Teams sprint to the certificate, then stop. Eleven months later the surveillance audit appears, the access reviews have not been run, half the policies are unversioned and the evidence is stale. The certificate is the start of the obligation, not the end of it — and the body that issued it is not permitted to help you keep it.
Why teams choose us.
Mandatory, And Structurally Yours
ISO 27001 requires an internal audit and management review annually. Your certification body cannot perform them without losing its impartiality. Somebody has to, and it is not them.
Drift Resolved, Not Reported
We do not just flag that the quarterly access review slipped. We run it, evidence it, and put it back on a cadence that survives your next headcount change.
Contracted On The Surveillance Cycle
The risk is not the first audit — it is the second. We contract around the surveillance date, so the work is done before the auditor asks, not after.
Advisory, Explicitly
We track and advise. You retain all decision and risk-acceptance authority in writing. This is not a vCISO service and we do not pretend it is.
The full menu.
Internal Audit & Management Review
- Annual internal audit against the standard
- Management review pack and minutes
- Nonconformity log and corrective actions
- Evidence your certification body cannot produce for you
Control Drift Management
- Access reviews run on cadence
- Control operation evidenced continuously
- Failing controls resolved, not just logged
- Change and exception tracking
Policy Lifecycle
- Scheduled review and versioning
- Exception register with owners and expiry
- Approval trail that survives fieldwork
- Updates on standard revisions
Audit Liaison
- Evidence defence during fieldwork
- Auditor questions answered directly
- Surveillance readiness check pre-audit
- Findings closed before the next cycle
Our process.
Baseline
We inherit your certified ISMS or SOC 2 programme, verify what is actually operating, and mark the drift that has already accumulated.
Cadence
Access reviews, evidence refresh, policy reviews and risk reassessment placed on a calendar that maps to your surveillance date.
Internal Audit
Full internal audit against the standard, plus the management review pack — the two artefacts your certification body is not allowed to produce.
Surveillance
Readiness check before fieldwork, then evidence defence during it. Findings close inside the cycle, not the next one.
What we build with.
The one service with no jurisdictional constraint
An internal audit and management review are first-party activities. The ISO/IEC 17021 independence bar applies to the certification body, not to the firm running your internal audit — so this sells identically everywhere.
Full scope for ISO 27001 internal audit, and for SOC 2 programme maintenance across the reporting cycle. A SOC 2 report is useful for roughly twelve months.
Full scope for private-sector clients. Contracted as advisory, which is what it is: we track and advise, and you retain all decision and risk-acceptance authority in writing.
Full scope. Because the artefacts are documents rather than production access, the engagement can be scoped to zero personal data, which removes the transfer problem that constrains our other services here.
Full scope. It maps cleanly onto DESC ISR v3, which extends rather than replaces ISO 27001:2022, and onto the recurring assessment cadence NESA expects.
Every market position we hold, with the legal reason and the transfer mechanism, is on where we work.
Choose this if...
Honest about who this is for.
This will be a fit.
- You already hold ISO 27001 certification or a SOC 2 report
- You want the mandatory internal audit and management review run properly
- You want control drift found in month three, not month eleven
- You accept that decision and risk-acceptance authority stays with you
Honestly — not our zone.
- —You want a vCISO or a named security leader — that is a different purchase and we do not sell it
- —You want monitoring, detection or a response SLA. This retainer carries none
- —You are not yet certified. Start with a Compliance Readiness Assessment instead
- —You want us to accept the residual risk. We track and advise; we never ensure
Common questions, straight answers.
One contract covers any of these.
Everything below runs on the same agreement, the same invoice and the same account team as Compliance Programme Retainer.
Compliance Readiness Assessment
A fixed-fee assessment of where you actually stand against SOC 2 or ISO 27001:2022, ending in a costed, sequenced remediation plan and a warm introduction to an auditor. We are not your auditor and legally cannot be — which is exactly why we can do this work.
Compliance Remediation Pod
Your platform lists eighty failing controls and your auditor is legally not allowed to close any of them. We put a security pod on the backlog — IAM, logging, encryption, cloud configuration, CI/CD hardening — and hand your auditor working evidence in the format they ask for.
Agentic AI Development
Custom AI agents, LLM integrations, RAG pipelines, and intelligent automation built into your product. On the Secure Build tier, every agent ships with a threat model, tool-permission scoping, guardrails, and an adversarial eval suite running in your CI.
Direct Hire
We source, vet, and shortlist senior engineers from a 100,000+ pool. You interview, offer, and own the employment.
Managed Growth
The whole digital operation for a business people physically visit — website built and maintained, SEO, AEO, GEO, Google Ads, email, campaigns, lead gen, and the automations behind them. One team, one fee, and ad spend passed through to the platforms at cost.
Graphic & Design Services
Brand systems, marketing collateral, and design-on-demand for product, social, and sales.































