• Skip to main navigation
  • Skip to main content
  • Global Services
    • Audit and assurance
      • Audit
      • Government, Risk, and Compliance
    • Legal and tax advice
    • Financial Advisory
      • Transactions
      • Ratings
      • Financial Modeling
      • Analytical and management accounting
      • Financial Advanced Solutions
      • Financing for companies
    • Consulting
    • Technology
    • Capital Markets
      • Debt Capital Markets
      • Equity Capital Markets
    • Public R&D&I and investment incentives
    • Restructuring and insolvency
  • About us
  • Sectors
    • Public Administration
    • Automotive and mobility
    • Consumer goods
    • Energy and natural resources
    • Hospitality, tourism and leisure
    • Industry
    • Retail and distribution
    • Health and life sciences
    • Services Sector
    • Financial Services
    • Technology, media and telecommunications
  • News
  • Talent
  • Contact
x

Government, Risk, and Compliance

We improve the comprehensive management of your company

The GRC service enables sound decision-making, risk reduction, and improved regulatory compliance. It responds transparently and effectively to an environment marked by legal requirements, growing risks, and technological transformation.

At PKF Attest companies toward more mature and secure management. We design customized roadmaps to strengthen operational efficiency and technological security through:

Audits and Internal Control, Risk Management, Compliance, Cybersecurity

Align GRC criteria with your business objectives

Boost confidence, protect your organization, and anticipate the future with a robust GRC strategy.

Start Consultation

Our GRC services

PKF Attest icon

Government

Corporate governance encompasses the set of rules, policies, and processes that ensure the organization moves consistently toward its strategic objectives. It covers resource management, talent, finance, management controls, and the ethical culture that underpins decision-making.

We help you create a solid, coordinated environment to meet business objectives, improve the customer experience, and ensure the engagement and accountability of every member of the company.

What services are included in the governance part of GRC?

Strategic consulting – Regulatory and corporate governance – Internal auditing – ESG – Governance models and decision-making structures – Corporate policies and document management – People management.

PKF Attest icon

Risk Management

At PKF Attest risk management as a strategic, continuous, and cross-functional process that allows us to anticipate, assess, and control financial, legal, operational, technological, and information security risks.

Our approach combines experience, proprietary methodology, and technology to align risk management with current and future objectives. Through specialized audits and advanced analysis models, we identify critical threats and vulnerabilities, assess their impact, and segment each risk to design customized and effective mitigation plans.

What services are included in Risk Management?

Vulnerability analysis – Legal risks – Cybersecurity – Information security – Strategic risk – Financial risk – Operational risk – ESG – Risk assessment and risk maps.

PKF Attest icon

Internal audit and internal control

We support companies in the development and optimization of their internal control models, both for financial and non-financial information. Our goal at PKF Attest minimize risks, improve management, ensure effective monitoring, and increase the company's profitability.

Internal auditing plays a fundamental role in achieving strategic objectives, as it allows risks to be identified, processes to be evaluated, and controls to be strengthened. We have specialized teams that provide internal auditing services both in-house and on an outsourcing basis, offering flexibility and experience within your organization's reach.

Outsourcing of the Internal Audit Function

We enable companies to access a high level of expertise and objectivity in audits without the need to maintain an internal team.

What services are included?

Internal audit – Outsourcing of the internal audit function – GRC audit – SCIIF and SCIIS consulting – Assessment of operational controls – Regulatory compliance review (regulated entities) – IT/systems audit

PKF Attest icon

Regulatory Compliance

Compliance with current legislation and regulations is essential for companies to operate safely, efficiently, and reliably. At PKF Attest audits that ensure your organization complies with all applicable laws, rules, and regulations in your sector.

From our GRC area, we help companies identify the policies and regulations they must comply with, implement practical solutions to align with legal and regulatory requirements, obtain certifications that support their ability to operate safely and compliantly, and successfully pass audits, reflecting a high standard of security and governance.

What services are included in regulatory compliance?

