Audit Preparation · 14 March 2025 · 6 min read
Preparing for SOC 2 Type II: A Practical Timeline
Most organisations underestimate how long the observation period alone takes. We walk through a realistic 26-week timeline from scoping and control design through the Type II observation window, common causes of delay, and how to brief stakeholders on each phase.
Read more
Regulatory Compliance · 2 February 2025 · 5 min read
GDPR and the Third-Party Risk Blind Spot
Data protection impact assessments frequently stop at the organisation's own systems, leaving vendor and sub-processor exposure unexamined. This briefing sets out a practical approach to extending your GDPR programme across the full supply chain without duplicating existing vendor risk work.
Read more
ISO 27001 · 19 November 2024 · 7 min read
Annex A Controls: Where Firms Lose the Most Audit Points
Drawing on recurring findings across our certification support engagements, we outline the Annex A control families that most often produce nonconformities — and the low-cost process changes that resolve them well before the certification body arrives.
Read more
Governance · 8 September 2024 · 4 min read
What Boards Actually Want From IT Risk Reporting
Technical risk registers rarely translate well into boardroom decisions. We share a reporting structure, tested across several client committees, that surfaces the risk exposure directors need without burying it in control-level detail.
Read more
Regulatory Compliance · 22 May 2024 · 6 min read
Operational Resilience and Outsourced IT: A Compliance Checklist
Regulatory expectations around critical outsourcing continue to tighten. This checklist covers the due diligence, contractual provisions and exit-planning documentation supervisors most commonly ask to review during operational resilience assessments.
Read more