Compliance and regulation

Internal audit, gap assessment and due diligence

Functionally segregated review for audits, customers, committees and corporate transactions.

What it involves

What we do

We assess the true state of compliance with sound judgement and functional segregation: internal audit of management systems, gap assessment against standards, readiness review before certification and technology due diligence in acquisitions and mergers.

What's included

  • Internal audit for ISO 27001, ISO 22301, ENS and ISO/IEC 42001
  • Gap assessment against NIS2, DORA, CRA and the AI Act
  • Readiness review ahead of certification or inspection
  • Cybersecurity due diligence in corporate transactions
  • Continuity and resilience review
  • Report with findings, risks and action plan

Who it's for

  • Certified organisations that need an independent internal auditor
  • Funds and buyers in M&A processes
  • Entities preparing for an inspection or external audit

Deliverables

  • Audit report
  • Findings and risk matrix
  • Prioritised action plan

Reference frameworks and standards

ISO 19011ISO 27001ISO 22301ENSISO/IEC 42001

Reference frameworks used to design, implement, review and evidence. They are not presented as our own certifications unless contractually applicable.

How we approach it

  1. DiscoverWe get to know your business, environment, risks and priorities.
  2. AnalyseWe assess maturity, exposure, compliance and real capabilities.
  3. DesignWe define strategy, roadmap, architecture and action plan.
  4. ImplementWe deliver controls, processes, technology and evidence.
  5. OperateWe monitor, respond and support continuous improvement.
  6. OptimiseWe measure results, reduce risk and evolve capabilities.

Let's talk

Does Internal audit, gap assessment and due diligence fit your situation?

Tell us about your challenges and let's design together the best strategy to protect and strengthen your business.