Services

Readiness programmes built on your operations, not a template

Every engagement starts with your actual processes. The management system we leave behind is one your team can run after we step away, and one an auditor can follow.

ISO/IEC 27001:2022

Information security management readiness

A complete ISMS built to pass a Stage 1 and Stage 2 audit, scoped to your business, not a template dump.

Who it's for

Organisations facing customer security requirements, tender obligations, or a first certification.

Timeline

Typically 12–20 weeks to audit readiness

Scope of work

  • Scope definition and boundary setting
  • Gap assessment against all Annex A controls
  • Risk assessment and treatment methodology
  • Policy and procedure set written to your operations
  • Internal audit and management review
  • Certification body selection and audit support

What you receive

  • Statement of Applicability
  • Risk register and treatment plan
  • Full ISMS documentation set
  • Internal audit report and corrective actions
  • Evidence pack mapped to each clause

ISO/IEC 42001:2023

AI management system readiness

Governance for the AI you are already shipping: inventory, impact assessment, controls, and oversight that stands up to scrutiny.

Who it's for

Teams deploying or procuring AI who need demonstrable governance for customers and regulators.

Timeline

Typically 10–18 weeks to audit readiness

Scope of work

  • AI system inventory and classification
  • AI impact assessments and risk methodology
  • Annex A / Annex B control implementation
  • Data governance and model lifecycle controls
  • Human oversight and incident handling
  • Alignment with existing ISO 27001 controls

What you receive

  • AI system register with risk tiering
  • AI policy, roles, and oversight model
  • Impact assessment templates and completed examples
  • Control implementation evidence
  • Audit readiness review

27001 + 42001

Integrated management system programme

One set of controls, one internal audit cycle, two certifications. The efficient path when both standards are in scope.

Who it's for

Organisations that need both certifications and refuse to run two parallel bureaucracies.

Timeline

Typically 16–26 weeks to audit readiness

Scope of work

  • Unified scope and shared clause structure
  • Single risk methodology covering security and AI
  • Merged control set with no duplicate evidence
  • Combined internal audit and management review
  • Joint or sequential certification planning

What you receive

  • Integrated management system manual
  • Combined control matrix across both standards
  • Single evidence repository structure
  • Programme plan through to certification

Engagement & payment

How we structure and bill the work

Fixed-scope programme

A defined path to audit readiness with agreed milestones and a fixed fee. The default for first certifications.

Advisory retainer

Ongoing support for an operating management system: internal audits, reviews, surveillance audit preparation.

Assessment only

A standalone gap assessment against 27001 or 42001, delivered as a prioritised remediation plan.

Payment methods

Invoices settle by card, bank transfer, or cryptocurrency through Coinbase for Business. Crypto settlement is available for both readiness programmes and course fees, raise it on the discovery call and we'll issue the appropriate invoice.

Start a conversation