ISO 27001:2022 & ISO 42001:2023

Governance you can prove, not just promise

Documenting how your organisation works isn't paperwork — it's the blueprint of the business itself.

Every company has policies and procedures. In an ever-changing world — and with AI now part of the picture — the question is: when did you last review yours? We offer a full range of ISO 27001:2022 and ISO 42001:2023 services to help you review, align and prove your operation meets today's requirements.

2ISO standards we work across
4control themes we audit
7services, one accountable partner
Multibiz ISO 27001:2022 and ISO 42001:2023 governance and audit services
Standards & partnerships
ISO 27001:2022
ISO 42001:2023
Essential Eight
Lenovo AI Partner

Documenting how your organisation works is critical — it's the blueprint of the business itself. Every company has policies and procedures; the real question is whether they still match how you operate today.

— Multibiz ISO Advisory
ISO 27001:2022 audit scope

Four control themes. One integrated review.

Our ISO 27001:2022 audits assess your Information Security Management System (ISMS) across four control themes — so nothing that touches your security posture is left unchecked.

Organisational Controls

The policies, roles and accountability structures that hold your ISMS together.

People Controls

How your team is screened, trained and held accountable for security day to day.

Physical Controls

The safeguards protecting the buildings, hardware and physical assets behind your data.

Technology Controls

The systems, access controls and technical safeguards that keep information secure.

Plus assets and asset valuation — we also review your organisation's assets and how they're valued within the ISMS, to verify it meets the requirements of ISO 27001:2022.
Our services

Seven services. One accountable partner.

From first audit to embedded continual improvement, grouped into three stages of the journey.

Stage 1

Audit & assurance

Find out exactly where you stand before you spend a dollar fixing anything.

01

ISO 42001:2023 & ISO 27001:2022 Audits

ISO 42001:2023 AIMS audit — we review your AI controls against the ISO standard, confirming conformity with your safety and security operational requirements.

ISO 27001:2022 audit — security and cybersecurity assessed across all four control themes above, plus your assets and asset valuation, verified against the ISO 27001:2022 standard.

ISO 42001:2023ISO 27001:2022ISMS
Business executive reviewing security controls
02

Compliance, Risk Assessment & Treatment Consulting

We deliver expert consulting to help you establish and maintain effective compliance, risk assessment and risk treatment processes in line with ISO/IEC 27001:2022 & ISO/IEC 42001:2023 — grounded in each standard's core principles, not a generic checklist.

Risk AssessmentRisk TreatmentCompliance
Lead auditor reviewing compliance and risk documentation
Stage 2

Design & documentation

Turn findings into a management system and a paper trail that will actually hold up.

03

AIMS & ISMS Creation, Design & Planning Assistance

Architecting security that drives business value. We offer comprehensive consulting to help create and maintain an AI Management System (AIMS) fully aligned with ISO/IEC 42001:2023, and an Information Security Management System (ISMS) fully aligned with ISO/IEC 27001:2022.

AIMSISMSDesign & Planning
Team planning an AIMS and ISMS system design
04

Statement of Applicability (SoA) Planning

Expert assistance developing and maintaining your Statement of Applicability (SoA), in alignment with ISO/IEC 27001:2022 & ISO 42001:2023 requirements — the document that ties every control back to a documented, defensible reason.

SoAISO 27001:2022
Reviewing the Statement of Applicability documentation
05

Quality Manual Alignment Consulting

Tailored guidance to create or modify your organisation's operational documentation — including policies, procedures and control narratives — so it's fully aligned with the structural and content requirements of ISO/IEC 27001:2022 & ISO/IEC 42001:2023.

PoliciesProceduresControl Narratives
Aligning quality manual documentation and control narratives
Stage 3

Coaching & culture

Compliance built into how your people think and work, not bolted on once a year.

06

Audit Team Coaching & Mentoring

ISO 27001:2022 & ISO 42001:2023 aren't about ticking compliance boxes — they're about cultivating a unified, informed and proactive team. Our customised coaching and mentoring aligns and empowers your auditors, AIMS & ISMS implementors, and risk management professionals as one cohesive force behind your organisation's security resilience.

Auditor CoachingMentoring
Coaching and mentoring an audit team
07

Continual Improvement Plans

Turning compliance into competitive advantage. ISO 27001 & ISO 42001 aren't one-time achievements — they're living systems that thrive on evolution. Our coaching and mentoring embeds a culture of constant refinement and resilience across your AI Management System and Information Security Management System.

Continual ImprovementAIMSISMS
Planning continual improvement for AIMS and ISMS
How it works

From first conversation to embedded practice.

The same three stages you just read about, run as one continuous engagement.

01

Audit & Assurance

We assess where your ISMS and AIMS stand today, across all four control themes, assets and risk.

02

Design & Documentation

We build or realign the AIMS, ISMS, SoA and Quality Manual so your documentation matches reality.

03

Coaching & Continual Improvement

We mentor your team and embed a cycle of review, so compliance keeps pace as your business changes.

Common questions

Frequently asked questions.

Straight answers to the questions we hear most before an engagement starts.

What's the difference between ISO 27001:2022 and ISO 42001:2023?
ISO 27001:2022 governs your Information Security Management System (ISMS) — how you protect information across people, process and technology. ISO 42001:2023 governs your AI Management System (AIMS) — how you manage the safety, security and governance of AI specifically. Many of our clients need both, since AI systems still run on top of the same information security foundation.
Do we need both standards, or just one?
It depends on whether AI is already part of your operations. If you're deploying or planning to deploy AI, ISO 42001:2023 is worth pursuing alongside ISO 27001:2022 — it's designed to sit on top of, not replace, your information security work. We'll help you work out what's actually relevant during the audit stage, rather than selling you both by default.
How long does an ISO 27001:2022 audit take?
It varies with the size and complexity of your operation, but most engagements move through the audit stage in a matter of weeks, not months. We'll give you a specific timeline once we understand your scope in an initial conversation.
What is a Statement of Applicability (SoA)?
The SoA is the document that lists every control in the ISO 27001 framework and states whether it applies to your organisation, and why. It's one of the most scrutinised documents in a certification audit, which is why we treat it as its own dedicated service rather than an afterthought.
Can you help maintain certification, not just achieve it?
Yes — that's what our Continual Improvement Plans and Audit Team Coaching services are built for. Certification is a point-in-time achievement; staying certified means your team needs to keep the system alive year-round, which is where ongoing coaching and mentoring makes the difference.
Let's talk

Turn your ISO obligations into a documented, defensible advantage.

A 30-minute conversation with a specialist — not a salesperson — mapped to audit, documentation and ongoing governance.

A clear read on where your ISMS and AIMS stand today
Straight answers on ISO 27001:2022 & ISO 42001:2023 requirements
A realistic next step, whether that's certification or just a tidy-up

5 + 12 =