Senior compliance, risk and resilience practitioners for complex, accountable organisations. Information security, business continuity, quality, environmental, health and safety, AI governance, Cyber Essentials and data protection, run as one working system rather than a shelf of certificates.
What a certificate tells you
Every requirement is assessed on how well it actually operates. Gaps surface before the auditor finds them, and the board gets a straight answer when it asks.
The certificate is on the wall and the documents exist. But the honest answer to "is it working?" is that nobody has measured it.
We help organisations move from the second position to the first, and stay there, whatever the standard.
Where to start
A review ahead of surveillance or recertification, so there are no surprises on the day.
A breach, an outage or a new threat is in the news, and the board asks "could that be us?" A practitioner-led review answers honestly.
An exercise against your real plans, not a generic scenario.
What it means for your organisation, whether it applies, and what to do first.
Each starts with a conversation, not a proposal. Talk to a practitioner.
The record
Zero major nonconformities across every client audit.

Global real estate services
ISO 27001, 22301, 9001, 14001, 45001Four-plus years. A business continuity system the auditor called one of the best she had audited.
Read the story
Sport and data foundation
ISO 27001Zero findings across both surveillance audits, with the system maintained in-house.
Read the story
UK public sector, around 1,000 staff
ISO 22301The board received evidence of validated progress, not recommendations.
Read the story
International law, multi-jurisdiction
ISO 27001, 22301A resilience framework the external auditor specifically noted.
Read the story
UK law firm, established in-house team
ISO 27001Targeted audits and realistic incident testing alongside the in-house team.
Read the story
Further education, multi-campus
ISO 22301Board-approved, site-specific plans, implemented without disrupting teaching.
Read the story
Telecoms, millions of customers
UK GDPRMore than 100 compliance areas, prioritised and closed inside a tight window.
Read the story
Hospitality, around 2,700 locations
ISO 22301A tested framework with local guidance and central oversight.
Read the storyProof that it lasts
"This recertification is a testament to our proactive approach to Business Continuity Planning."
Zoe Harris, Director, Head of Compliance, Operations & Facilities, Colliers UK
How we work
Nothing is relearned and nothing slips between audits. The knowledge of your frameworks stays with the people who built and run them alongside you.
Rather than assuming it is. The standards call this effectiveness: whether planned activities are carried out and planned results achieved. It is what the auditor is assessing, and it is what we measure. Every requirement is scored on how well it achieves its purpose, so you can answer the board with evidence rather than reassurance.
Knowledge transfer is built in from the first day, so the system works for you every day, not only when we are in the room.
Whatever the standard, the work falls into five areas.