Governance, Risk & Compliance
Governance frameworks, control design, and certification readiness that withstand external audit.
Certification works best as a by-product of a control environment that already functions, rather than as the objective. The failure mode is familiar: a control set designed backwards from the auditor's checklist, policies written to be shown rather than followed, and an organisation that passes the audit while being no more secure than it was. That certificate is worth something commercially and very little operationally, and the gap tends to surface at the worst possible moment.
Done properly, the sequence is unglamorous. A gap assessment that tells you the truth, control design mapped to your actual obligations, remediation prioritised so the expensive items are the ones that matter, and evidence collected as a routine output of doing the work rather than assembled in a panic the fortnight before the auditor arrives. Evidence management is where most programmes quietly fail, and it is largely a question of building the collection into normal operations.
Where several frameworks apply, and they usually do, the controls should be mapped once and evidenced once. An organisation carrying ISO/IEC 27001, SOC 2 and PCI-DSS obligations is mostly carrying the same controls under three different names, and gathering the same evidence three times is a tax with no benefit.
You might need this if
- A customer contract requires ISO/IEC 27001 or SOC 2 and the clock has already started
- Policies exist, are current, and are followed by almost nobody
- The same evidence is being gathered separately for three different frameworks
- A previous audit produced findings that were accepted and never actually closed
- You are answering security questionnaires from scratch every time one arrives
Who it's for
Boards and executives who need defensible assurance, and teams preparing for a certification or a customer-driven audit.
How the engagement runs
- 01
Scoping and gap assessment
Establish what is genuinely in scope, which is usually narrower than the first instinct, and assess honestly against the standard. An inflated scope is the most expensive early mistake.
- 02
Control design and remediation
Controls mapped to your obligations rather than lifted from a template, and a remediation roadmap prioritised by risk and cost rather than by the order the clauses happen to appear in.
- 03
Evidence and internal audit
Evidence collection built into how the work already happens, followed by an internal audit that finds the problems while there is still time to fix them.
- 04
External audit and certification
Auditor liaison, evidence packs, and support through the certification audit and its findings, so the process is a formality rather than a discovery exercise.
What's delivered
- Certification readiness for ISO/IEC 27001:2022 and SOC 2 Type 2
- Control framework mapped to your obligations, not a generic checklist
- Policy and standards set that people will actually follow
- Gap assessment with a prioritised, costed remediation roadmap
- Audit liaison and evidence management through to certification
Proof point
Led ISO/IEC 27001:2022 and SOC 2 Type 2 attainment at one of New Zealand's largest technology organisations, end to end from gap assessment to certification.
Common questions
- ISO/IEC 27001 or SOC 2?
- Follow the buyer. Broadly, ISO/IEC 27001 travels better internationally and with enterprise procurement, while SOC 2 is expected by North American technology customers. If both are being asked for, build one control set and evidence it against both rather than running two programmes.
- Can you certify us as well?
- No, and nobody credible can do both. Certification requires an accredited independent body, and my involvement in designing your controls would disqualify me from auditing them. I prepare you and work alongside the auditor; the opinion has to come from someone with no stake in it.
- How much of this can our own team do?
- More than most consultancies will tell you, and that is the intended outcome. The parts genuinely worth buying in are the scoping judgement, the control design, and the audit experience. The evidence routine should end up owned entirely by your team, because it has to outlive the engagement.
- Do we need a GRC platform?
- Not to begin with. A capable spreadsheet and disciplined evidence collection carry most organisations through a first certification. Buy the tooling once you know your own process well enough to judge whether a given product fits it.
Other services
- Risk Management & Quantitative Risk Analysis
- Digital, Cyber & Technology Risk
- Third-party & Supply Chain Risk
- AI Security, Risk & Governance
- Applied AI for Cyber
- Security Operations
- Data Governance & Privacy
- Secure Architecture & Zero Trust
- Secure Web Applications for SMEs
- Virtual CISO & Security Leadership
- Incident Response & Readiness
Let's talk about your security programme
Considering a vCISO, a security strategy and architecture, a SOC uplift, an AI assurance review, or a secure web build? Tell me where you are and where you need to get to.