Skip to content

About

Credentials and accreditations

Audit is a credentials business. Here is what our practitioners hold, what the firm works to, and — set out just as plainly — what we do not hold.

Professional certifications across the practice

Practitioners hold recognised certifications relevant to the work they perform. Engagement staffing is matched to the certification the scope requires, and the proposal names who is assigned.

  • CISA — Certified Information Systems Auditor (ISACA)
  • CISM — Certified Information Security Manager (ISACA)
  • CRISC — Certified in Risk and Information Systems Control (ISACA)
  • CISSP — Certified Information Systems Security Professional (ISC2)
  • ISO/IEC 27001 Lead Auditor and Lead Implementer
  • ISO 22301 Lead Auditor for business continuity engagements
  • Offensive security certifications within the technical testing team

Standards the firm works to

  • ISACA ITAF — the IT audit and assurance framework governing how engagements are planned, evidenced and reported
  • COBIT 2019 — governance and management objectives
  • ISO/IEC 27001:2022 — information security management systems
  • ISO 22301:2019 — business continuity management systems
  • NIST CSF 2.0 — cyber security programme structure and maturity
  • OWASP ASVS and the OWASP Testing Guide — application security testing
  • IIA Global Internal Audit Standards — where we co-source with an internal audit function

Frameworks and standards we audit against

ISACA ITAF COBIT 2019 ISO/IEC 27001:2022 ISO 22301:2019 NIST CSF 2.0 OWASP ASVS PCI DSS IIA Standards

What we do not hold — and what we offer instead

This section exists because overclaiming is common in this market and it is trivially checkable. Every item below is something a client has asked us for, and something we have declined to claim.

  • We are not a PCI Qualified Security Assessor. A Report on Compliance can only be issued by a QSA registered with the PCI Security Standards Council. We provide cardholder data discovery, scope definition and reduction, gap assessment, remediation planning and internal audit — and prepare the evidence package for the QSA you appoint.
  • We are not an Approved Scanning Vendor. External vulnerability scanning for PCI validation purposes must be performed by an ASV. Our penetration testing is a different exercise and does not substitute for it.
  • We are not a certification body. ISO certificates are issued only by accredited certification bodies. We provide the independent gap assessment and the internal audit the standard requires — which, by design, an implementation consultant cannot provide for a management system they built.
  • We are not lawyers. Where the application of a regulation to your entity is a legal question, we say so and recommend counsel. We assess whether technical and organisational controls meet the requirements as your legal advisers interpret them.
  • We do not implement what we audit. Where we have provided advisory or implementation support, we do not then provide independent assurance over that same scope for the same client.

Why we publish this

A firm that claims an accreditation it does not hold usually gets away with it until the moment it matters — a tender evaluation, a regulator's question, a client's due diligence. At that point the overclaim does more damage than the missing capability ever would, because it puts every other statement the firm has made into question.

Stating a limit clearly costs a small amount of work occasionally. It is also, for an assurance practice, the entire point.

Verification

Certification status for named individuals can be verified directly with the issuing body — ISACA and ISC2 both operate public verification. We will provide certification numbers on request during procurement, and we expect to be asked.

See the team for who holds what, and our methodology for how those standards are applied in practice. If you hold these certifications and want to use them properly, we are hiring.

Frequently asked questions

Ask us directly and we will tell you the current position rather than implying one here. Note that a consultancy holding ISO 27001 certification says something about how it runs itself, not about the quality of its assessment work — those are different questions, and the second is the one that should decide your appointment.

Yes, on request, along with CVs in whatever format the tender prescribes. Certification status for CISA, CISM, CRISC and CISSP can be verified independently with ISACA and ISC2.

We mark it non-compliant in the compliance matrix, explain why, and propose what we can deliver instead. We will not mark a requirement compliant where we are not — a single overclaim discovered during evaluation puts every other answer in doubt.

Need an independent view?

Tell us the scope, the regulator and the deadline. We will come back with an approach, a team and a fee estimate.

Request a proposal
Top