SUSTAIN
Keep the certificate current without hiring for it.
A managed retainer covering certification renewals, surveillance audit support, governance upkeep, and enterprise security questionnaire responses. For certified organisations without an internal compliance hire.
From £1,450 per month
THE ENGAGEMENT
Certification is an operating obligation, not a finished project.
The certificate arrives and the programme team disbands. Then the risk register stops being reviewed, policies pass their review dates, management review slips a cycle, and the evidence base that took three months to build goes stale. Management systems decay between audits when nobody owns them, and the decay is only visible when a surveillance auditor arrives or an enterprise buyer sends a two-hundred-question security questionnaire.
The retainer puts a senior practitioner on the obligation. Surveillance audits are prepared for and supported, renewals are managed, the risk register and the policy set are reviewed on an agreed cadence, and management review is prepared and documented so the record exists before the auditor asks for it.
Questionnaires are answered from a maintained evidence base rather than reconstructed each time, which is usually where the largest amount of unplanned internal time disappears. The alternative is a compliance hire at several times the cost, carrying a single point of failure and a recruitment cycle before any of it starts.
DELIVERABLES
What you receive.
Surveillance audit preparation and support each cycle
Certification renewal management
Risk register and policy review on a defined cadence
Management review preparation and documentation
Enterprise security questionnaire responses from a maintained evidence base
Monthly or quarterly governance reporting, agreed at scoping
FIT
Who this is for.
- You are certified and have no dedicated compliance function to keep the system current.
- Enterprise security questionnaires arrive often enough to be a meaningful internal cost.
- You hold more than one certification and the audit calendar has become something to manage.
This is not for organisations with an established internal compliance team. The retainer would duplicate capability you already pay for, and targeted support such as internal audit is the better fit.
WHAT COMES NEXT
Where organisations go from here.
Where independence is the specific gap rather than capacity across the whole cycle, the clause 9.2 internal audit can be taken on its own and is included within the retainer scope where agreed.
ASSURE
ISO 27001 Internal Audit
An independent clause 9.2 internal audit of your ISMS, delivered to certification body evidence standard with nonconformity tracking.
Explore internal auditASSURE
Stage 2 Audit Defence
Not yet certified? Senior practitioner attendance at the certification audit, with findings managed through to closure and certificate issue.
Explore audit defenceQUESTIONS
Common questions.
Certified, and no one owns it?
A 45 minute scoping call establishes your certification portfolio, your questionnaire volume, and the right retainer scope and price. No sales pitch. If an internal hire is the better answer, we will tell you.
Prefer email? Write to info@goldlineconsultancy.co.uk.
