Can you certify us?
No. Only an accredited certification body can issue an accredited ISO certificate. What we do is everything around that moment: the internal audits the standard requires, the readiness audit before the certification body arrives, and, under contract to certification bodies, the lead auditing behind their certification decisions.
Will you help us fix what you find?
We explain every finding, agree practical corrective actions and verify them once done. What we will not do is design or implement the fix ourselves, because then we would be auditing our own work. For implementation help, you engage a consultancy of your choice; whoever implements, your auditor must have had no hand in it, and we hold ourselves to that rule without exception.
What makes you independent?
We take no implementation or consultancy work, we run a conflict check before every engagement, and we decline any audit where impartiality could reasonably be questioned. Independence is the product we sell, so we protect it more carefully than anything else.
Do you only audit ISO management systems?
No. We also provide outsourced internal audit as a function: risk-based audit plans, internal control testing, and governance and compliance reviews, reported to the board or audit committee. Our practice is led by financial statement audit experience, so finance processes and controls are home ground. We do not perform statutory financial statement audits, which are a separately regulated activity.
How long does an audit take?
A typical internal or readiness audit for a small or medium organisation runs two to five auditor days depending on scope, spread over two to three weeks including planning and reporting. You get the exact duration and price at scoping, before you commit.
Our management system is implemented. What now?
For most organisations, certification: an accredited certification body examines the system in two stages and issues the certificate if it holds up. Before that happens, the standard requires internal audits, and a readiness audit tells you what the certification body will find before they find it. Both are exactly what we do.
Why involve a certification body at all?
Because assurance only counts when it comes from someone with nothing at stake. A certificate says an independent third party confirmed your management system meets the standard. Strip out the independence and all that is left is your own opinion of your own work, which your customers already had for free.
Could we not just certify ourselves?
Nothing physically stops an organisation printing its own certificate. The market decides what that paper is worth, and it decides quickly. The same logic applies one layer down, which is why the standards require internal audits to be independent too: an organisation reviewing its own work is marking its own homework.
What does an audit cost?
A fixed fee, agreed at scoping and before you commit. The price follows the auditor days your scope genuinely needs, and we show you that calculation. We do not publish a rate card, because scope drives everything: a focused readiness audit for a small SaaS company and a multi-standard internal audit programme are very different engagements. What we will never do is surprise you after the work has started.
Who do you work with?
Two groups. Startups and growing companies that need credible, independent audit work without enterprise overhead, and certification bodies that contract lead auditors for their certification audits. If you are a large enterprise with a procurement portal and a panel process, we are probably not your firm, and we are comfortable saying so.
Can one audit cover more than one standard?
Yes. It is usually the efficient route, because ISO 27001, ISO 42001 and ISO 22301 share the same management system clauses: an integrated audit tests the shared machinery once and the standard-specific controls separately. One plan, one report and less interview time for your team.
Do you audit organisations outside Ireland?
Yes. Fieldwork can run remotely through the platform, with on-site days where the scope needs them. Management system audits translate well across borders because the standards are international by design.