Governance, Risk & Compliance

Certification is the outcome. Control is the point.

Most compliance programmes produce a folder of documents that describe an organisation nobody works in. We build the controls first and let the documentation describe what is actually happening.

ISO 27001 SOC 2 DPDP HIPAA One control set · 31 mapped categories Access review Scan history Change log Training Evidence collected continuously, not before the audit
8Frameworks supported
31Mapped finding categories
LiveEvidence collection
0Spreadsheets required

The certificate is easy. The second year is hard.

Getting certified is a solvable problem. Enough consultants, enough templates and enough time in the month before the audit will get almost anyone through a Stage 2. The difficulty arrives afterwards, when the same evidence has to be produced again, and again, and the person who assembled it the first time has moved on and left a shared drive full of screenshots with no dates on them.

This is why we build for the surveillance audit rather than the certification audit. Controls should produce their own evidence as a by-product of operating — access reviews that log themselves, vulnerability scans that record their own history, change approvals that live in the system where changes actually happen. If evidence has to be assembled by hand, it will be assembled by hand once, badly, in the week before the auditor arrives.

The platform side of this matters more than it sounds. SemperWise One™ maps controls to live signals across ISO 27001, SOC 2, HIPAA, GDPR and DPDP, collects the evidence continuously, and tells you the day a control drifts rather than eleven months later. Our security testing feeds the same register, so a penetration test finding and a control failure are the same object rather than two teams’ separate problems.

Coverage

Frameworks we work in

Most clients need one certification and two or three others satisfied contractually. Controls overlap heavily, so we implement once and map to everything.

ISO 27001:2022

Full ISMS implementation: scoping, gap assessment, risk assessment and treatment, Statement of Applicability, policy set, internal audit, management review, and support through Stage 1 and Stage 2.

SOC 2 Type I and Type II

Readiness against the trust services criteria, control design, evidence preparation and auditor liaison — the standard request from North American enterprise buyers.

DPDP Act 2023

India’s data protection law: consent and notice architecture, data-principal rights workflows, breach notification readiness and Significant Data Fiduciary obligations where they apply.

GDPR

Records of processing, lawful basis, DPIAs, subject-rights handling and cross-border transfer mechanisms for Indian companies serving EU customers.

HIPAA

Security and Privacy Rule readiness for healthcare organisations and their business associates, with technical safeguards actually tested rather than merely asserted.

PCI DSS

Scope reduction and segmentation review, gap assessment against the current version, and the quarterly testing rhythm that keeps it valid.

NIST CSF

Used where a maturity view is more useful than a certificate — common for organisations reporting to a board rather than a regulator.

ISO 42001

AI management systems, for organisations whose enterprise customers have started asking how their AI features are governed.

Approach

How a compliance programme runs

A first ISO 27001 certification typically takes four to nine months depending on starting position and how much of the organisation is in scope.

  1. 01 · Scope

    What is being certified, which entities and systems are included, and what can be legitimately excluded. Getting this right is the single largest lever on cost.

  2. 02 · Gap assessment

    Where you are against where you need to be, with each gap costed in effort rather than listed as a requirement.

  3. 03 · Risk assessment

    A risk register your management team can actually discuss, with treatment decisions recorded and owned.

  4. 04 · Implement

    Controls built and documented, policies written to match how the organisation works, and evidence collection automated wherever the platform can do it.

  5. 05 · Test and audit

    Independent technical testing for the controls that require it, then an internal audit and management review that a certification body will accept.

  6. 06 · Certify and sustain

    Support through the external audit, then continuous monitoring so the surveillance audit is a review rather than a rebuild.

Run against recognised standards

  • ISO/IEC 27001:2022ISMS certification
  • ISO/IEC 27701Privacy extension where required
  • SOC 2AICPA trust services criteria
  • DPDP Act 2023India data protection
  • GDPREU data protection
  • HIPAAUS healthcare
  • PCI DSSCard payments
  • NIST CSFMaturity and risk framework

Deliverables

What you actually receive.

The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.

