I work in compliance and information security for regulated digital services. That means ISO/IEC 27001 compliance across an information security management system, and meeting the requirements of the UK Digital Identity and Attributes Trust Framework.
It also means audit, policy and assurance across a business, and working alongside product development to translate regulatory requirements into practical product controls, so that compliance is built into the roadmap rather than bolted on afterwards.
Before compliance I spent nearly a decade as a biomedical scientist in a hospital biochemistry laboratory. That is where the discipline comes from: internal quality control and external quality assurance, validating software before it went live, managing change to analysers and systems, and documentation that had to stand up to inspection. In a laboratory, evidence is not paperwork, it is the work.
I bring that same standard to compliance. Controls that are tested rather than assumed, records that hold up when someone independent looks at them, and findings explained clearly enough that the people who have to act on them understand why.
Delivered through Cram Limited on an independent basis, which means you deal directly with the person doing the work.
ISO/IEC 27001 audits against your ISMS. Controls tested, gaps evidenced, findings written so they can actually be acted on.
Internal audit programmes, and getting you ready for the external assessor before they arrive rather than during.
An independent read of where your regulatory obligations sit against what you are actually doing, with a prioritised route to closing the distance.
Auditing what exists and writing what does not. Policies and procedures people follow because they are clear, not because they are mandatory.
Turning new obligations into controls, owners and evidence. Built into the way the business already works, not bolted alongside it.
Tell me what you are trying to satisfy, and where you think the gaps are. If I am not the right fit I will say so.