The five steps
The effort in each step depends on your standard, the size of your organisation and how much of your system is already in place — but the path is the same.
01 — Discovery & Scope Definition
We understand your business, customer requirements, applicable standards, certification goals and timelines to define the right compliance roadmap.
It starts with a scoping conversation: what your organisation does, which customers or tenders are driving the need, which standard or framework fits, how many sites are involved and how complex your operations are. Where more than one standard applies, we look at whether an integrated approach will save effort. From that, we send a fixed-price proposal within 24 hours setting out the scope and approach. Nothing else begins until you are comfortable with the scope and cost. You'll provide: a basic picture of your business, sites, customer requirements and any existing certifications.
02 — Gap Assessment & Roadmap
We assess your current systems, controls and documentation against the selected standard and identify priorities, gaps and required actions.
We work through the standard requirement by requirement and build a clear picture of what already works, what needs strengthening and what is missing. You get a prioritised roadmap of actions rather than a list of complaints. This step is deliberately thorough, so significant weaknesses surface early rather than during the formal audit, and it can usually be carried out remotely. You'll provide: access to existing policies, procedures and records, and to the people who run the processes.
03 — Implementation & Control Strengthening
Our consultants help develop and implement practical policies, processes, controls and evidence aligned with your actual business operations.
We work alongside your team to close the gaps — building or reshaping the management system, drafting the policies and procedures that are genuinely missing, strengthening controls, and making sure the evidence the standard expects is actually produced. Everything is shaped around how your business already runs, so the system is practical to operate rather than a set of documents on a shelf. We also train the people who operate it day to day. You'll provide: the people who own the processes, and the time for them to embed the changes.
04 — Audit Readiness & Pre-Assessment
We review implementation, verify evidence, conduct readiness checks and help your team prepare confidently for the independent certification or attestation audit.
Before the formal audit, we check that the system is working as intended. We review implementation, verify that the evidence is complete, and help you run internal audits and a management review where the standard requires them, so the system has a track record of operating. A readiness check approached the way an auditor would approach it highlights anything still to close, and we brief your team on the questions and evidence requests to expect. You'll provide: records that show the system operating, and the people who will speak to the auditor.
05 — Independent Audit & Certification Support
We coordinate and support you through the independent assessment process, help address audit findings and guide you through to successful completion.
Your certification body — or, for attestations such as SOC 2, a licensed CPA firm — carries out the independent assessment. For ISO management systems this normally happens in two stages: Stage 1 reviews whether the system is documented and ready, and Stage 2 assesses whether it is genuinely implemented and effective, through interviews, records and observation. We coordinate with you through the process and stay available throughout; if findings are raised, we help you plan and evidence the corrective action through to successful completion. You'll provide: records and people who can show the system working day to day.