Services
Compliance Audit
A written picture of where you stand — and what to fix first.
Most organisations reach a compliance audit because something forced the question: a new contract, an investor's due diligence, a near-miss incident, or a regulatory enquiry. The audit exists to give you the honest picture before someone else does.
What you get
£8,500 fixed, 2–3 weeks end to end. Scales to £15,000 for multi-site groups or more complex, multi-framework estates — confirmed at the scoping call before we quote the higher figure. No markup on any infrastructure named in the roadmap.
- Written gap analysis — A clear, framework-mapped assessment of your current posture against each in-scope framework. Not a checklist. An honest account of what is missing, what is partial, and what is done.
- Risk register — Gaps ranked by likelihood and impact. You see which ones matter most, not just a list of everything that could be better.
- Prioritised remediation plan — A sequenced list of actions, with rough effort estimates. You know what to fix first and approximately how much work each fix involves.
- Regulator-ready documentation — Structured outputs that can be presented to an auditor, DPO, or compliance function without additional translation work. Where a control is in place, we document the evidence. Where it is not, we document the gap and the remediation path.
- Debrief session — A 60-minute session to walk through findings, answer questions, and confirm priorities. Results do not sit in a PDF.
Process
- 1
Scoping call (30 minutes)
We agree which frameworks are in scope, what access we need, and what the deadline is.
- 2
Evidence gathering (1–2 weeks, depending on scope)
We review documentation, configuration, policies, contracts, and technical controls. We ask specific questions. We do not rely on self-assessment alone.
- 3
Draft report
Delivered for review before finalisation. You can correct factual errors.
- 4
Final report and debrief
Signed off and ready to use.
When it is the right fit
You should book a scoping call if:
- A client, insurer, or investor has asked for evidence of your compliance posture and you do not have a clear answer ready.
- You are preparing for ISO 27001 certification or Cyber Essentials Plus and need to understand the gap before engaging a certification body.
- You are about to process a new category of personal data (healthcare records, financial data, children's data) and need to assess whether your current controls are adequate.
- A data breach or near-miss has raised internal questions about your posture and you need an independent assessment.
Regulatory frameworks covered
Audits are scoped per engagement. Frameworks we cover:
- UK GDPR / EU GDPR — Enforced by the ICO under the UK Data Protection Act 2018; EU equivalent under Regulation 2016/679.
- Cyber Essentials / Cyber Essentials Plus — NCSC scheme; mandatory for UK government contracts.
- ISO 27001:2022 — International information security management standard.
- SOC 2 Type I / Type II — AICPA trust services criteria; common requirement for US-connected clients.
- NIS2 Directive — EU network and information security directive; applies from October 2024.
- DORA (Digital Operational Resilience Act) — EU financial sector; applies from January 2025.
- DSPT (Data Security and Protection Toolkit) — NHS England requirement for suppliers handling NHS patient data.
Not every organisation needs every framework. The scoping call determines which are relevant to your situation.
Book a scoping call
30 minutes. No obligation. We will tell you if it is not a fit.
Book a scoping call