Governance you can prove, not just promise
Documenting how your organisation works isn't paperwork — it's the blueprint of the business itself.
Every company has policies and procedures. In an ever-changing world — and with AI now part of the picture — the question is: when did you last review yours? We offer a full range of ISO 27001:2022 and ISO 42001:2023 services to help you review, align and prove your operation meets today's requirements.
Documenting how your organisation works is critical — it's the blueprint of the business itself. Every company has policies and procedures; the real question is whether they still match how you operate today.
Four control themes. One integrated review.
Our ISO 27001:2022 audits assess your Information Security Management System (ISMS) across four control themes — so nothing that touches your security posture is left unchecked.
Organisational Controls
The policies, roles and accountability structures that hold your ISMS together.
People Controls
How your team is screened, trained and held accountable for security day to day.
Physical Controls
The safeguards protecting the buildings, hardware and physical assets behind your data.
Technology Controls
The systems, access controls and technical safeguards that keep information secure.
Seven services. One accountable partner.
From first audit to embedded continual improvement, grouped into three stages of the journey.
Audit & assurance
Find out exactly where you stand before you spend a dollar fixing anything.
ISO 42001:2023 & ISO 27001:2022 Audits
ISO 42001:2023 AIMS audit — we review your AI controls against the ISO standard, confirming conformity with your safety and security operational requirements.
ISO 27001:2022 audit — security and cybersecurity assessed across all four control themes above, plus your assets and asset valuation, verified against the ISO 27001:2022 standard.
Compliance, Risk Assessment & Treatment Consulting
We deliver expert consulting to help you establish and maintain effective compliance, risk assessment and risk treatment processes in line with ISO/IEC 27001:2022 & ISO/IEC 42001:2023 — grounded in each standard's core principles, not a generic checklist.
Design & documentation
Turn findings into a management system and a paper trail that will actually hold up.
AIMS & ISMS Creation, Design & Planning Assistance
Architecting security that drives business value. We offer comprehensive consulting to help create and maintain an AI Management System (AIMS) fully aligned with ISO/IEC 42001:2023, and an Information Security Management System (ISMS) fully aligned with ISO/IEC 27001:2022.
Statement of Applicability (SoA) Planning
Expert assistance developing and maintaining your Statement of Applicability (SoA), in alignment with ISO/IEC 27001:2022 & ISO 42001:2023 requirements — the document that ties every control back to a documented, defensible reason.
Quality Manual Alignment Consulting
Tailored guidance to create or modify your organisation's operational documentation — including policies, procedures and control narratives — so it's fully aligned with the structural and content requirements of ISO/IEC 27001:2022 & ISO/IEC 42001:2023.
Coaching & culture
Compliance built into how your people think and work, not bolted on once a year.
Audit Team Coaching & Mentoring
ISO 27001:2022 & ISO 42001:2023 aren't about ticking compliance boxes — they're about cultivating a unified, informed and proactive team. Our customised coaching and mentoring aligns and empowers your auditors, AIMS & ISMS implementors, and risk management professionals as one cohesive force behind your organisation's security resilience.
Continual Improvement Plans
Turning compliance into competitive advantage. ISO 27001 & ISO 42001 aren't one-time achievements — they're living systems that thrive on evolution. Our coaching and mentoring embeds a culture of constant refinement and resilience across your AI Management System and Information Security Management System.
From first conversation to embedded practice.
The same three stages you just read about, run as one continuous engagement.
Audit & Assurance
We assess where your ISMS and AIMS stand today, across all four control themes, assets and risk.
Design & Documentation
We build or realign the AIMS, ISMS, SoA and Quality Manual so your documentation matches reality.
Coaching & Continual Improvement
We mentor your team and embed a cycle of review, so compliance keeps pace as your business changes.
Frequently asked questions.
Straight answers to the questions we hear most before an engagement starts.
What's the difference between ISO 27001:2022 and ISO 42001:2023?
Do we need both standards, or just one?
How long does an ISO 27001:2022 audit take?
What is a Statement of Applicability (SoA)?
Can you help maintain certification, not just achieve it?
Turn your ISO obligations into a documented, defensible advantage.
A 30-minute conversation with a specialist — not a salesperson — mapped to audit, documentation and ongoing governance.