ISOs – ENS – Dora Regulation – Money Laundering Prevention – Sustainability Directives – MiFID II / MIFIR – ESMA / EBA Guidelines and Directives Unified Code of Good Governance

GRC Strategy

We unify GRC criteria and coordinate efforts

The current environment is increasingly demanding, with constantly changing regulations, critical risks, and rapid technological disruption. Adapting without affecting profitability is a challenge.
At PKF Attest, we unify criteria in Governance, Risk, and Compliance (GRC) to align strategies, optimize processes, and coordinate efforts efficiently. Through innovative methodologies and advanced technology, we strengthen governance, mitigate risks, and ensure regulatory compliance, allowing your company to operate with confidence, greater control, and strategic vision.

pkf attest GRC strategy

Implementation of a GRC strategy with PKF Attest

The implementation of a GRC program enables companies to make informed decisions, manage critical risks, and comply with all applicable regulations without compromising efficiency or profitability.

At PKF Attest a comprehensive and personalized approach, supported by professionals specializing in legal, tax, auditing, ESG, cybersecurity, and consulting, as well as advanced technological tools that facilitate the monitoring, analysis, and automation of Governance, Risk, and Compliance processes. Implementing our GRC strategy allows you to:

initial diagnosis and assessment

Initial diagnosis and risk assessment

strategy

Custom GRC strategy design

implementation and coordination

Implementation and coordination of controls

GRC monitoring and reporting

Continuous monitoring and reporting

Evaluation and improvement

Evaluation and continuous improvement

What do we offer in auditing?

GRC Consulting

Operate with confidence and sustainability. We adapt to your needs.

At PKF Attest your company optimize governance, risk management, and regulatory compliance through specialized audits and customized solutions.

Your company, a focus for investors

We strengthen controls to ensure transparency, identify gaps and vulnerabilities in processes, and mitigate critical risks, ensuring continuity and operational security.

Do you need GRC advice or consulting?

Contact an expert
ideko
Endesa
Provincial Council of Gipuzkoa
Biscayan Federation of Metal Companies
Iberdrola
Adif
Fagor
Cinfa

GRC Software, Applied Technology

MideNet regulatory compliance GRC software provides support and agile responses for risk management and internal control. Companies use GRC software to:

GRC Process Management Software

Strategic management software that covers all key stages of a GRC process strategy. A results-oriented tool designed to transform your organization.

Request a demo

Monitor and provide ongoing auditing

Identify the regulations that apply to your company, verify compliance with obligations, and create tasks to plan actions, avoid penalties, and mitigate the risk of non-compliance.

Monitoring, management control, and strategy evaluation

MideNet offers a comprehensive view through modules of all operations within a company for monitoring and evaluating each strategic stage of Risk and Compliance Governance.

Integrate GRC models with business management plans

MideNet allows you to manage, among other things: Criminal Compliance, SCIIF, GDPR/ENS, and Corporate Risks. As well as project management models, strategy, sustainability, etc.

Related content

Regulation and economics
EVENT

Regulation and economics

Read more
Conference: financing opportunities for the digitalization of companies in Biscay
EVENT

Conference: financing opportunities for the digitalization of companies in Biscay

Read more
Materiality analysis: The first step in your ESG strategy
EVENT

Materiality analysis: The first step in your ESG strategy

Read more
New regulatory landscape in sustainability: less regulatory burden, more strategic opportunity
EVENT

New regulatory landscape in sustainability: less regulatory burden, more strategic opportunity

Read more
The directive that will change corporate cybersecurity in Spain
EVENT

The directive that will change corporate cybersecurity in Spain

Read more
We consolidate our growth in Madrid with the move to a new PKF Attest office
EVENT

We consolidate our growth in Madrid with the move to a new PKF Attest office

Read more

Where are our offices located?

Alicante – Barcelona – Bilbao – Granada – San Sebastian – Madrid – Pamplona – Seville – Valencia – Valladolid – Vitoria – Zaragoza

Other complementary services

Legal and tax advice, auditing and economic consulting, information technology, R&D&I incentives, organization and people management, capital markets, corporate finance, and regulation.

