When this fits
A certification or customer audit is coming and the evidence is scattered.
Policies exist, and what the organisation does differs from what they say.
Risk is tracked in a spreadsheet nobody has updated since the last incident.
How we work within it
Start from what is actually done
Policy written to describe and improve real practice. A control the organisation does not perform is not a control, however well it is documented.
Evidence as a by-product of operating
Where possible, evidence is produced by the system doing the work rather than by someone assembling screenshots the week before an audit.
Risk in terms the business uses
Ranked by what it would actually cost you, not by a severity label copied from a scanner.
What you get it on
GRC, across these domains
A delivery model is not a product. These are the technology domains we work in through it — start from the one your problem sits in.
Engagement and pricing model
Fixed-price for a defined readiness assessment or gap analysis; a retainer for ongoing programme support. Certification audits themselves are performed by an accredited body, never by us — that separation is the point of certification.
What we commit to, and what we measure
Findings closed versus reopened at the next review.
Evidence retrievable on request without a preparation project.
Time from an auditor's question to a sourced answer.
Targets are set per engagement and written into the agreement. We do not publish a number here, because a service level that is not attached to a specific scope is not a commitment.
Questions we are asked
Can you certify us?
No, and nobody who prepares you should. Certification is issued by an accredited certification body, and a supplier who both prepares and certifies has removed the independence that makes the certificate worth anything.
Which framework should we adopt?
Usually whichever your customers and regulator ask for, before whichever is most respected. Adopting a framework nobody is asking you for is a real cost with a speculative return.
How long does readiness take?
It depends far more on how much you already do than on the framework. The gap analysis is what produces a timeline, and it comes before any date is promised.
Do you write the policies for us?
We draft them from what you actually do and then work with you to change what should change. A policy set written in isolation reads well and fails at the first audit interview.
What happens after certification?
The part most organisations underestimate: surveillance audits and continuous evidence. That is what a retainer is for, and it is worth budgeting before the certificate rather than after.
Start with an assessment
The fastest way to a useful answer is a short, scoped look at what you already have.