>
ISO 27001 Lead Implementer plus Data Protection Officer practice. Framework readiness, evidence capture, and auditor-facing documentation generated as a byproduct of delivery, not scrambled together the month before assessment week.
Not every regulatory framework can be signed off by the same practitioner. Here is the honest split: what we lead end-to-end on your behalf, and what we do the heavy readiness work on while a licensed partner handles the final attestation.
Federal privacy law for commercial activity. Full programme design, DPO function, breach response procedure, cross-border transfer assessment, individual rights handling.
Loi 25 compliance for operations touching Quebec residents. Privacy Impact Assessments, biometric data rules, automated-decision disclosure, data-portability workflows.
Provincial privacy law for private-sector organizations in BC and Alberta. Alignment with Office of the Information and Privacy Commissioner requirements for each province.
ISMS design, Statement of Applicability, Annex A control mapping, internal audit, management review cycle. Readiness through certification audit prep.
Trust Services Criteria design, control implementation, evidence collection across the 6- to 12-month observation window. Licensed CPA firm issues the final attestation report.
Technology and Cyber Risk Management guideline for Canadian federally regulated financial institutions. Readiness work paired with a financial-sector specialist for formal regulatory engagement.
Canadian firms handling US Protected Health Information. Business Associate Agreement review, Security Rule mapping, breach notification workflows. US-licensed attorney coordinates jurisdictional sign-off.
Payment card data environment scoping, segmentation, control implementation for merchants and service providers. Qualified Security Assessor handles the formal assessment and ROC.
Most compliance consultancies arrive six weeks before your assessment with a binder template and a stress-induced caffeine addiction. We do it the opposite way: every control gets its evidence captured the moment it is implemented, in a form your auditor can actually read.
Phase 01 scoping maps every applicable control to a specific system, process, or policy in your environment. No gap stays silent.
Each control gets implemented with its evidence capture built in. Backups generate restore-test logs. Access reviews produce signed attestations. Policies versioned on commit.
Evidence binder populates itself as controls operate. Monthly review cycle flags drift. You can see your readiness % at any point, not just the quarter before audit.
Point the auditor at the binder. Walk them through the control narrative. Answer specific questions from existing evidence. No last-minute reconstruction.
Most compliance work ends up as a shelf of binders nobody opens between audits. Here is what we insist on.
Policies that say "the IT team shall ensure" are dead on arrival. Ours say what Priya in operations does on Monday morning when the backup fails.
If your team cannot recognize the policy as describing their actual job, it is not a policy. It is a liability.
Access reviews produce signed attestations. Backup tests produce restore logs. Policies live in version control, not SharePoint folders no one reads.
By assessment week your evidence binder is already complete. You spend the audit explaining the business, not scrambling to generate proof.
Your ISO 27001 Lead Implementer stays on the account from scoping through certification. Not a BDR, not an account manager, not a template consultant filling blanks.
When your DPO function needs a response within 72 hours, the person who understands your environment is the one who answers.
No, and that is an important distinction. We do the readiness, implementation, and evidence work. The formal attestation is issued by an independent party, which is how it should be. A single firm doing both the implementation and the attestation is a conflict most frameworks explicitly prohibit.
For ISO 27001, a certification body like BSI, Schellman, or similar issues the certificate after their external audit. For SOC 2, a licensed CPA firm issues the attestation report. For PIPEDA, Law 25, and PIPA, there is no third-party certification required but there is regulator oversight. We help you prepare for all of them.
From a reasonable starting point, Stage 1 audit at month 5 to 7, Stage 2 audit at month 7 to 9, certificate issued shortly after. Faster is sometimes possible if the organization already has mature IT practices. Slower is normal if there is significant policy or control work to do first.
The common failure mode is firms promising certification in 90 days. That either means skipped controls (which fail at external audit) or a very small scope that does not actually cover the business.
Yes, and that is actually a common starting point. First engagement is usually a gap analysis against the specific findings plus the broader framework. Remediation plan with target dates, control-by-control ownership, and evidence capture built in.
We do not re-skin the previous consultant's work. If the policies were templated, we rewrite them in plain English against your actual operations. If the controls were theoretical, we implement them properly. The next assessment should be a different experience, not a re-run.
It means we have operated the DPO function at an organizational level, not just advised on it. That includes handling subject access requests, running Data Protection Impact Assessments, maintaining the records of processing activities, coordinating breach notification within statutory windows, and sitting across the table from a regulator when required.
For clients that need a fractional or named DPO, we offer that as a retained service. For clients where an internal person holds the role, we provide the backstop practice: review, escalation, difficult decisions.
Policies, notices, and user-facing documentation are delivered in both official languages. Internal procedures can be English-primary with French-translated versions where required. We do not use machine translation for anything a Quebec regulator might read.
Law 25 also brings specific requirements that PIPEDA does not: biometric database registration, automated-decision disclosure, data portability, and much stricter PIA requirements for new initiatives. All of those are handled during Phase 01 scoping.
Yes, and that commitment is in the engagement document. Every policy, procedure, control narrative, and piece of evidence lives in your own repository and your own evidence platform. No proprietary consulting portals that lock you in.
If you move to another provider or hire in-house, everything hands off cleanly. The person taking over has a complete, documented, versioned compliance programme to inherit, not a stack of PDFs scattered across inboxes.