Audits & Questionnaires
An audit finding or a client questionnaire — and nobody inside owns the answer.
Both start the same way: something external is asking a question your team cannot answer alone, and a deal or a deadline is waiting on it.
We answer the questionnaire or the audit finding with evidence, then close the gaps it turns up — against Loi 25, SOC 2 or ISO 27001, whichever one is asking.
You get: A prioritised list of what is missing
01
Assess
- The finding, the questionnaire or the obligation, read line by line
- What controls actually exist today, not what the policy claims
- The gap between the two, against Loi 25, SOC 2 or ISO 27001
How it runs
- Discovery call — what arrived, and who is asking
- Gap review against the framework in play
- A prioritised list of what is missing
02
Report
- Answers to every question, with the evidence behind each one
- A written gap analysis against the framework in play
- A remediation plan, ranked by what the finding actually requires
How it runs
- Evidence gathered from what already exists, not recreated from scratch
- Drafted, then reviewed with you before it goes out
- Delivered in the format the auditor or client asked for
03
Implement
- The controls the finding or the questionnaire called out as missing
- Evidence that holds up when someone actually asks for it
- Documentation kept current, not written once and left
How it runs
- Fixes scoped and built with your team, not handed over as a list
- Evidence pack organised the way an auditor expects to see it
- Handover once the gaps are closed
An audit finding, a questionnaire, or a Loi 25 question sitting on someone's desk?
Tell us what arrived and we will scope the right engagement with you. Or start with the free evaluation — sixty minutes, and a written read on which domains deserve a real look. We reply within one business day.