Skip to main content

Services

Compliance Audit

A written picture of where you stand — and what to fix first.

Most organisations reach a compliance audit because something forced the question: a new contract, an investor's due diligence, a near-miss incident, or a regulatory enquiry. The audit exists to give you the honest picture before someone else does.

What you get

£8,500 fixed, 2–3 weeks end to end. Scales to £15,000 for multi-site groups or more complex, multi-framework estates — confirmed at the scoping call before we quote the higher figure. No markup on any infrastructure named in the roadmap.

  • Written gap analysisA clear, framework-mapped assessment of your current posture against each in-scope framework. Not a checklist. An honest account of what is missing, what is partial, and what is done.
  • Risk registerGaps ranked by likelihood and impact. You see which ones matter most, not just a list of everything that could be better.
  • Prioritised remediation planA sequenced list of actions, with rough effort estimates. You know what to fix first and approximately how much work each fix involves.
  • Regulator-ready documentationStructured outputs that can be presented to an auditor, DPO, or compliance function without additional translation work. Where a control is in place, we document the evidence. Where it is not, we document the gap and the remediation path.
  • Debrief sessionA 60-minute session to walk through findings, answer questions, and confirm priorities. Results do not sit in a PDF.

Process

  1. 1

    Scoping call (30 minutes)

    We agree which frameworks are in scope, what access we need, and what the deadline is.

  2. 2

    Evidence gathering (1–2 weeks, depending on scope)

    We review documentation, configuration, policies, contracts, and technical controls. We ask specific questions. We do not rely on self-assessment alone.

  3. 3

    Draft report

    Delivered for review before finalisation. You can correct factual errors.

  4. 4

    Final report and debrief

    Signed off and ready to use.

When it is the right fit

You should book a scoping call if:

  • A client, insurer, or investor has asked for evidence of your compliance posture and you do not have a clear answer ready.
  • You are preparing for ISO 27001 certification or Cyber Essentials Plus and need to understand the gap before engaging a certification body.
  • You are about to process a new category of personal data (healthcare records, financial data, children's data) and need to assess whether your current controls are adequate.
  • A data breach or near-miss has raised internal questions about your posture and you need an independent assessment.

Regulatory frameworks covered

Audits are scoped per engagement. Frameworks we cover:

  • UK GDPR / EU GDPREnforced by the ICO under the UK Data Protection Act 2018; EU equivalent under Regulation 2016/679.
  • Cyber Essentials / Cyber Essentials PlusNCSC scheme; mandatory for UK government contracts.
  • ISO 27001:2022International information security management standard.
  • SOC 2 Type I / Type IIAICPA trust services criteria; common requirement for US-connected clients.
  • NIS2 DirectiveEU network and information security directive; applies from October 2024.
  • DORA (Digital Operational Resilience Act)EU financial sector; applies from January 2025.
  • DSPT (Data Security and Protection Toolkit)NHS England requirement for suppliers handling NHS patient data.

Not every organisation needs every framework. The scoping call determines which are relevant to your situation.

Book a scoping call

30 minutes. No obligation. We will tell you if it is not a fit.

Book a scoping call
Global infrastructure·Your data, never ours·AI and infrastructure you control·GDPR by design