ISMS & AIMS Audits

ISO 27001 and ISO 42001. Implement it, or audit it.

ISMS (Information Security Management System) and AIMS (AI Management System) are the ISO standards that prove your business is serious. We work either side of the line: building the management system, documentation and evidence trail, or auditing a system somebody else built. What we will not do is both on the same system, because an audit is only worth something if the person running it had no hand in the thing being audited.

ISMS is the established one. AIMS is the one almost nobody's ready for yet.

ISO 27001 has been around two decades and is now table stakes for serious procurement. ISO 42001 is brand new and almost no Australian business has even started - which is exactly why now is the right time. We help with both.

ISMS - ISO 27001

Information Security Management System.

The standard most procurement teams now ask for. Proves you treat information security like a system, not a series of fires.

  • Information security policies and procedures, written for your business
  • Risk assessment, treatment plans, and statements of applicability
  • Evidence trails an auditor can actually follow
  • Gap analysis against the ISO 27001 controls

AIMS - ISO 42001

AI Management System.

Published in 2023. The first ISO standard purpose-built for AI governance. Almost no business is certified yet - early movers will be ahead of the curve.

  • AI governance, risk and lifecycle controls
  • Use-case registers and impact assessments
  • Roles, accountability and review cadence for internal AI
  • Mapping your AI initiatives to ISO 42001 clauses

What this looks like in practice.

Gap analysis

Where you currently stand against ISO 27001 (ISMS) or ISO 42001 (AIMS), what's missing, and the order to close those gaps in.

Internal documentation

Policies, procedures and statements of applicability written for your business - not boilerplate copied from a template that won't survive an auditor's first question.

Evidence & audit prep

The records and artefacts an auditor wants to see, organised the way they want to see them. Get the certification conversation off on the right foot.

Independent audit

Auditing a management system we had no hand in building. Where the implementation was ours, an independent practitioner we work with takes the audit instead.

AI governance (ISO 42001)

AIMS is new - most businesses don't yet know what's required. We help you stand up the AI governance, risk and lifecycle controls before regulators or customers ask.

Three steps, every time.

Scope the system

Agree what's in and out of the management system, who the stakeholders are, and which clauses of the standard genuinely apply to your business.

Close the gaps

Write the documentation, build the controls, and capture the evidence in a way that holds up under audit scrutiny.

Hand off to audit

When you're ready, we help you engage a certification body and stand alongside you through the stage 1 and stage 2 audit. Where we built the system, the audit goes to an independent practitioner rather than back to us.