Skip to main content

FOR ORGANISATIONS ALREADY ON A COMPLIANCE PLATFORM

The platform is running. The audit is not getting closer.

Vanta, Drata, Sprinto, Thoropass or another. They collect evidence and monitor controls continuously, and they do that well. What none of them does is decide your scope, write a Statement of Applicability an auditor will accept, run your clause 9.2 internal audit, or sit in the room at Stage 2. Where those are missing, the platform shows green and the audit still fails.

Delivered by

ISO 42001 Lead Implementer (PECB)
ISO 42001 Lead Auditor (PECB)
ISO 27001 Senior Lead Implementer (PECB)
ISO 27001 Lead Auditor (PECB)
CISSP
Currently accepting platform rescue engagements
Open the booking calendar

Free 45 minute diagnostic. Bring the trust page, the questionnaire or the auditor's finding.

Book the Free DiagnosticSame-week availability

Loading the calendar

Open the booking page

Calendar not loading? Open Calendly directly

Already mid-certification? That is the most useful time to look.

info@goldlineconsultancy.co.uk
  • One practitioner

    who reads your configuration, not a summary of it

  • Fixed fee

    agreed once the scope is actually known

  • A written route to Stage 1

    with an owner and a date against every gap

Built for teams who bought the platform and stalled

Find out what is actually missing

The platform reports on the controls it was configured to watch. If the scope was wrong when it was set up, everything downstream is green and wrong with it.

The document the platform will not write

Clause 6.1.3 d) requires a Statement of Applicability recording which controls you decided were necessary and why. That is a judgement about your risk, and no software can make it for you.

An audit that is independent

Clause 9.2 requires auditors selected to ensure objectivity. If the people who configured the platform also audit it, the requirement is not met, and a certification body checks.

Someone in the room at Stage 2

The auditor will ask why a control is in scope and why another is out. Those answers live in the decisions, not in the dashboard.

What this is for

  • The platform was bought months ago and the certification date has not moved.

  • Controls show as passing but nobody can explain what is in scope.

  • Policies came from the template library and have never been read by the people who own them.

  • An auditor has asked a question the platform cannot answer.

What happens

PHASE 01

Scope review

What the management system actually covers, written down, and whether the platform configuration matches it.

PHASE 02

Configuration audit

Which controls are monitored, which are manual, and which are switched on but meaningless.

PHASE 03

Evidence gap register

Every gap with an owner and a date, mapped to the clause or control it fails.

PHASE 04

Route to audit

What has to happen before Stage 1, in what order, and what it will cost.

What you get

  • A written scope statement

  • A platform configuration review

  • A gap register with owners and dates

  • A dated route to Stage 1

Fixed price, confirmed at the free diagnostic.

Frequently asked

Find out what is actually missing

A free diagnostic call with the practitioner who would do the work. Scope, configuration and evidence reviewed before anything is priced.

45 minutes, video, with the practitioner who would do the work. No sales pitch.

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.