Governance. Risk. Compliance. Cybersecurity.
Methodology

Methodology — Integrated Management System (IMS)

Our Integrated Management System (IMS) methodology is built on five repeatable phases refined across hundreds of engagements in the UAE, KSA, India and Africa. Each phase produces signed-off artefacts that carry forward into the next.

  • ISO/IEC 27001 Certified
  • ISO/IEC 27701 Certified
  • ISO 9001 Certified

Delivered by an ISO/IEC 27001, 27701 & 9001 certified organisation

Guiding principles

  • Risk-led, not checklist-led — every control traces back to a business risk.
  • Evidence-first delivery — every workshop ends with an artefact in your repository.
  • Local context — Arabic, English and Hindi delivery, local regulator relationships.
  • Single source of truth — one risk register, one control set, many audits.
Principles applied to every engagement

Checklist titled "Principles applied to every engagement" with 4 items, every item marked complete: Risk-led, not checklist-led; Evidence-first delivery; Local context; Single source of truth.

  • Risk-led, not checklist-led
  • Evidence-first delivery
  • Local context
  • Single source of truth

Phase 1. Standards Mapping

Map clauses and controls across ISO 27001, 9001, 14001, 45001, 27701, 22301, 20000-1 and 42001 into a single normalised matrix.

  • Defined entry and exit criteria captured in the engagement charter
  • Weekly progress reporting against an agreed traffic-light scorecard
  • Outputs reviewed by a Lead Auditor before sign-off
  • Lessons captured to refine the next Compliance & Certification engagement
Integrated Management System (IMS) delivery phases

Process flow diagram titled "Integrated Management System (IMS) delivery phases" with 6 sequential steps: Standards Mapping; Integrated Design; Unified Implementation; Combined Internal Audit; Joint Certification; Continuous Improvement.

  1. Standards Mapping
  2. Integrated Design
  3. Unified Implementation
  4. Combined Internal Audit
  5. Joint Certification
  6. Continuous Improvement

Phase 2. Integrated Design

One policy suite, one risk methodology, one Statement of Applicability and one document control framework spanning every standard in scope.

  • Policy and standard drafting against agreed templates
  • Control design workshops with control owners
  • Risk treatment plan signed off by risk committee
  • Tooling and architecture decisions captured in ADRs

Phase 3. Unified Implementation

Shared controls, training, supplier assurance, incident and change processes deployed once across the organisation.

  • Hands-on rollout with control owners — not slide-only consulting
  • Awareness training delivered in English, Arabic and Hindi as needed
  • Evidence captured in a single repository against each control
  • Weekly burn-down against the remediation backlog

Phase 4. Combined Internal Audit

One internal audit programme and one management review covering all standards in a single cycle.

  • Internal audit dry-run with formal findings register
  • Management review with executive sponsor
  • External audit liaison and observation room support
  • Findings closure plan with target dates and owners

Phase 5. Joint Certification

Coordinated Stage 1 + Stage 2 with an accredited body that audits all schemes in one engagement.

  • Internal audit dry-run with formal findings register
  • Management review with executive sponsor
  • External audit liaison and observation room support
  • Findings closure plan with target dates and owners

Phase 6. Continuous Improvement

Single corrective-action, KPI and surveillance-audit calendar — sustainable beyond first certification.

  • Defined entry and exit criteria captured in the engagement charter
  • Weekly progress reporting against an agreed traffic-light scorecard
  • Outputs reviewed by a Lead Auditor before sign-off
  • Lessons captured to refine the next Compliance & Certification engagement

Quality gates

Each phase ends with a formal gate review attended by the engagement partner, your sponsor and any second-line stakeholders. No phase closes until the gate criteria are documented and signed off.

  • Gate 1 — scope, RACI and risk appetite formally agreed.
  • Gate 2 — control design reviewed and approved by your security committee.
  • Gate 3 — evidence pack independently sampled before audit submission.
  • Gate 4 — post-audit lessons-learned and continuous improvement plan signed off.
Four quality gates per engagement

Process flow diagram titled "Four quality gates per engagement" with 4 sequential steps: Gate 1; Gate 2; Gate 3; Gate 4.

  1. Gate 1
  2. Gate 2
  3. Gate 3
  4. Gate 4