Gap analysis
Where you stand against the standard, and what certification will require. Scope is set here, and scope decides both the cost of the work and whether the report satisfies your buyers.
Gap analysis →SERVICES
We take on the work rather than the advice alone. Every engagement is scoped and priced before it starts, and delivered to a schedule you can see.
Most work starts in one of three places. A buyer has sent a security or AI questionnaire and the answers do not exist. A certification deadline has been set and nobody internally has the time or the background to meet it. Or a compliance platform was bought some months ago and the outstanding task list has not moved.
Where you stand against the standard, and what certification will require. Scope is set here, and scope decides both the cost of the work and whether the report satisfies your buyers.
Gap analysis →The management system, controls, documentation and evidence, built to your deadline and built to survive examination. We write the policies, establish the controls and run the project.
Implementation →Required annually under ISO 27001 and ISO/IEC 42001. It cannot be carried out by the body that certifies you, and most companies have nobody internally who is both competent and independent.
Internal audit →Preparation for Stage 1 and Stage 2, evidence assembly, and attendance alongside you through the audit itself.
Certification support →CAIQ, SIG, SIG Lite, DDQ and bespoke questionnaires, answered from your approved evidence rather than assembled from memory each time.
Buyer security reviews →Retained support covering control re-testing, evidence refresh, regulatory change and buyer response.
Continuous assurance →FRAMEWORKS
We work across ISO/IEC 42001, SOC 2, ISO 27001, the EU AI Act, the NIST AI Risk Management Framework and GDPR as it applies to AI. Where two frameworks overlap, one evidence set serves both.