Gap assessment with costed remediation

Every gap with an effort estimate and an owner, so the programme can be planned rather than discovered.

Complete policy set

Written for your organisation, in language your staff will follow, not a renamed template pack.

Risk register and treatment plan

Live, owned and reviewable — the document auditors examine most closely and clients maintain worst.

Automated evidence collection

Controls monitored continuously in SemperWise One™, with evidence gathered as an artefact of operation.

Internal audit and management review

Run properly, documented properly, and accepted by certification bodies.

Audit support

We are in the room for Stage 1 and Stage 2, and we answer the technical questions so your team does not have to.

Is this for you?

Talk to us if any of these are true.

If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.

Book a scoping call
  • A customer contract requires ISO 27001 or SOC 2 and there is a deadline attached.
  • You process personal data of Indian residents and have not addressed the DPDP Act.
  • You are certified but the surveillance audit is a fire drill every year.
  • You sell to healthcare, banking or government and are being audited by your customers.
  • You have policies nobody reads and controls nobody operates, and you know it.

How we work

Six steps, and no surprises.

The same engagement model applies to every piece of work we take on, so you always know what happens next.

01

Scope

A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.

02

Authorise

Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.

03

Test

Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.

04

Report

One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.

05

Remediate

A walkthrough call with your engineers. We answer questions on the fix, not just the finding.

06

Retest

A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.

Questions

Compliance & Audit — answered.

The questions clients actually ask during scoping. If yours is not here, ask it directly.

How long does ISO 27001 certification take?

Four to nine months for most organisations, driven by starting position and scope rather than by company size. A company with reasonable IT discipline, a clear scope and an internal owner who can give it real time can be audit-ready in about four months. A company starting from nothing, with a broad scope and no dedicated owner, should plan for nine. The certification body also needs Stage 1 and Stage 2 booked, with a gap between them, which adds calendar time you cannot compress.

What does ISO 27001 certification cost in India?

Two separate costs. The certification body charges its own audit fee, which depends on scope and headcount and is paid directly to them — we do not mark it up. Our implementation fee depends on how much of the work you can absorb internally: organisations with an existing IT function and an engaged owner pay considerably less than those needing the whole programme delivered. We scope it properly and quote a fixed price rather than an hourly rate that grows.

Can you be both our consultant and our auditor?

No, and nobody legitimate can. The certification audit must be performed by an accredited certification body that is independent of whoever implemented the ISMS. We implement, we run your internal audit, and we support you through the external audit — but the certificate is issued by an independent body, and any firm offering to do both is offering you a worthless certificate.

Do we need ISO 27001 or SOC 2?

It usually depends on who is asking. European, Indian and Middle Eastern enterprise buyers, and most tender processes, ask for ISO 27001. North American technology buyers ask for SOC 2. If you sell to both, start with ISO 27001 — it is a management system, so it gives you the structure — and add SOC 2 afterwards, which is considerably cheaper in that order than the reverse.

What is the DPDP Act and does it apply to us?

The Digital Personal Data Protection Act 2023 is India’s data protection law. It applies to any organisation processing the digital personal data of individuals in India, and to processing outside India where goods or services are offered to people in India. In practice that is almost every business with Indian customers or Indian employees. The obligations centre on consent and notice, data-principal rights, security safeguards, breach notification and additional duties for organisations designated as Significant Data Fiduciaries.

We already have policies. Can you just review them?

Yes, and it is a sensible first step — a gap assessment against your existing documentation costs a fraction of a full programme and tells you honestly how far you are. Be prepared for the common finding: the policies are fine, and nothing described in them is happening. Auditors test the operation of controls, not the existence of documents.

Does compliance make us secure?

No. It makes you consistent, and consistency is a precondition for security, not a substitute for it. A compliant organisation has decided what its controls are and can show they operate. Whether those controls stop a competent attacker is a separate question, which is what testing answers. This is exactly why we do both, and why our testing findings feed the same risk register the compliance programme runs on.

Next step

Get a written scope and a fixed price.

A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.