Teams sprint to the certificate, then stop. Eleven months later the surveillance audit appears, the access reviews have not been run, half the policies are unversioned and the evidence is stale. The certificate is the start of the obligation, not the end of it — and the body that issued it is not permitted to help you keep it.
Why teams choose us.
Mandatory, And Structurally Yours
ISO 27001 requires an internal audit and management review annually. Your certification body cannot perform them without losing its impartiality. Somebody has to, and it is not them.
Drift Resolved, Not Reported
We do not just flag that the quarterly access review slipped. We run it, evidence it, and put it back on a cadence that survives your next headcount change.
Contracted On The Surveillance Cycle
The risk is not the first audit — it is the second. We contract around the surveillance date, so the work is done before the auditor asks, not after.
Advisory, Explicitly
We track and advise. You retain all decision and risk-acceptance authority in writing. This is not a vCISO service and we do not pretend it is.
The full menu.
Internal Audit & Management Review
- Annual internal audit against the standard
- Management review pack and minutes
- Nonconformity log and corrective actions
- Evidence your certification body cannot produce for you
Control Drift Management
- Access reviews run on cadence
- Control operation evidenced continuously
- Failing controls resolved, not just logged
- Change and exception tracking
Policy Lifecycle
- Scheduled review and versioning
- Exception register with owners and expiry
- Approval trail that survives fieldwork
- Updates on standard revisions
Audit Liaison
- Evidence defence during fieldwork
- Auditor questions answered directly
- Surveillance readiness check pre-audit
- Findings closed before the next cycle
Our process.
Baseline
We inherit your certified ISMS or SOC 2 programme, verify what is actually operating, and mark the drift that has already accumulated.
Cadence
Access reviews, evidence refresh, policy reviews and risk reassessment placed on a calendar that maps to your surveillance date.
Internal Audit
Full internal audit against the standard, plus the management review pack — the two artefacts your certification body is not allowed to produce.
Surveillance
Readiness check before fieldwork, then evidence defence during it. Findings close inside the cycle, not the next one.
What we build with.
The one service with no jurisdictional constraint
An internal audit and management review are first-party activities. The ISO/IEC 17021 independence bar applies to the certification body, not to the firm running your internal audit — so this sells identically everywhere.
Full scope for ISO 27001 internal audit, and for SOC 2 programme maintenance across the reporting cycle. A SOC 2 report is useful for roughly twelve months, so the annuity is structural.
Full scope for private-sector clients. Contracted as advisory, which is what it is: we track and advise, and you retain all decision and risk-acceptance authority in writing.
Full scope. Because the artefacts are documents rather than production access, the engagement can be scoped to zero personal data, which removes the transfer problem that constrains our other services here.
Full scope, and the best global fit in the portfolio. It maps cleanly onto DESC ISR v3, which extends rather than replaces ISO 27001:2022, and onto the recurring assessment cadence NESA expects.
Every market position we hold, with the legal reason and the transfer mechanism, is on where we work.
Choose this if...
Honest about who this is for.
This will be a fit.
- You already hold ISO 27001 certification or a SOC 2 report
- You want the mandatory internal audit and management review run properly
- You would rather find control drift in month three than month eleven
- You accept that decision and risk-acceptance authority stays with you
Honestly — not our zone.
- —You want a vCISO or a named security leader — that is a different purchase and we do not sell it
- —You want monitoring, detection or a response SLA. This retainer carries none
- —You are not yet certified. Start with a Compliance Readiness Assessment instead
- —You want us to accept the residual risk. We track and advise; we never ensure































