Skip to content

Sector · Professional services

Show clients their information is handled properly, without hiring a compliance team.

Law, accounting, engineering and consulting firms are asked for 27001 in RFPs and questionnaires. Partners do not have a spare month for it.

What gets asked

The stack.

The standards this sector is asked for, and why.

The first eight weeks

A worked plan.

What a typical programme looks like on ISO Assist. Scope and existing evidence move the dates; the shape holds.

  1. WEEK 1

    Adopt 27001. Scope to the client-data estate; owners assigned across partners and IT.

  2. WEEK 2–4

    Policies adapted from the library; risk register; asset and vendor registers for the SaaS estate.

  3. WEEK 5–7

    Access reviews, training acknowledgements, internal audit.

  4. WEEK 8

    Stage 1 dossier; trust page live to answer questionnaires once.

Registers that matter

What you will actually maintain.

Registers are data on a generic engine: pack-defined columns, CSV in and out, evidence links per row.

AssetsVendorsRisksAccess reviewsLegal obligations

Example

Illustrative, a typical programme, not a named customer.

An advisory firm closing a 27001 gap list of 41 items in six weeks, then answering client questionnaires from its trust page.

Book the Professional services demo.

Bring your tender clause or client request. We adopt the standards it names, live.