Skip to content
SecuriFii

How we work

A fixed scope, a named date, and no surprises in month three.

Compliance projects overrun for predictable reasons: scope agreed from a questionnaire rather than from evidence, an audit date chosen before anyone checked what has to run for six months first, and a consultant who leaves once the documents are written. Our model is built around those three failures.

What we commit to

  • We scope from evidence, not from a form

    Before a proposal exists we look at your actual systems, contracts and obligations. A scope derived from a self-assessment questionnaire is a guess, and the correction always lands as a change request halfway through.

  • The date is set backwards from the audit

    Some controls have to be seen operating before they can be tested. We plan from the certification body's or auditor's calendar backwards, so the date we give you is one the evidence can support.

  • We build with your team, not beside it

    A management system maintained by a consultancy fails its first surveillance audit after the consultancy leaves. Your people own the controls from the start; we are there to make that ownership possible.

  • One practitioner owns your engagement

    You get a named lead who is doing the work, not a manager relaying it. When you ask a question about a control, you are answered by the person who implemented it.

  • We tell you when the answer is no

    If a deadline is not reachable, or a scope is larger than it needs to be, or you do not need the service you asked for, we say so before you commit — not in a status report.

The shape of an engagement

Durations are indicative for an organisation of under 200 people with a contained scope. We give you real figures once we have seen the estate.

  1. 01Discovery1–2 weeksWe look at your systems, contracts, obligations and current state. You get a written scope, a fixed price and a schedule with an audit date on it. This is chargeable and is deducted from the engagement if you proceed.
  2. 02Assessment2–4 weeksA full gap assessment against the standard, with a register of every gap, its owner and the effort to close it. Nothing here is a surprise later.
  3. 03Build2–5 monthsRisk assessment, controls, documentation and training, implemented alongside your teams. Progress is visible weekly against the gap register.
  4. 04Operate and evidence1–6 monthsControls run and produce evidence. For SOC 2 Type 2 this is the observation period; for ISO it is the run-up that makes Stage 2 testable. We monitor for lapses while they are still fixable.
  5. 05Audit2–6 weeksInternal audit, management review, rehearsal, then support through the external assessment and closure of anything it raises.
  6. 06Sustainongoing, optionalSurveillance audits, annual risk reassessment, internal audit cycle and retesting. Some clients take this on themselves, which is a good outcome.

What we will not do

These are not modesty. Two are barred by the standards themselves, and the rest are things that would make our work worth less to you.

  • Issue a certificate, sign an attestation, or act as your certification body — ISO/IEC 17021-1 bars an organisation from assessing a management system it helped build.
  • Audit an engagement we delivered, in any capacity that presents itself as independent.
  • Promise you will pass. The assessment is somebody else's independent judgement, and a consultancy that promises the outcome is claiming influence it should not have.
  • Write documentation for a system nobody operates. A policy set produced to pass an audit will fail the surveillance audit a year later.
  • Test an asset you cannot demonstrate authority over.

Latest insights

Tell us the deadline you are working to.