Skip to main content

CYBER · AI · ASSURANCE · UK · START-UPS · DEFENCE

Your customer wants ISO 27001 or ISO 42001 before they'll sign. We get the security right first.

The controls go in properly and the certificate follows. You come out more secure, not just certified.

A free 45 minute diagnostic with a senior practitioner. No pitch.

ISO 42001 Lead Implementer and Lead Auditor, ISO 27001 Senior Lead Implementer and Lead Auditor, CISSP.

WHO WE WORK WITH

Where are you?

Early stage

A customer has asked for a certificate and the deal is waiting.

  • A named customer is waiting on a certificate.
  • No security lead, so the founder or first engineer owns it.
  • A platform may already be bought, with nobody sure what it misses.
Start here

Scaling

More than one framework, a platform running, and clause 9.2 due.

  • Two frameworks live, with control sets that overlap.
  • A compliance lead, but no separate audit function.
  • Clause 9.2 due on a system your own team built.
Start here

Established

Multiple entities, an approaching Stage 2, AI entering scope.

  • Several entities or regions inside one scope.
  • Findings still open with Stage 2 approaching.
  • AI systems entering scope with no framework decided.
Start here

99%

96%

90%

Cisco 2025 Data Privacy Benchmark Study. 2,600+ security and privacy professionals across 12 countries, surveyed autumn 2024.

OUR THREE PROGRAMMES

Three fixed-scope programmes, senior practitioner led.

Every engagement lands the same way: senior practitioner-led, with the timeline calibrated at scoping. Choose the programme that fits your primary regulatory or commercial pressure.

AI GOVERNANCE

ISO 42001 AI management system.

For regulated UK organisations and AI-enabled scaleups facing investor diligence, EU AI Act pressure, or procurement questions on AI governance. Delivered on your GRC platform of choice, or ours.

The sequence is fixed. Your timeline is set at the free diagnostic.

  • Full AI Management System implementation
  • EU AI Act risk classification and readiness
  • UKAS-accredited certification body coordination
Explore the ISO 42001 Sprint

INTEGRATED

ISO 42001 and ISO 27001 together.

One scope, one set of evidence, one audit window. For organisations facing both an AI governance question and an information security gate at the same time.

The sequence is fixed. Your timeline is set at the free diagnostic.

  • A single integrated management system covering both standards
  • One Statement of Applicability and one AI risk framework built together
  • Roughly a fifth less than running the two programmes separately
Explore the Integrated Sprint

INFORMATION SECURITY

ISO 27001 information security management system.

For regulated UK organisations and AI-enabled scaleups whose enterprise pipeline is paused on ISO 27001. Delivered on your GRC platform of choice, or ours.

The sequence is fixed. Your timeline is set at the free diagnostic.

  • Full information security management system implementation
  • Statement of Applicability aligned to your operating environment
  • UKAS-accredited certification body coordination
Explore the ISO 27001 Sprint

HOW IT RUNS

What actually happens, phase by phase.

Most consultancies publish a timeline and nothing inside it. Here is the whole shape, phase by phase, so you can compare it against anyone else's before you commit.

Before Phase 1: a free 45 minute diagnostic with a senior practitioner. You leave with a written note the same day, yours to keep whether or not you buy anything.

  1. PHASE 01

    Scope and gap

    The scope boundary is fixed and written down, because scope decides the cost of everything after it. Every control is assessed against where you actually are, not where a template assumes you are.

    You get: a gap register with an owner and a date on every line, and a drafted Statement of Applicability.

  2. PHASE 02

    Build

    Policies, procedures and the records that evidence them, built on your GRC platform or ours. A weekly working session with the people who will own each control. Nothing gets written that nobody will maintain.

    You get: policies, procedures and the records that evidence them.

  3. PHASE 03

    Evidence and internal audit

    The clause 9.2 internal audit and the clause 9.3 management review both have to happen before Stage 2, and neither can be back-dated. Where Goldline implemented the system, the internal audit is run independently and not by us. We tell you exactly what it has to cover and make sure the evidence exists.

    You get: the clause 9.2 internal audit and the clause 9.3 management review, completed and evidenced.

  4. PHASE 04

    Stage 1 and audit defence

    The certification body reviews your documentation at Stage 1. Findings are closed before Stage 2 rather than after it. A senior practitioner is in the room for both.

    You get: Stage 1 findings closed before Stage 2, with a senior practitioner in the room.

After certification. Managed compliance: surveillance audits, the annual cycle, questionnaire responses and governance upkeep. Priced separately, and only if you want it.

Why we do not audit our own work

An accredited certification body issues the certificate and a separate party should test the system. Goldline does not perform a clause 9.2 internal audit on a management system Goldline implemented, and does not sell implementation and certification to the same organisation for the same scope. It costs us a line of revenue and it is the right way round.

Your diagnostic sets the length of your programme, and the shape above is typical rather than a commitment. Readiness assessments credit in full against a subsequent Sprint. Certification body audit fees are billed separately and pass through at cost. GRC platform subscriptions are billed separately; where Goldline supplies the platform as a partner, the price is confirmed in writing before purchase and you are free to buy direct instead.

  • PECB ISO 42001 Lead Implementer badge
    ISO 42001 Lead Implementer
  • PECB ISO 42001 Lead Auditor badge
    ISO 42001 Lead Auditor
  • PECB ISO 27001 Senior Lead Implementer badge
    ISO 27001 Senior Lead Implementer
  • PECB ISO 27001 Lead Auditor badge
    ISO 27001 Lead Auditor
  • Cyber Essentials certified badge (IASME-issued)
    Cyber Essentials
  • IASME Cyber Assurance Level One certified badge
    IASME Cyber Assurance L1
  • IASME Quality Principles certified badge
    IASME Quality Principles
  • JOSCAR Registered supplier badge
    JOSCAR Registered
  • Bloom
    Bloom Accredited Supplier
  • Crown Commercial Service Supplier badge
    Crown Commercial Service Supplier

Goldline Consultancy Ltd · Companies House 10901798

FREE TOOL

What will ISO 27001 cost you? Four questions, no signup.

An instant price band for the readiness, Guided and Sprint routes, plus an estimate of what your certification body will charge on top.

Open the cost calculator

GRC PLATFORMS

The platform is a tool. Somebody still has to build the system.

A GRC platform automates evidence collection and continuous control monitoring, and it does that well. It does not write your Statement of Applicability, run your risk assessment, or sit in the room at Stage 2. Goldline is a partner across Drata, Thoropass and Sprinto, so the platform and the implementation can be bought together, or you can bring your own.

See our platform and certification partners

Certification body audit fees are billed separately and pass through at cost. GRC platform subscriptions are billed separately; where Goldline supplies the platform as a partner, the price is confirmed in writing before purchase and you are free to buy direct instead.

FREQUENTLY ASKED

Frequently asked.

FRAMEWORKS WE WORK IN

Goldline prepares organisations for assessment. Certificates are issued by accredited certification bodies.

Book the Free Diagnostic.

Senior practitioner conversation about your AI governance or information security programme. ISO 42001, ISO 27001, or both. No sales pitch. No follow-up sequence unless you ask.

Or email info@goldlineconsultancy.co.uk

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.