About
Credentials and accreditations
Audit is a credentials business. Here is what our practitioners hold, what the firm works to, and — set out just as plainly — what we do not hold.
Professional certifications across the practice
Practitioners hold recognised certifications relevant to the work they perform. Engagement staffing is matched to the certification the scope requires, and the proposal names who is assigned.
- CISA — Certified Information Systems Auditor (ISACA)
- CISM — Certified Information Security Manager (ISACA)
- CRISC — Certified in Risk and Information Systems Control (ISACA)
- CISSP — Certified Information Systems Security Professional (ISC2)
- ISO/IEC 27001 Lead Auditor and Lead Implementer
- ISO 22301 Lead Auditor for business continuity engagements
- Offensive security certifications within the technical testing team
Standards the firm works to
- ISACA ITAF — the IT audit and assurance framework governing how engagements are planned, evidenced and reported
- COBIT 2019 — governance and management objectives
- ISO/IEC 27001:2022 — information security management systems
- ISO 22301:2019 — business continuity management systems
- NIST CSF 2.0 — cyber security programme structure and maturity
- OWASP ASVS and the OWASP Testing Guide — application security testing
- IIA Global Internal Audit Standards — where we co-source with an internal audit function
Frameworks and standards we audit against
What we do not hold — and what we offer instead
This section exists because overclaiming is common in this market and it is trivially checkable. Every item below is something a client has asked us for, and something we have declined to claim.
- We are not a PCI Qualified Security Assessor. A Report on Compliance can only be issued by a QSA registered with the PCI Security Standards Council. We provide cardholder data discovery, scope definition and reduction, gap assessment, remediation planning and internal audit — and prepare the evidence package for the QSA you appoint.
- We are not an Approved Scanning Vendor. External vulnerability scanning for PCI validation purposes must be performed by an ASV. Our penetration testing is a different exercise and does not substitute for it.
- We are not a certification body. ISO certificates are issued only by accredited certification bodies. We provide the independent gap assessment and the internal audit the standard requires — which, by design, an implementation consultant cannot provide for a management system they built.
- We are not lawyers. Where the application of a regulation to your entity is a legal question, we say so and recommend counsel. We assess whether technical and organisational controls meet the requirements as your legal advisers interpret them.
- We do not implement what we audit. Where we have provided advisory or implementation support, we do not then provide independent assurance over that same scope for the same client.
Why we publish this
A firm that claims an accreditation it does not hold usually gets away with it until the moment it matters — a tender evaluation, a regulator's question, a client's due diligence. At that point the overclaim does more damage than the missing capability ever would, because it puts every other statement the firm has made into question.
Stating a limit clearly costs a small amount of work occasionally. It is also, for an assurance practice, the entire point.
Verification
Certification status for named individuals can be verified directly with the issuing body — ISACA and ISC2 both operate public verification. We will provide certification numbers on request during procurement, and we expect to be asked.
See the team for who holds what, and our methodology for how those standards are applied in practice. If you hold these certifications and want to use them properly, we are hiring.
Frequently asked questions
Need an independent view?
Tell us the scope, the regulator and the deadline. We will come back with an approach, a team and a fee estimate.
Request a proposal