence trails, and board-ready reporting on one operating model - so the controls you commit to in policy are the controls that actually run.
Your MSP can manage Fig day to day while you keep an independent view of risk, resilience, and assurance work.
01Standards
Your MSP works to the standards you set, not just the bare minimum in a framework. DDQs, board-approved standards, and client commitments stay visible in day-to-day delivery.
02Resolution
When a vendor's patching or MFA posture drifts, Fig does more than highlight it on a dashboard. It records the issue, assigns ownership, applies the right deadline, and tracks it through to closure.
03Operating model
Fig works through the MSP that already manages your infrastructure. They can run the platform day to day while you keep an independent view of the resilience work they are delivering.

01Operational
Keep your internal team and your MSP working from the same view, with risks, issues, and follow-up tracked centrally.
02Decision-making
Move from "tell us about your controls" to "here is what we see in your environment." Make informed decisions with real data.
03Assurance
Maintain audit trails and compliance reports. When regulators ask "how do you monitor your MSP?" you have a documented answer.
Fig enforces your actual compliance commitments - your DDQs, your board-approved standards, your client-facing obligations - not just the minimum framework bar.
EU critical infrastructure resilience
Digital Operational Resilience Act
Information security management
Service organisation controls
Cyber Security and Resilience
Data protection and privacy
Your supply chain is only as secure as your weakest vendor. Fig gives you a single dashboard of all your critical third parties' compliance status. For corporates in the UK MOD supply chain, Fig also delivers Defence Cyber Certification (DCC L0/L1) alongside Cyber Essentials.

Continuous monitoring of MSP security posture, not an annual snapshot.
Evidence and attestations flow from every vendor into one live view.
Third-party controls scored by coverage, responsiveness, and breach history.
Complete documented history of every third-party risk review and remediation.
Always-on signals replace stale annual questionnaires and point-in-time attestations.
Your MSP deploys Fig across your environment in two business days.
Your MSP selects the frameworks and configures your internal policies and governance requirements.
Fig connects to your vendor and internal tooling via 300+ integrations. No migration, no disruption.
Within 48 hours you see your full compliance and risk posture. Your MSP manages it. You oversee it.
Use the same evidence gathered for oversight and resilience work to support renewals and insurer discussions.
01Reporting
AI-powered executive narratives generated from live compliance and risk data. Board packs assembled from real evidence, not quarterly spreadsheet exercises.
02Privacy
ROPA, DPIA, DSAR management, consent lifecycle, and breach notification with GDPR 72-hour deadline tracking. Connected to your compliance engine, not a separate tool.
03Change
7-state change workflow with AI risk scoring, policy compliance gates, and DPIA integration. Every change checked against your governance requirements before deployment.
01Portability
Your compliance data, evidence, and audit trails belong to you. Export everything in standard formats at any time. No exit fees.
02Coexistence
Fig feeds data into your existing GRC platform. It does not replace it or compete with it. Your investment in Archer, ServiceNow, or OneTrust is protected.
03Pricing
The price agreed is the price you pay. No mid-contract increases. No hidden charges for additional frameworks or users. No consultant fees.
Everything you need to know before you speak to the team.
Insurance doesn't cover negligence or lack of due diligence on your part. If a breach happens and you can't show you monitored your MSP's compliance, you share the liability. Fig lets you document that oversight.
Fig can still assess your MSP's compliance through our questionnaire module and document your review process. We also encourage MSPs to use Fig so you get direct, real-time visibility instead of annual questionnaires.
Yes. Fig integrates with most enterprise GRC tools. We can feed compliance data into your existing systems and act as a specialised overlay for MSP/third-party monitoring.
Fig gives you the evidence to have data-driven conversations. You can identify gaps, set remediation timelines, and track progress. We provide the documentation for your contracts and legal requirements.
We support NIS2, DORA, ISO 27001, SOC 2, CMMC, GDPR, and custom frameworks. We can configure Fig to match your specific compliance requirements.
Underwriters want to see that you have strong third-party risk management and documented controls. When you can show continuous compliance monitoring and audit trails, insurers see lower risk, which translates to better premiums and lower deductibles.
Enterprise GRC platforms cost £30,000 to £500,000, can take 3-6 months to deploy, and require dedicated teams to operate. Fig deploys in 48 hours through your MSP, enforces your actual policies operationally, and connects your compliance evidence directly to insurance underwriting.
Fig works through your MSP. They manage the platform, handle onboarding, and run day-to-day operations. You get independent visibility into the compliance posture they are delivering.
Most organisations are live within 48 hours. Your MSP configures the frameworks and policies, connects your tooling via 300+ integrations, and you have real-time compliance visibility within two business days.
Your data belongs to you. Export everything in standard formats at any time. No exit fees. No proprietary data traps.
Both. Fig enforces your selected compliance frameworks and your internal policies - the commitments from your DDQs, your board-approved standards, and your client-facing obligations.
Get real visibility into your MSP's compliance posture and document your due diligence.
We only load non-essential analytics and advertising tags after explicit consent. You can review our cookie register in the cookie policy section and update your choice at any time via “Cookie settings” in the footer.