Mandate

What the practice exists to do.

Four mandates structure every engagement. Each is measurable, each is named on the engagement letter, and each must close before the engagement does.

01
Implementation

Build management systems that pass certification.

End-to-end ISMS, BCMS and PCI DSS programs — designed, documented, and walked through the certification audit. No shelfware policies; every control has an operator and an evidence trail.

02
Audit

Run the internal audit before the external one does.

Internal audit, surveillance preparation and gap closure. The aim is a certification audit where the certifier finds nothing the practice has not already documented and remediated.

03
Governance

Govern VAPT, vendor risk, and incident response.

SLA-driven remediation tracking on high / critical findings. Third-party risk registers, vendor security assessments, and incident investigation workflows wired to the board audit committee.

04
Assurance

Brief the regulator, the board, the customer.

Executive dashboards for the board audit committee. Regulator-facing evidence packs for IRDAI, RBI and PCI DSS QSAs. Customer due-diligence responses on standardised questionnaires.

Methodology

Five phases. Every engagement.

The practice does not improvise. Every engagement runs the same five-phase playbook — adapted to the framework, but not skipped.

PHASE 01

Gap assessment

Current-state diagnostic against the target framework. Gap log, prioritised.

PHASE 02

Design

Policy & SOP framework, risk register, control architecture, RACI.

PHASE 03

Implementation

Operationalise controls, evidence capture, awareness rollout, tabletop drills.

PHASE 04

Internal audit

Pre-certification audit, NC closure log, evidence walk-through with auditor.

PHASE 05

Surveillance

Annual surveillance, recertification support, continuous improvement log.

Credentials

Eight accreditations. All current.

The accreditation set covers the major frameworks ComplyGeek's clients are audited against. Originals available on request.

CISA ISO 27001:2022 Lead Auditor ISO 22301 Lead Auditor PCI DSS IRDAI Cyber Security Audit CEH ITGC Google Hall of Fame

The practice runs on a small number of named engagements.