Compliance & audit readiness
Prove your controls work — continuously, not once a year
Guardian's compliance practice maps your existing security controls to every framework you are held to, closes the gaps that matter, and replaces the annual evidence scramble with monitoring that produces auditor-grade proof on demand.
Guardian does not act as your auditor. We prepare, map and monitor; an independent assessor of your choosing issues the opinion.
Why programmes stall
You are not running six programmes. You are running one, badly labelled six times.
Most organisations discover, somewhere around their third framework, that they are answering the same question repeatedly in slightly different vocabulary. Access review, change management, logging, encryption, vendor oversight and incident response account for the large majority of every framework's demands — but each is evidenced separately, by a different team, on a different cadence.
Guardian collapses that duplication. We build a single control library for your organisation, map each control to every framework clause it satisfies, and attach an evidence source to each one. From that point a new framework is a mapping exercise measured in weeks, not a programme measured in quarters.
- One control, many obligations. A typical enterprise library of 180 controls satisfies more than 1,400 individual framework requirements.
- One evidence source per control. Collected once, presented in whichever format the assessor expects.
- One owner per control. Named, with a review date, so nothing drifts silently between audits.
Framework coverage
What we support, and what each engagement produces
Coverage means a maintained clause-by-clause mapping, a defined evidence source per control, and consultants who have taken clients through the assessment — not a logo on a slide.
| Framework | Applies to | Guardian control mapping | Evidence automation | Typical time to ready |
|---|---|---|---|---|
| ISO/IEC 27001:2022 | Any organisation seeking a certified information security management system | All 93 Annex A controls plus clauses 4–10 of the management system | High — 81% | 5–8 months to stage 1 |
| SOC 2 Type II | Service organisations reporting to customers in North America | Security, availability, confidentiality, processing integrity and privacy criteria | High — 86% | 3 months to readiness, then a 6-month observation window |
| PCI DSS 4.0 | Any entity storing, processing or transmitting cardholder data | All 12 requirements, including the customised approach and targeted risk analyses | Medium — 68% | 6–10 months, driven by segmentation work |
| HIPAA Security Rule | Covered entities and business associates handling protected health information | Administrative, physical and technical safeguards with risk analysis documentation | Medium — 72% | 3–6 months |
| GDPR | Processing of personal data of individuals in the EU and UK | Articles 5, 25, 30, 32–34; records of processing and transfer impact assessments | Medium — 64% | 4–7 months |
| NIS2 Directive | Essential and important entities across 18 sectors in the EU | Article 21 risk management measures, Article 23 incident reporting, governance duty | Medium — 70% | 4–8 months |
| DORA | EU financial entities and their critical ICT third-party providers | ICT risk framework, incident classification, resilience testing, register of information | Medium — 66% | 6–9 months |
| FedRAMP Moderate / High | Cloud service providers selling to United States federal agencies | NIST SP 800-53 Rev. 5 baselines with continuous monitoring obligations | Assisted — 54% | 12–18 months |
Scroll the table horizontally to see every column.
Also supported with maintained mappings: CIS Controls v8.1, NIST CSF 2.0, TISAX, CMMC Level 2, ISO 27017/27018 and the UK Cyber Essentials Plus scheme.
Multi-jurisdiction by default. Where two frameworks conflict — data residency against log retention, for instance — we document the conflict, the position taken and the legal basis, so an assessor sees a decision rather than an omission.
Scope reduction first. The cheapest control is the one you no longer need. Most PCI DSS engagements begin by shrinking the cardholder data environment; we have removed entire business units from scope with tokenisation alone.
Assessor-neutral. Guardian holds no audit practice and takes no referral fee. We work alongside whichever QSA, certification body or CPA firm you appoint, and we will happily be introduced to one you already trust.
Gap assessment
Four weeks to know exactly where you stand
Every engagement opens with a fixed-scope, fixed-fee gap assessment. It ends with a scored control register, a remediation plan sequenced by effort, and a defensible date you can give the board.
Scope and discovery
We establish which systems, data flows, business units and third parties fall inside the boundary — and, critically, which can be excluded. Interviews with control owners run alongside automated inventory collection from your cloud and identity providers.
Week 1
Control testing
Each control is tested rather than asked about. We sample access reviews, pull change records, inspect encryption configuration and read the last three incident tickets. Design and operating effectiveness are scored separately.
Weeks 2–3
Gap analysis
Findings are mapped to every applicable framework clause, so one deficiency shows its full blast radius. Each gap carries a severity, an estimated remediation effort in person-days, and a dependency chain.
Week 3
Roadmap and readout
A sequenced plan with owners, dates and quick wins separated from structural work, presented to the executive sponsor and to the engineering leads in two different sessions with two different levels of detail.
Week 4
Deliverable
The control register
A live spreadsheet and platform view of every control: identifier, statement, owner, framework mappings, test procedure, evidence location, last tested date and current status. It becomes the operating document for the programme and the first artefact your assessor asks for.
| ID | Control | Maps to | Status |
|---|---|---|---|
| AC-04 | Quarterly access recertification for privileged roles | ISO A.5.18 · SOC 2 CC6.2 · PCI 7.2.4 | Effective |
| LOG-02 | Centralised, tamper-evident audit logging with 400-day retention | ISO A.8.15 · SOC 2 CC7.2 · PCI 10.5 · NIS2 21(2)(g) | Effective |
| VM-07 | Critical vulnerabilities remediated within 7 days on internet-facing assets | ISO A.8.8 · PCI 6.3.3 · NIS2 21(2)(e) | Partially effective |
| TPR-03 | Security review before onboarding any processor handling personal data | ISO A.5.19 · GDPR Art. 28 · DORA Ch. V | Gap |
Deliverable
The readiness scorecard
A single view of maturity per control domain, scored on design and on operating effectiveness. It is deliberately blunt: leadership sees where the programme actually is, and where the next quarter's budget will move the needle furthest.
