Services
Readiness programmes built on your operations, not a template
Every engagement starts with your actual processes. The management system we leave behind is one your team can run after we step away, and one an auditor can follow.
ISO/IEC 27001:2022
Information security management readiness
A complete ISMS built to pass a Stage 1 and Stage 2 audit, scoped to your business, not a template dump.
Who it's for
Organisations facing customer security requirements, tender obligations, or a first certification.
Timeline
Typically 12–20 weeks to audit readiness
Scope of work
- Scope definition and boundary setting
- Gap assessment against all Annex A controls
- Risk assessment and treatment methodology
- Policy and procedure set written to your operations
- Internal audit and management review
- Certification body selection and audit support
What you receive
- Statement of Applicability
- Risk register and treatment plan
- Full ISMS documentation set
- Internal audit report and corrective actions
- Evidence pack mapped to each clause
ISO/IEC 42001:2023
AI management system readiness
Governance for the AI you are already shipping: inventory, impact assessment, controls, and oversight that stands up to scrutiny.
Who it's for
Teams deploying or procuring AI who need demonstrable governance for customers and regulators.
Timeline
Typically 10–18 weeks to audit readiness
Scope of work
- AI system inventory and classification
- AI impact assessments and risk methodology
- Annex A / Annex B control implementation
- Data governance and model lifecycle controls
- Human oversight and incident handling
- Alignment with existing ISO 27001 controls
What you receive
- AI system register with risk tiering
- AI policy, roles, and oversight model
- Impact assessment templates and completed examples
- Control implementation evidence
- Audit readiness review
27001 + 42001
Integrated management system programme
One set of controls, one internal audit cycle, two certifications. The efficient path when both standards are in scope.
Who it's for
Organisations that need both certifications and refuse to run two parallel bureaucracies.
Timeline
Typically 16–26 weeks to audit readiness
Scope of work
- Unified scope and shared clause structure
- Single risk methodology covering security and AI
- Merged control set with no duplicate evidence
- Combined internal audit and management review
- Joint or sequential certification planning
What you receive
- Integrated management system manual
- Combined control matrix across both standards
- Single evidence repository structure
- Programme plan through to certification
Engagement & payment
How we structure and bill the work
Fixed-scope programme
A defined path to audit readiness with agreed milestones and a fixed fee. The default for first certifications.
Advisory retainer
Ongoing support for an operating management system: internal audits, reviews, surveillance audit preparation.
Assessment only
A standalone gap assessment against 27001 or 42001, delivered as a prioritised remediation plan.
Payment methods
Invoices settle by card, bank transfer, or cryptocurrency through Coinbase for Business. Crypto settlement is available for both readiness programmes and course fees, raise it on the discovery call and we'll issue the appropriate invoice.
Start a conversation