ISO 27001 certification as a condition of institutional due diligence
- Service:
- Security & Compliance
- Duration:
- 6 months
Challenge
An institutional partner demanded evidence of a working information security management system, while internal policies were scattered and had never been audited.
What we did
- Gap analysis across every ISO/IEC 27001 clause and Annex A control
- ISMS scope, risk register, and Statement of Applicability
- Implementation support alongside the internal IT and compliance teams
- Internal audit and management review ahead of the certification audit
Outcome
- ISMS documentation centralised and consistent across business units
- Passed Stage 1 and Stage 2 audits with an independent certification body
- Security evidence requests answered from a single prepared pack