Illustrative scorecard from an anonymised financial services engagement at the end of week four.
Continuous compliance
Controls drift. Monitoring catches it in hours, not at the next audit.
Point-in-time compliance is a photograph of a moving object. Guardian Sentinel evaluates your control set against live configuration and telemetry continuously, raises a finding the moment a control stops operating, and files the evidence automatically when it is operating correctly.
Continuous control evaluation
Each automated control has a test that runs on a schedule — hourly for configuration checks, daily for access, weekly for process controls. Results are timestamped and immutable.
Drift alerting with ownership
A failed control raises a ticket to its named owner with the exact delta — which bucket became public, which role gained a wildcard, which host stopped shipping logs — not a generic policy violation.
Evidence collected as it happens
Screenshots, configuration exports, ticket references and approval records are captured at the moment of the test and stored against the control, with a hash chain so an assessor can verify nothing was edited later.
Audit-window reporting
Select a date range and a framework; receive the population, the sample, the evidence and the exception log in the format your assessor requested. What used to take three weeks takes an afternoon.
A full engagement
What twelve months looks like
Illustrated with a SOC 2 Type II and ISO 27001 dual-track programme for a 900-person software company — the most common shape of work we do.
Kickoff and scope lock
Boundary agreed, systems inventoried, control owners named and the assessor selected. We insist on naming owners before any remediation begins — unowned controls are the single strongest predictor of a programme slipping.
Gap assessment and roadmap
Control register built, 180 controls tested, 47 gaps identified. Roadmap splits into nine quick wins deliverable inside a fortnight and four structural projects requiring engineering capacity.
Remediation and policy build
Policies written to match what the organisation actually does, not aspirational templates. Access recertification automated, log retention extended to 400 days, vendor review workflow implemented, encryption gaps closed on two legacy stores.
Continuous monitoring goes live
140 of 180 controls move to automated evaluation in Guardian Sentinel. Evidence begins accumulating from this date, which is what makes the observation window survivable.
Internal audit and readiness review
We run the audit before the auditor does, using the assessor's own test procedures. Findings are fixed while there is still time, and management responses are drafted for anything that will remain open.
Observation window and assessment
SOC 2 Type II observation runs while the ISO 27001 stage 1 and stage 2 audits take place. Guardian sits in every assessor session, produces evidence on request and manages the exception log. Report issued in month twelve.
Surveillance and the next framework
Quarterly control review, annual policy refresh and surveillance audit support. The same library then carried this customer into NIS2 readiness in eleven weeks, because 78% of the required measures were already mapped and evidenced.
Our first SOC 2 consumed two engineers for four months and we still scrambled for evidence in the final fortnight. With the control library and continuous monitoring in place, this year's ISO 27001 certification cost us eleven days of internal effort in total. The auditor asked for a sample and we exported it while she was still on the call.
See how compliance work pairs with penetration testing for requirement 11.4 evidence, or with managed detection and response for continuous monitoring obligations.
Frequently asked
Practical questions about the engagement
Can Guardian certify us?
No, and that is deliberate. Certification bodies, QSAs and CPA firms must be independent of the party that built the controls. Guardian prepares you, maps your controls, remediates the gaps and manages the evidence; an assessor of your choosing issues the certificate or opinion. We work regularly with all the major bodies and can make introductions if you do not already have one.
We already have a GRC tool. Does this replace it?
Usually not. Most GRC platforms are good at holding a control register and poor at proving controls are operating. Guardian integrates with the major GRC vendors and pushes continuous evaluation results and evidence into the register you already maintain. If you have no tool, the control register and evidence store are included in the engagement at no additional cost.
How do you handle evidence for controls that are not technical?
Roughly a fifth of any framework concerns process and governance — board oversight, training completion, supplier review, disciplinary procedure. These cannot be scraped from an API, so we instrument them instead: workflow steps in your existing systems that produce a dated, attributable record as a by-product of doing the work. Evidence you have to remember to create is evidence you will not have.
Does continuous monitoring require Guardian Sentinel?
The automated evaluation engine runs on the Guardian Sentinel platform, so yes for the automated portion. The advisory work — gap assessment, control library, remediation, audit support — is entirely platform-independent and a significant share of clients take it alone. We will tell you honestly which controls we can automate against your existing stack before you commit.
What happens if the auditor raises a finding anyway?
We stay in the room. Guardian drafts the management response, agrees a corrective action plan with the assessor, and does the remediation work under the original engagement where it falls inside scope. Across 210 supported SOC 2 Type II audits we have not had a qualified opinion, but exceptions do occur and the plan for handling them is written before the audit starts, not after.
How is the work priced?
The gap assessment is fixed fee and fixed scope. Remediation and audit support are quoted as a programme with a defined deliverable set, not a day rate you cannot forecast. Continuous compliance monitoring is licensed per evaluated control per year and is included in the Enterprise platform tier. See pricing for the platform, or contact us for a programme quotation.
Stop rebuilding the same evidence every year
Start with a four-week gap assessment. You will end it with a scored control register, a sequenced plan and a date you can defend to the board.