Governance, Risk & Compliance

You do not want a readiness project. You want the certificate.

Most compliance engagements sell you readiness and then leave. You are ready, the audit is somebody else's problem, and six months later the evidence has gone stale. This is the whole thing, run for you, on a subscription.

ISO 27001 SOC 2 DPDP HIPAA One control set · 31 mapped categories Access review Scan history Change log Training Evidence collected continuously, not before the audit
End to endGap to audit
IncludedSemperWise One™
MultiFramework from one control set
OngoingNot a project that ends

Why readiness projects disappoint

A readiness engagement produces documents. A gap assessment, a risk register, a policy set, a Statement of Applicability, and a list of things to do. All of it correct, all of it delivered, and none of it self-maintaining. The consultant leaves, the client discovers that the evidence has to be collected by somebody every quarter, and by month nine the programme is a folder nobody has opened.

The second disappointment is the handover to the audit. Readiness and certification are usually bought separately, which means the moment of maximum confusion — the first contact with the certification body, the scope definition, the Stage 1 findings — is the moment nobody is accountable for. A great deal of the pain in a first certification is concentrated in exactly that gap.

So this is sold as one thing, on a subscription: the programme, the platform that keeps it alive, the testing evidence behind the technical controls, and the coordination through Stage 1 and Stage 2 to the certificate. It does not end when you are ready, because being ready is not the thing you wanted.

Coverage

What is included

The work, the platform and the audit coordination, as one subscription.

Gap assessment and scope definition

What applies, what does not, and why. Getting the scope right is the single highest-leverage decision in any certification, and the one most often rushed.

Control implementation

Working through the controls with the people who own them, in SemperWise One rather than in a spreadsheet, so state and evidence live in the same place as the work.

Policy set, drafted and maintained

Adapted to how you actually operate. A policy set nobody has adapted reads exactly like a policy set nobody has adapted, and assessors notice.

Evidence, collected on a cycle

Access records, policy register, audit trail, processors, consents — gathered automatically where the platform can, chased where it cannot, and dated either way.

The testing evidence

Penetration testing and vulnerability management behind the technical controls, run by us, mapped to the clauses they evidence. Most compliance providers subcontract this.

Internal audit and management review

Run properly, minuted, and tracked to closure — the parts of the standard that are easiest to do badly and most visible when you do.

Audit coordination

Managing the process with the certification body you appoint, through Stage 1 and Stage 2, and handling findings to closure.

Surveillance, afterwards

The programme keeps running. A certificate is maintained, not achieved — and the surveillance audit is where an unmaintained one falls over.

Approach

How it runs

Typical first certification. The timeline depends on your starting point, which the gap assessment establishes.

  1. 01 · Scope and gap assessment

    What is in scope, where you stand against it, and a plan with owners and dates.

  2. 02 · Build

    Controls, policies, risk treatment and the evidence routine — set up so it keeps running without us.

  3. 03 · Operate

    The standard requires evidence of controls operating over a period. This is that period, and it is why certification cannot be compressed indefinitely.

  4. 04 · Internal audit and management review

    Before the external audit finds them, we do.

  5. 05 · Stage 1 and Stage 2

    Coordinated with your certification body, with us in the room and findings closed against a plan.

  6. 06 · Maintain

    Surveillance, re-certification, and the programme carrying on between them.

Deliverables

What you actually receive.

The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.

A live compliance programme

Controls, owners, test dates and dated evidence in SemperWise One — not a folder of documents.

The full document set

Policies, Statement of Applicability, risk treatment plan, internal audit records and management review minutes.

Testing evidence

Assessment reports behind the technical controls, with findings tracked to closure and retested.

Audit support

Coordination with your certification body through both stages, and findings closed against a plan.

A programme that survives us

Set up so your team can run it. A dependency on your consultant is not a compliance programme.

Is this for you?

Talk to us if any of these are true.

If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.

Book a scoping call
  • A customer has made certification a condition of the contract.
  • You have no compliance function and no intention of building one this year.
  • A previous readiness project delivered documents and stopped.
  • You need more than one framework and do not want to run two programmes.
  • Your certificate is due for surveillance and the evidence has gone quiet.

How we work

Six steps, and no surprises.

The same engagement model applies to every piece of work we take on, so you always know what happens next.

01

Scope

A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.

02

Authorise

Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.

03

Test

Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.

04

Report

One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.

05

Remediate

A walkthrough call with your engineers. We answer questions on the fix, not just the finding.

06

Retest

A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.

Questions

Compliance as a Service — answered.

The questions clients actually ask during scoping. If yours is not here, ask it directly.

Do you issue the certificate?

No, and nobody selling you consultancy can. ISO 27001 certificates are issued by accredited certification bodies, a SOC 2 report is issued by a licensed CPA firm, and a PCI assessment is signed by a QSA. Those are independent parties and the independence is the entire point of the certificate. We run the programme, produce the evidence and manage the process with them — and we say this plainly because a provider who is vague about it is telling you something.

Do you have certification bodies you work with?

We coordinate with whichever body you appoint, and we can introduce you to accredited ones if you have not chosen. We do not resell audits or take a commission on them, and we would be cautious of anybody who does — a provider with a financial interest in which body assesses you has an interest that is not yours.

How long does a first certification take?

It depends almost entirely on where you start, which is what the gap assessment is for. The constraint that cannot be compressed is that the standard requires evidence of controls operating over a period, so an organisation starting from nothing should plan in months rather than weeks. Anybody quoting a fixed timeline before looking at your environment is quoting a sales number.

What if we only want part of this?

That is normal, and most engagements are. Some clients have a compliance lead and want the platform and the testing evidence. Others want the whole thing. The gap assessment is a sensible first step either way, because it tells both of us what is actually needed.

Can you do more than one framework at once?

Yes, and it is much cheaper than doing them in sequence. The platform holds one normalised control set behind every framework, so a control implemented for ISO 27001 evidences the equivalent clause in SOC 2, DPDP, SEBI CSCRF or IRDAI without being implemented again. The second framework is a mapping exercise rather than a second programme.

What happens after we are certified?

The programme keeps running — that is the difference between this and a readiness project. Evidence keeps being collected and keeps expiring on schedule, controls keep being tested, and the surveillance audit finds a maintained programme rather than a reconstructed one. Reconstructing a year of evidence in the fortnight before surveillance is the single most common way a certificate becomes a problem.

Next step

Get a written scope and a fixed price.

A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.