Governance and Audit / evidence it

Audit and assurance

Audit-ready evidence, produced as a by-product of doing the work and recording it as you go, then kept current between assessments. When a regulator, insurer or prime contractor asks how you protect data, the proof is already in order. From a team certified for ISO 27001 by a UKAS-accredited certification body.

Governance and Audit / 01 · What assurance means

What is assurance?

Assurance is the ongoing work of producing and maintaining the evidence that your controls are in place and working, not a separate project you start when an audit looms. We capture the trail continuously, package it the way assessors want it, and keep it current, so an audit becomes a matter of producing a pack.

Governance and Audit / 02 · What the evidence is

The proof an assessor asks for

Auditors ask for specific things. We make sure each one exists, is current, and is ready to hand over.

01Document

Policies and procedures

The documented backbone: information security and acceptable use policies, access control and data retention procedures, and the incident response plan.

02Log

Audit logs and monitoring

Logging, monitoring and change records, retained so the trail is there when an assessor asks. The difference between saying a control works and showing it has been working.

03Configure

Security configurations

The state of your systems, captured as evidence: hardening, firewall rules, multi factor authentication and patch status, recorded so an auditor can verify what is in place rather than what is claimed.

04Certify

Certification evidence

The certificates, assessment records and training logs that show your obligations are met, mapped to whichever standard applies, from Cyber Essentials to ISO 27001 to a sector toolkit.

Governance and Audit / 03 · The assurance cycle

Why assurance is continuous, not annual

A certificate is a snapshot: it says your controls were in good order on the day you were assessed. Systems change, people come and go, and threats move on, so a control that was sound in March can drift by September. Assurance keeps the picture true between snapshots.

For a standard like ISO 27001 this is built in. You keep the management system alive with internal audits, management reviews and surveillance audits between full recertifications. The same logic applies where a standard does not formally require it: evidence is only worth having if it reflects reality, and reality keeps moving.

Governance and Audit / 04 · How we work

How the evidence comes together

The approach we use for our own ISO 27001 certification: evidence captured as the work happens, then assembled when it is needed.

01

Establish the baseline

We record where you stand against the standards that apply, so compliance is demonstrable rather than asserted.

02

Capture as you go

Monitoring, change records and policy evidence are captured continuously, as part of running the technology, not bolted on before an audit.

03

Review internally

Internal review and management oversight keep the evidence current and catch drift early.

04

Package for assessment

When an audit, insurer or client asks, we assemble a pack mapped to the relevant certification or framework, ready to hand over.

Governance and Audit / 05 · How this fits

How assurance fits with our other work

Audit and assurance is part of our governance and audit work. It builds on the documented backbone from policy frameworks and the preparation in compliance readiness. For the regulated supply chain, including defence and aerospace, this ongoing evidence is what turns a one-off certification into something a prime contractor can keep relying on.

FAQ

Common questions

What is the difference between an audit and assurance?

An audit is a point-in-time review that tells you where you stand. Assurance is the ongoing work that keeps your evidence current between audits, so your compliance position stays true as systems and people change. Our standalone audit gives you that picture once, while assurance is the continuous work behind a certification you have to keep.

What evidence will an auditor or regulator actually want?

Typically your policies, your security configurations, your audit logs, and your certification evidence. In other words, the documents that show your controls exist, the records that show they have been operating, and the certificates that show your obligations are met. We make sure each of these exists, is current, and is mapped to the standard being assessed.

How long do you retain audit logs?

We capture monitoring and change records continuously and retain them so the trail is available when an assessor asks. The right retention period depends on the standard and the sector you operate in, so we agree it with you against your specific obligations rather than applying a single blanket figure.

Can you help with a data subject access request?

We can support the technical discovery, helping you find and assemble the relevant data. The legal assessment of what to provide remains your responsibility, because that is a judgement only you can make about your own data. We handle the technical side so you can concentrate on the decision.

Do I need this if I already use a compliance platform?

A platform can track tasks and store documents, which is useful. It does not operate the controls, verify that a change happened, or stand behind the security it asks you to confirm. We run and secure the technology as well as evidencing it, so the assurance describes what is in place, and one team is responsible for both.

Talk to us about audit and assurance

Tell us which assessments you face and we will make sure the evidence is in order and stays that way.

Reading, Berkshire  /  ISO 27001 certified via a UKAS-accredited body  /  reply within one working day