Audits & Questionnaires

An audit finding or a client questionnaire — and nobody inside owns the answer.

Both start the same way: something external is asking a question your team cannot answer alone, and a deal or a deadline is waiting on it.

We answer the questionnaire or the audit finding with evidence, then close the gaps it turns up — against Loi 25, SOC 2 or ISO 27001, whichever one is asking.

You get: A prioritised list of what is missing

01

Assess

  • The finding, the questionnaire or the obligation, read line by line
  • What controls actually exist today, not what the policy claims
  • The gap between the two, against Loi 25, SOC 2 or ISO 27001

How it runs

  • Discovery call — what arrived, and who is asking
  • Gap review against the framework in play
  • A prioritised list of what is missing
02

Report

  • Answers to every question, with the evidence behind each one
  • A written gap analysis against the framework in play
  • A remediation plan, ranked by what the finding actually requires

How it runs

  • Evidence gathered from what already exists, not recreated from scratch
  • Drafted, then reviewed with you before it goes out
  • Delivered in the format the auditor or client asked for
03

Implement

  • The controls the finding or the questionnaire called out as missing
  • Evidence that holds up when someone actually asks for it
  • Documentation kept current, not written once and left

How it runs

  • Fixes scoped and built with your team, not handed over as a list
  • Evidence pack organised the way an auditor expects to see it
  • Handover once the gaps are closed

An audit finding, a questionnaire, or a Loi 25 question sitting on someone's desk?

Tell us what arrived and we will scope the right engagement with you. Or start with the free evaluation — sixty minutes, and a written read on which domains deserve a real look. We reply within one business day.