ISO certification support
Obtaining a certification is a project. Keeping it is a daily discipline. We handle both.
What we cover
- Gap analysis against the standard you are aiming for
- Internal audits, and preparation for the certification audit itself
- Documentation: policies, procedures and records
- The tools and the organisation needed to run the system day to day
- Staff training and awareness
- Surveillance audits and improvement after the certificate is issued
Why this matters in the region
Across Southeast Asia, certification is often a condition for joining a supply chain, answering a public tender, or satisfying a foreign head office. The requirement usually arrives with a deadline attached.
The certificate is not the finish line
Many organisations obtain a certificate, then let the system fall out of use. The next surveillance audit finds it.
We set up something your teams can actually maintain, with tools that fit the way they already work. We can also stay involved afterwards to keep the system alive between audits.
Standards we support
We work on IT-related standards only. For quality, environmental or sector-specific standards, we will point you to a specialist.
| ISO/IEC 27001 | Information security management |
|---|---|
| ISO/IEC 27701 | Privacy information management |
| ISO/IEC 27017 | Security controls for cloud services |
| ISO/IEC 27018 | Personal data in public cloud services |
| ISO/IEC 20000-1 | IT service management |
| ISO 22301 | Business continuity management |
GDPR
The European data protection regulation applies to organisations outside Europe as soon as they handle the personal data of people in Europe. Many companies in the region are concerned through a head office, a European client, or an online audience.
GDPR is a regulation, not a standard: there is no certificate to obtain. We help you map the data you hold, put the required records and procedures in place, and answer requests from individuals. ISO/IEC 27701 is the usual way to show that the work has been done.
