Skip to main content

ABOUT GOLDLINE

Senior practitioner-led AI governance and information security.

Goldline is a UK consultancy delivering ISO 42001 implementation and ISO 27001 implementation to regulated organisations and AI-enabled scaleups. Founded and delivered by Alfred Obeng, who holds Lead Implementer and Lead Auditor credentials from PECB across both ISO 42001 and ISO 27001.

  • Cyber Essentials Certified
  • JOSCAR Registered
  • Companies House 10901798

Meet the Founder

Alfred Obeng, Founder and Principal Consultant of Goldline Consultancy.

Alfred Obeng

Founder & Principal Consultant

Connect on LinkedIn

Alfred Obeng is the Founder and Principal Consultant of Goldline Consultancy, a UK senior cyber governance practice. A senior practitioner specialising in cyber programme management and governance, Alfred has delivered across UK Defence, Central Government, Automotive, Big Tech, and Regulated Industries for thirteen years. He holds ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, and PMP certifications, and reads an Executive MBA with Artificial Intelligence specialism.

The credential set covers both sides of both standards. Implementer credentials mean the management system is designed to certify. Auditor credentials mean the same system can be tested against the standard the way a certification body will test it. Holding Lead Implementer and Lead Auditor across both ISO 42001 and ISO 27001 is a combination the UK market currently has very few of, and it is why implementation work is built to survive audit rather than to survive the next meeting.

Expertise

Senior practitioner credentials, calibrated to UK regulated markets.

Goldline is led by a senior practitioner holding the credentials UK regulated and defence-adjacent buyers expect. The practice combines structured methodology with the specialist depth required for ISO 27001, ISO 42001, SOC 2, and DCC programme delivery.

  • PECB ISO 42001 Lead Implementer badge

    ISO 42001 Lead Implementer (PECB)

  • PECB ISO 42001 Lead Auditor badge

    ISO 42001 Lead Auditor (PECB)

  • PECB ISO 27001 Senior Lead Implementer badge

    ISO 27001 Senior Lead Implementer (PECB)

  • PECB ISO 27001 Lead Auditor badge

    ISO 27001 Lead Auditor (PECB)

  • CISSP certification badge

    CISSP

  • Project Management Professional (PMP) badge

    PMP

Business credentials

  • Cyber Essentials certified badge

    Cyber Essentials

  • JOSCAR registered supplier badge

    JOSCAR Registered

Credentials maintained through ongoing professional development. Active membership in ISC2 and Project Management Institute.

Practice principles

Senior practitioner delivery

No junior consultant pyramid. Founder-level delivery throughout the engagement, from scoping to certification handover.

Methodology, not bespoke

A nineteen-activity structure across four phases. Predictable phases, audit-ready outputs, no reinvention per client.

AI-accelerated delivery

Proprietary AI tooling accelerates evidence collection, control mapping, and policy drafting where leverage is appropriate. Senior practitioner judgement remains the foundation of every engagement.

Calibrated framework portfolio

Two primary frameworks Goldline delivers as headline programmes: ISO 42001 (AI governance) and ISO 27001 (information security). Additional frameworks are addressed through the overlapping controls in these two management systems, or through partner referrals where the framework is outside Goldline's delivery focus.

What we are not

Goldline does not deliver penetration testing, managed detection and response, generic IT services, or compliance frameworks outside the UK regulated and defence-adjacent specialism. We refer specialist work to specialist partners under independent relationships.

How we work

Scope before delivery.

Every engagement is fixed-scope before we start. No open-ended retainers. No scope creep billed back at day rate. If implementation exposes complexity that materially changes scope, we tell you, and re-quote, before additional work starts.

Founder-led delivery.

The practitioner you meet in discovery is the practitioner delivering the work. No junior hand-off. No body-shop staffing.

Credentials over marketing.

Our positioning is built on SC clearance, active implementer credentials, and delivery history across UK defence, government, and regulated enterprise, not on marketing narrative.

Calibrated for the buyer.

Our copy, our proposals, and our pricing are written for procurement officers, heads of compliance, and programme directors, not for innovation teams.

Where we've delivered

Sector-level summaries of programmes Goldline has led or embedded into. We describe capability and scale rather than name clients; specific engagement references can be shared under NDA on request.

  • UK Defence and MoD

    Classified programme delivery under UK SECRET accreditation. Secure collaboration environments deployed across multiple classified sites. Hybrid cloud transition for end-of-life defence infrastructure.

  • Defence Primes and NATO

    Multinational defence programme delivery across UK, France, and Italy. Secure collaboration platforms, export-control governance, and engineering compliance under NATO defence standards.

  • Central Government

    Cloud and infrastructure transformation for UK departments of state. Data centre exits, Active Directory uplift, and 10,000+ endpoint migrations to Windows 11 and Microsoft Intune. Delivery aligned to NCSC and departmental compliance frameworks.

  • Global Technology

    Cybersecurity and software assurance programmes delivered at global scale. Cross-regional engineering coordination, alignment with enterprise security standards, and AI application risk programmes.

  • Regulated Enterprise

    Azure and AWS migration of mission-critical legacy systems across mid-market and enterprise estates. Privileged Access Management deployment, cloud security uplift, and AI-driven SOC analytics improving incident response.

  • Global Manufacturing

    Global supply chain and warehouse systems transformation across multiple markets. Cross-regional engineering coordination between UK, EMEA, and the Americas, delivering material operational savings.

Capability statement

Two pages covering services, delivery model, accreditations, delivery experience, insurance limits and commercial terms. Written for procurement and supplier onboarding. Enter a work email and the download opens immediately.

PDF, 2 pages, August 2026. One email address, nothing else. We use it to follow up on the enquiry only.

More detail on the capability statement page.

How engagements are actually run is set out on the delivery methodology page.

Ready to scope an engagement?

Discuss your ISO 27001, ISO 42001, SOC 2, DCC, or GDPR programme. All engagements begin with a structured diagnostic call, not a commitment.

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.