Two distinct propositions. Implementation builds and operationalizes the management system or compliance programme. A readiness assessment tests what already exists, benchmarks it against what an assessor would conclude, and prioritizes the gaps that change the outcome.
Group A
Management System Implementation
Build and operationalize a certifiable management system - governance, risk, controls, evidence and the improvement cycle that keeps it working after the audit.
End-to-end implementation of an ISO/IEC 27001:2022 Information Security Management System - governance, risk methodology, Statement of Applicability, controls, evidence and the internal audit and management review cycle that keeps it alive.
Implementation of an ISO/IEC 42001:2023 AI Management System - AI governance structure, system inventory, AI risk and impact assessment, responsible lifecycle controls, third-party AI oversight and performance monitoring.
Implementation of a Privacy Information Management System aligned to ISO/IEC 27701:2025 - privacy governance and accountability, controller/processor role modelling, personal information lifecycle, processing inventory, rights handling and privacy evidence architecture.
Implementation of a Business Continuity Management System aligned to the current edition of ISO 22301 - BCMS governance, business impact analysis, recovery requirements, continuity strategy, crisis management, plans, exercising and supplier continuity.
Explore this service
Group B
Readiness Assessments
Test an existing management system against certification expectations, benchmark it with evidence, and prioritize the gaps that actually change the audit outcome.
An evidence-based benchmark of your existing ISMS against ISO/IEC 27001:2022 certification expectations - clause and Annex A readiness, documentation sufficiency, evidence sampling, and a prioritized 30/60/90-day remediation roadmap.
An independent evaluation of AI governance maturity against ISO/IEC 42001:2023 - AIMS boundary, use-case inventory quality, AI risk and impact evidence, accountability effectiveness, third-party oversight and prioritized certification gaps.
An evidence-based review of your privacy management system against ISO/IEC 27701:2025 - PIMS boundary, accountability, transparency evidence, controller/processor obligation mapping, rights-handling records and a PIMS assurance heatmap.
An independent evaluation of business continuity capability against ISO 22301 - critical activity validation, dependency mapping, BIA quality, recovery objective coherence, crisis readiness, exercise evidence and supplier resilience.
Explore this service
Group C
Regulatory & Compliance Programmes
Implement and assess against regulatory and payment-industry obligations, from applicability through operating processes to compliance evidence.
Implementation support for India’s Digital Personal Data Protection obligations - data fiduciary governance, personal data inventory, notice and consent architecture, data principal rights, grievance workflow, retention, processor oversight and breach response.
A structured assessment of DPDP preparedness - applicability profiling, obligation mapping, phased-commencement readiness, notice and consent testing, rights and grievance walkthroughs, breach preparedness and a risk-ranked remediation programme.
Implementation support for PCI DSS v4.0.1 - scope definition, cardholder data environment design, payment data flow mapping, segmentation, secure configuration, access control, vulnerability management, logging and the compliance evidence programme.
An independent readiness review against PCI DSS v4.0.1 - validation route review, scope accuracy, CDE boundary challenge, payment flow validation, evidence sufficiency, technical control weaknesses and remediation sequencing.
Explore this service
Group D
SOC 2 Preparation
Prepare for an independent SOC 2 examination - system description, control design and the operating discipline that proves controls ran throughout the period.
Preparation for a SOC 2 Type I examination - system boundary definition, Trust Services Category selection, system description preparation, control design suitability, criteria mapping and point-in-time evidence.
Preparation for a SOC 2 Type II examination - operating effectiveness programme, evidence calendar, recurring control execution, exception and deviation management, access and change evidence, and auditor evidence-pack preparation.
Explore this service
Group E
GRC, Audit & Cybersecurity Advisory
Governance structure, risk process, maturity benchmarking, audit capability and third-party oversight - the disciplines that hold the rest together.
Advisory support to design and integrate the GRC operating model - governance framework, compliance architecture, risk and control integration, obligation management, management reporting and evidence governance.
Design and implementation of security governance - governance structure and accountability, policy architecture, risk oversight, security metrics and management visibility.
A structured cybersecurity maturity assessment aligned to the NIST Cybersecurity Framework 2.0 functions, producing current-state maturity, target-state definition and a prioritized improvement roadmap.
Independent IT audit covering IT general controls, access controls, change management and IT operations, with structured evidence testing, findings and tracked remediation.
Support for SOX IT general controls - logical and privileged access, change management, IT operations, control design, testing readiness, evidence standards and deficiency remediation.
Design and operation of a practical risk management process - identification, assessment, treatment, ownership, monitoring and reporting - connected to the controls and decisions it is meant to influence.
Internal audit programme design and delivery - audit universe and planning, fieldwork, evidence, findings, corrective action and reporting, for management systems and business processes.
Design and operation of third-party risk management - supplier due diligence, criticality tiering, risk assessment, contractual controls, ongoing monitoring and periodic review.
Explore this service
Not sure whether you need implementation or a readiness assessment?
If a management system is already in place and its real condition is unclear, start with a readiness assessment. If there is little or nothing to test, start with implementation. Tell us where you stand and we will say which applies.