Frequently asked questions GRC

Which professionals work on a GRC strategy?
Deploy
It depends on the nature and scope of the GRC project. At PKF Attest, thanks to our versatility as a professional services firm, we put together multidisciplinary teams that are tailored to the specific needs of each GRC initiative. In other words, we bring together the profiles with the greatest knowledge and experience in each of the areas that make up the Governance, Risk, and Compliance strategy. The professionals who usually participate include: auditors, consultants, experts in ISO regulations and standards, developers and technicians, cybersecurity specialists, etc. This combination of profiles allows us to approach GRC projects with a comprehensive, solid vision that is tailored to each organization.
What does a GRC consultant do?
Deploy
GRC consultants help companies and organizations manage governance, risk, and compliance by ensuring project continuity, security, and efficiency. A consultant is responsible for identifying areas for improvement and compliance in order to align GRC objectives with business objectives.

Contact

Name and Surname(Required)
Company(Required)

  • PKF Attest
  • Services
  • Sectors
  • Locations
  • Corporate policies and certificates
  • Communication Area
  • News
  • Corporate videos
  • Press releases
  • Events
  • Connect with us
  • Talent
  • Contact
  • PKF Attest
  • 2026 All rights reserved ©
  • Legal Notice
  • Privacy Policy
  • Cookies Policy
  • Complaints channel
  • Links to social networks

PKF Attest is a member of PKF Global, the network of member firms of PKF International Limited, each of which is a separate and independent legal entity and accepts no responsibility or liability for the actions or inactions of any individual member or correspondent firm(s). "PKF" and the PKF logo are registered trademarks used by PKF International Limited and member firms of the PKF Global network. They may not be used by anyone other than a duly authorized member firm of the Network.

PKF Attest is a member of PKF Global, the network of member firms of PKF International Limited, each of which is a separate and independent legal entity and does not accept any responsibility or liability for the actions or inactions of any individual member or correspondent firm(s). "PKF" and the PKF logo are registered trademarks used by PKF International Limited and member firms of the PKF Global Network. They may not be used by anyone other than a duly licensed member firm of the Network.

GDPR Report - Biometric Data

Did you know that the use of fingerprint or facial recognition in labor control is not always legal? In our report on biometric data and workday registration we analyze the AEPD criteria, the legal risks faced by companies and the safe and less intrusive alternatives. Discover all the news!

By clicking on this content, you agree to our Privacy Policy.

Photo by Wafi Saleh

Wafi Saleh

 

Wafi has over 20 years of corporate and investment banking experience, with most of his career developed at Banco Santander and Banesto.

Prior to joining PKF Attest CM, he occupied various positions at Santander Global Banking & Markets division (SGBM), where he was Head of Middle East Corporates, Head of the Global Funding Platform, Head of the MTN Desk at the European Bond Syndicate, responsible for Private Placements origination covering European: Corporates, FIG, & SSA issuers.

Before joining Banco Santander, Wafi worked at Banesto, where he was Head of DCM, Bond Syndicate and the Funding Platform. He has extensive experience in bond issuance and has set up and managed the SPV, the EMTN and ECP programmes for the bank and corporate clients, issuing vanillas and structured notes. He was a board member of Banesto Financial Products PLC and Santander International Products PLC.

Wafi has an outstanding fingerprint in the capital markets and is co-responsible for the creation and management of the Banesto Funding Platform, a unique primary bond market platform that helped corporates access capital markets recurrently and efficiently through primary MTNs and CP issuance.

Wafi holds a BA Hons degree in International Business and Management studies from the European Business School, London, and has attended IESE management development program in Madrid.

Photo by Javier Jordán

Javier Jordan

Javier is an experienced banker and financial advisor with over 20 years of experience in banking and financial advisory services covering capital markets, project and structured finance, syndicated loans origination and distribution.

Prior to joining PKF Attest CM, he worked at Banco Santander and prior to that at Banesto were he was Head of Structured Financing for the Basque Country region, responsible for origination, risk analysis, debt structuring and syndication of a wide range of financing products: corporate finance, project finance, LBO and debt restructuring.

Before Joining Banesto, Javier worked at Accenture and Management Solutions where he was senior consultant in different international projects covering banking and insurance sectors.

Javier holds BA Hons in Economics and Business Administration from Deusto University

Photo by Jokin

Jokin Cantera

Jokin has over 25 years of commercial and investment banking experience, with most of his career developed at Banco Santander, Banesto and JP Morgan Chase.

