Pick the GCCAP tier that matches your assurance maturity.
Start with a fixed‑scope sprint to expose the seam and produce an audit‑ready Proof Pack. Then, keep momentum with monthly or quarterly visibility — without creating more work for your teams.
Where we focus
Tier overview
Each tier keeps the same evidence rules and defensibility posture — you’re choosing cadence and depth.
Tier 1 — Proof‑Gap Diagnostic Sprint (fixed scope)
When clients love this: new vendor/site, audit preparation, recurring incidents, or when everyone “has a story” but nobody has proof.
- Seam mapping: handoffs, dwell windows, control points
- Structured evidence capture + hashing
- Exceptions register + compensatory controls
- CAPA register (actionable, versioned)
- Audit‑ready Proof Pack draft + right of reply
Tier 2 — Monthly Assurance Pack
When clients love this: trend visibility, vendor management, and early warning before the next audit cycle.
- Monthly Watchdog insights: dwell + excursions + confidence gaps
- Exceptions & CAPA progress roll‑up
- Controls drift detection (where evidence goes quiet)
- Versioned notes suitable for governance packs
Tier 3 — Quarterly Review
When clients love this: executive cadence, governance narrative, and prioritised investment decisions.
- Quarterly seam risk narrative (what changed, why it matters)
- Recurring exposures and priority fixes
- Board‑ready summary, with defensibility boundaries
- Optional: comparative view across sites/handlers (where available)
What “excited” clients say they wanted
These are the outcomes clients typically chase — and what the GCCAP deliverables are built to enable.
Want a Tier 1 sprint scoped for your airport?
Send your location, handler/caterer context, and any known pain points. We’ll respond with a seam-focused scope outline.