Compliance Advisory
ISO 27001/27701, RBI NBFC mappings, SOC 2 readiness, PCI DSS scoping — delivered with playbooks, evidence, and audit handover.
Where we help
ISO 27001 ISMS build
Scope, risk & SoA, policies, internal audit
ISO 27701 & Privacy
DPIAs, data maps, processor controls
RBI NBFC
RBI↔ISO mapping, VA/PT cadence, audit prep
PCI DSS scoping
Data flows, scope reduction, logging/retention
Third-party risk? See V-ROC.
How we work
- Step 1Discover & scopeSystems, data, locations
- Step 2Assess gapsDesign & operating effectiveness
- Step 3RemediatePolicies, controls, tooling
- Step 4Implement & evidenceArtifacts, KRIs, dashboards
- Step 5Internal audit / readinessDry run before audit
- Step 6Audit handoverSupport up to certification
Typical SOC 2 Type 1 readiness: ~30–45 days (organisation-dependent).
What you’ll get
- Policy set & Statement of Applicability
- Risk register, KRIs & dashboards
- Control matrix & framework mappings
- Evidence pack templates
- Runbooks & onboarding checklists
- Executive summary & roadmap
Packages
FAQs
Can you work with our auditor?
Yes — including our CPA partner for SOC 2, or your existing auditor.
Do you sign NDAs?
Yes — same-day in most cases. Email us and we’ll countersign promptly.
Can we start with a gap assessment only?
Yes — fixed-scope gap assessments are available and can roll into remediation.
Do you provide policies?
Yes — tailored policy sets mapped to control objectives and your environment.
How do you handle multi-framework mapping?
We maintain a common control library across frameworks to minimise duplicate work.
Related services
NDA friendly. Serving NZ, Australia, India & the Pacific.