Prior to PKF Attest CM, Jokin worked at Santander Global Banking & Markets division (SGBM) in London, where he was Head of Northern European Institutional Sales, covering credit markets, rates and FX distribution of flow and non-flow products.

Before joining Banco Santander, Jokin was deputy general manager of the wholesale banking division at Banesto, responsible for credit markets (origination, trading and distribution), ACPM, securitization, rates and structured products distribution. He was also head of institutional sales, responsible for the structuring, origination and distribution of credit, rates, FX and multi-asset products to institutional investors.

With a strong innovative mindset and an entrepreneurial approach, Jokin was co-responsible for the creation of the Banesto Funding Platform, a unique primary bond market platform that helped corporates access the capital markets recurrently and efficiently through primary MTNs and CP issuance. He was also a board member of Banesto Financial Products PLC.

Jokin holds a BA Hons degree in Economics and Business Administration from Deusto University and has attended IESE, Chicago GSB & IE management programmes in Madrid and London.

M&A Report - Mechanical Engineering

Download our exclusive and free report "M&A Overview - Mechanical Engineering Sector", prepared by the M&A experts at PKF Attest. Access 2024 and 2025 data and trends in the industry.

If you give your consent, you are accepting our privacy policy and PKF Attest information security policies.

M&A Report - Packaging Sector

Download our exclusive and free report "M&A Overview - Packaging Sector", prepared by the M&A experts at PKF Attest. Access 2024 and 2025 industry data and trends.

If you give your consent, you are accepting our privacy policy and PKF Attest information security policies.

M&A Report - Technology Sector

Download our exclusive and free report "M&A Overview - Technology Sector", prepared by the M&A experts at PKF Attest. Access 2024 and 2025 data and trends in the IT services sector.

If you give your consent, you are accepting our privacy policy and PKF Attest information security policies.

 

If you give your consent, you are accepting our privacy policy and PKF Attest information security policies.

M&A Report - Chemical Sector

Download our exclusive and free report "M&A Overview - chemical sector", prepared by PKF Attest's M&A experts. Access data and trends for 2024

If you give your consent, you are accepting our privacy policy and PKF Attest information security policies.

Download our exclusive and free report "M&A Overview - Iberian Automotive sector", prepared by the M&A experts at PKF Attest. Access data and trends for 2024.

 

If you consent, we will use this information to send you related content.

Iberian M&A Overview

Access data and trends in the pharmaceutical sector in 2024.

Download our exclusive and free report "Iberian M&A Overview", prepared by the M&A experts at PKF Attest.

If you consent, we will use this information to send you related content, discounts and other special offers.

Report: IFRS Adoption Process

Access to exhaustive information on the International Financial Reporting Standards, identifying some of the main differences in valuation with the General Accounting Plan, without the scope of the work performed pretending to be exhaustive.

Fill in the form and get instant access to the report!

If you consent, we will use this information to send you PKF Attest related content.

 

We love to see you here! PKF ATTEST SERVICIOS PROFESIONALES, S.L. uses its own and third party cookies for a variety of purposes, such as improving your browsing experience and our service. The use of cookies by third parties is subject to their own cookie policy. You can accept or reject all use of cookies by clicking on the "Accept all and close" or "Reject all" button. You can also set and save your cookie preferences by clicking on the "Set cookies" button. You can learn more about the use of cookies and your rights in our cookie policy.

 


Strictly necessary cookies

Third party cookies

Powered by GDPR Cookie Compliance
Privacy summary

This website uses cookies so that we can provide you with the best possible user experience. Cookie information is stored in your browser and performs functions such as recognizing you when you return to our site or helping our team understand which sections of the site you find most interesting and useful.

Strictly necessary cookies

Strictly necessary cookies must always be enabled so that we can save your cookie setting preferences.

If you disable this cookie we will not be able to save your preferences. This means that every time you visit this website you will have to enable or disable cookies again.

Third party cookies

This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, or the most popular pages.

Leaving this cookie active allows us to improve our website.

Please enable strictly necessary cookies first so that we can save your preferences!