Hael
Book a meeting

SERVICES

Services

We implement the controls, prepare the evidence and manage the assessment, rather than stopping at recommendations. Every engagement is scoped and priced before it begins.

Where our engagements typically begin

Most engagements start in one of three places. An enterprise customer has asked for a SOC 2 report and the deal is waiting on it. An audit window or certification deadline has been set and the organisation needs practitioner-led delivery to meet it. Or Vanta, Drata or Secureframe is already in place and the work of turning the checklist into an examinable control environment remains to be done.

SOC 2 is the programme we run most. SOC 2 compliance consulting covers readiness, implementation, evidence, project management and coordination of the independent CPA firm that performs the examination.

What we do

SOC 2 readiness and implementation

SOC 2 compliance consulting run end to end: scope and Trust Services Criteria, readiness assessment, control implementation and remediation, policies, evidence, project management and independent CPA audit coordination.

SOC 2 readiness and implementation

Compliance readiness and gap assessment

A decision-ready assessment of the organisation's current control environment against the frameworks, regulations and assurance requirements that matter, with a practical programme for the work required.

Compliance readiness and gap assessment

Security control and policy implementation

Establish the policies, responsibilities, controls and evidence a framework requires — access, change, logging, vulnerability management, incident response and vendor oversight — translated from requirement into working practice.

Security control and policy implementation

Audit readiness and independent assessment support

Focused readiness review, remediation, evidence coordination and audit support so the organisation enters an independent CPA examination or certification assessment properly prepared.

Audit readiness and independent assessment support

Internal audit and compliance project management

Objective, evidence-based internal audit across security and AI governance management systems, and the programme management that keeps a compliance timetable on the date it was promised for.

Internal audit and compliance project management

Continuous compliance and assurance

Ongoing practitioner support and structured oversight so systems, controls, evidence and approvals remain current between reporting periods as the organisation changes.

Continuous compliance and assurance

Buyer security reviews

A governed assurance position for enterprise diligence, with approved claims and supporting evidence used consistently across questionnaires, diligence calls and buyer-facing materials.

Buyer security reviews

AI governance implementation

Where AI is in scope, the policies, responsibilities, controls and evidence needed to govern the AI the organisation develops, provides and uses, including a named practitioner on retainer as your accountable AI Governance Officer.

AI governance implementation

Technology — the Hael platform

The system of record we use during engagements and hand to clients afterwards, holding systems, obligations, controls, evidence and approvals in one place so the position is maintainable.

Technology — the Hael platform

FRAMEWORKS

Frameworks

We work across SOC 2, ISO 27001, ISO/IEC 42001, the EU AI Act, the NIST AI Risk Management Framework and GDPR as it applies to AI. Where two frameworks overlap, one evidence set serves both.

Frameworks we cover →

GET STARTED

Tell us the framework and the deadline.

We will set out what the work involves and what it costs. Thirty minutes, no obligation.