How we work
A fixed scope, a named date, and no surprises in month three.
Compliance projects overrun for predictable reasons: scope agreed from a questionnaire rather than from evidence, an audit date chosen before anyone checked what has to run for six months first, and a consultant who leaves once the documents are written. Our model is built around those three failures.
What we commit to
We scope from evidence, not from a form
Before a proposal exists we look at your actual systems, contracts and obligations. A scope derived from a self-assessment questionnaire is a guess, and the correction always lands as a change request halfway through.
The date is set backwards from the audit
Some controls have to be seen operating before they can be tested. We plan from the certification body's or auditor's calendar backwards, so the date we give you is one the evidence can support.
We build with your team, not beside it
A management system maintained by a consultancy fails its first surveillance audit after the consultancy leaves. Your people own the controls from the start; we are there to make that ownership possible.
One practitioner owns your engagement
You get a named lead who is doing the work, not a manager relaying it. When you ask a question about a control, you are answered by the person who implemented it.
We tell you when the answer is no
If a deadline is not reachable, or a scope is larger than it needs to be, or you do not need the service you asked for, we say so before you commit — not in a status report.
The shape of an engagement
Durations are indicative for an organisation of under 200 people with a contained scope. We give you real figures once we have seen the estate.
- 01Discovery1–2 weeksWe look at your systems, contracts, obligations and current state. You get a written scope, a fixed price and a schedule with an audit date on it. This is chargeable and is deducted from the engagement if you proceed.
- 02Assessment2–4 weeksA full gap assessment against the standard, with a register of every gap, its owner and the effort to close it. Nothing here is a surprise later.
- 03Build2–5 monthsRisk assessment, controls, documentation and training, implemented alongside your teams. Progress is visible weekly against the gap register.
- 04Operate and evidence1–6 monthsControls run and produce evidence. For SOC 2 Type 2 this is the observation period; for ISO it is the run-up that makes Stage 2 testable. We monitor for lapses while they are still fixable.
- 05Audit2–6 weeksInternal audit, management review, rehearsal, then support through the external assessment and closure of anything it raises.
- 06Sustainongoing, optionalSurveillance audits, annual risk reassessment, internal audit cycle and retesting. Some clients take this on themselves, which is a good outcome.
What we will not do
These are not modesty. Two are barred by the standards themselves, and the rest are things that would make our work worth less to you.
- Issue a certificate, sign an attestation, or act as your certification body — ISO/IEC 17021-1 bars an organisation from assessing a management system it helped build.
- Audit an engagement we delivered, in any capacity that presents itself as independent.
- Promise you will pass. The assessment is somebody else's independent judgement, and a consultancy that promises the outcome is claiming influence it should not have.
- Write documentation for a system nobody operates. A policy set produced to pass an audit will fail the surveillance audit a year later.
- Test an asset you cannot demonstrate authority over.
Latest insights
Regulation · India
Is the DPDP Act in force? What applies today, and the deadline that matters
The Act is law today and its obligations bite on 13 May 2027. Penalties reach ₹250 crore, and the work that takes longest is the work nobody has started.
Regulation · EU
Does the GDPR apply to an Indian company? Scope, roles and the EU representative question
Most Indian firms are caught through a contract rather than by a regulator — and most do not need the EU representative they are being sold.
Technical testing
The OWASP Testing Guide, and how to tell a real penetration test from a scan
Two tests can cost the same and cover entirely different ground. The methodology is how you tell, and it is checkable before you pay.