Security & Compliance

The internal audit
your certification body isn't allowed to do.

ISO 27001 requires an internal audit and a management review every single year, and your certification body is barred from performing either. We run them, resolve control drift before it reaches the auditor, and hold your evidence current through surveillance.

12 mo
A SOC 2 report stays useful
3 yrs
ISO 27001 cycle, audited annually
Month 11
When most teams discover the drift
Trusted by 32+ teams shipping remote engineering, today
Razorpay
Naamly
Tekdoors
SimAgro
Enzen Technologies
Greenlink Health
R360
SharafDG
Concourse Solutions
YOptima
ReMarketplace
Desisiv
Dealflow
LIAISON
Stealth Connect
Car Concierge Pro
Dinner Daddy
Heal Me Fit
Heather Hakes
Kegelbell
Laina
MogiFit
Visag
YouthRenewal
OC Weight Loss
USPTO Lawmatics
Delegata
AZCap
Mindbase
WeBuyUglyBuildings
One Collab Space
Epifinder
Razorpay
Naamly
Tekdoors
SimAgro
Enzen Technologies
Greenlink Health
R360
SharafDG
Concourse Solutions
YOptima
ReMarketplace
Desisiv
Dealflow
LIAISON
Stealth Connect
Car Concierge Pro
Dinner Daddy
Heal Me Fit
Heather Hakes
Kegelbell
Laina
MogiFit
Visag
YouthRenewal
OC Weight Loss
USPTO Lawmatics
Delegata
AZCap
Mindbase
WeBuyUglyBuildings
One Collab Space
Epifinder
Why it matters

Teams sprint to the certificate, then stop. Eleven months later the surveillance audit appears, the access reviews have not been run, half the policies are unversioned and the evidence is stale. The certificate is the start of the obligation, not the end of it — and the body that issued it is not permitted to help you keep it.

Benefits

Why teams choose us.

Mandatory, And Structurally Yours

ISO 27001 requires an internal audit and management review annually. Your certification body cannot perform them without losing its impartiality. Somebody has to, and it is not them.

Drift Resolved, Not Reported

We do not just flag that the quarterly access review slipped. We run it, evidence it, and put it back on a cadence that survives your next headcount change.

Contracted On The Surveillance Cycle

The risk is not the first audit — it is the second. We contract around the surveillance date, so the work is done before the auditor asks, not after.

Advisory, Explicitly

We track and advise. You retain all decision and risk-acceptance authority in writing. This is not a vCISO service and we do not pretend it is.

What we offer

The full menu.

Internal Audit & Management Review

  • Annual internal audit against the standard
  • Management review pack and minutes
  • Nonconformity log and corrective actions
  • Evidence your certification body cannot produce for you

Control Drift Management

  • Access reviews run on cadence
  • Control operation evidenced continuously
  • Failing controls resolved, not just logged
  • Change and exception tracking

Policy Lifecycle

  • Scheduled review and versioning
  • Exception register with owners and expiry
  • Approval trail that survives fieldwork
  • Updates on standard revisions

Audit Liaison

  • Evidence defence during fieldwork
  • Auditor questions answered directly
  • Surveillance readiness check pre-audit
  • Findings closed before the next cycle
How it works

Our process.

01

Baseline

We inherit your certified ISMS or SOC 2 programme, verify what is actually operating, and mark the drift that has already accumulated.

02

Cadence

Access reviews, evidence refresh, policy reviews and risk reassessment placed on a calendar that maps to your surveillance date.

03

Internal Audit

Full internal audit against the standard, plus the management review pack — the two artefacts your certification body is not allowed to produce.

04

Surveillance

Readiness check before fieldwork, then evidence defence during it. Findings close inside the cycle, not the next one.

Tech stack

What we build with.

Standards
ISO/IEC 27001:2022ISO/IEC 27002SOC 2 Trust Services Criteria
Platforms
VantaDrataSprintoJiraConfluence
By jurisdiction

The one service with no jurisdictional constraint

An internal audit and management review are first-party activities. The ISO/IEC 17021 independence bar applies to the certification body, not to the firm running your internal audit — so this sells identically everywhere.

United StatesDeliverable

Full scope for ISO 27001 internal audit, and for SOC 2 programme maintenance across the reporting cycle. A SOC 2 report is useful for roughly twelve months, so the annuity is structural.

United KingdomDeliverable

Full scope for private-sector clients. Contracted as advisory, which is what it is: we track and advise, and you retain all decision and risk-acceptance authority in writing.

European UnionDeliverable

Full scope. Because the artefacts are documents rather than production access, the engagement can be scoped to zero personal data, which removes the transfer problem that constrains our other services here.

UAE & GCCDeliverable

Full scope, and the best global fit in the portfolio. It maps cleanly onto DESC ISR v3, which extends rather than replaces ISO 27001:2022, and onto the recurring assessment cadence NESA expects.

Every market position we hold, with the legal reason and the transfer mechanism, is on where we work.

Right fit?

Choose this if...

You are certified or attested and nobody owns keeping it true
Your surveillance audit or Type II renewal is inside twelve months
Your compliance lead left and the programme went with them
You want the internal audit run by someone other than the body that certified you
Right fit?

Honest about who this is for.

Pick us if

This will be a fit.

  • You already hold ISO 27001 certification or a SOC 2 report
  • You want the mandatory internal audit and management review run properly
  • You would rather find control drift in month three than month eleven
  • You accept that decision and risk-acceptance authority stays with you
Skip us if

Honestly — not our zone.

  • You want a vCISO or a named security leader — that is a different purchase and we do not sell it
  • You want monitoring, detection or a response SLA. This retainer carries none
  • You are not yet certified. Start with a Compliance Readiness Assessment instead
  • You want us to accept the residual risk. We track and advise; we never ensure
FAQ

Common questions, straight answers.

Why can't our certification body just do the internal audit?

Impartiality rules. Under ISO/IEC 17021 a certification body may not consult on the management system it certifies, and the internal audit is part of that system. It is a mandatory annual requirement that the people auditing you are structurally forbidden to perform for you.

When is the right time to start?

At certification, not at kickoff. The failure mode is universal: teams sprint to the certificate, disband, and rediscover the programme in month eleven when the surveillance audit appears. Contract on the surveillance cycle and the work is already done when the auditor arrives.

Is this a vCISO service?

No, and we would rather not blur it. A vCISO is a seniority-and-trust purchase with a named security leader attached. This is programme maintenance and the mandatory internal audit. If you need a CISO, hire one — we will help you find them.

When can we start?

Onboarding for existing certified programmes opens as our own ISO 27001 certification completes — we publish the scope statement, certification body and stage dates on the site and update them monthly. We would rather show you our evidence than ask you to take the claim on faith.

Are your certification body's fees included?

No. Their fees are separate and quoted by them, and we will tell you roughly what they are before you sign with us. We take no fee, commission or rebate from any auditor or certification body.

What is not included?

It is advisory. We track and advise, we never ensure or maintain on your behalf, and you retain all decision and risk-acceptance authority in writing. No monitoring, no detection, no incident response, no availability or response SLA.

From $3,500/mo· The internal audit your certification body can't do

Ready to start?

Book a free 30-minute call. We'll scope the work, share examples, and send a plan within a week.

Related

More from this category

Compliance Readiness Assessment
The honest gap list, costed in engineer-days
Compliance Remediation Pod
Keep your Vanta. Keep your auditor. We ship the fixes.
Agent Security & AI Governance Review
Answer the AI questionnaire, fix what it exposes