Context
Clients in healthcare, financial services, and the UK public sector were asking for certifications the firm did not hold, and the deals were large enough that "we follow best practices" was no longer an answer.
Approach
We built one control framework mapped to every target standard rather than five separate programs, so evidence collected once served each audit.
Controls were wired into the platforms people already used: identity, endpoint, ticketing, and the cloud estate. Compliance became a byproduct of operations rather than a spreadsheet exercise.
Internal audit rehearsals ran before every external audit, using the same evidence requests the assessors would make. [verify: order of certifications and rough timeline]
What I took from it
- One control set, many certifications. The reverse is how compliance programs collapse under their own weight.