GRC & Compliance
ISO 27001 readiness for a growing SaaS company
Gap assessment to certification-ready in one quarter, unblocking enterprise deals stalled in security review.
Client
B2B SaaS provider (anonymised)
Duration
1 quarter
0
Major non-conformities
1 quarter
Gap to audit-ready
93
Controls documented
The challenge
Enterprise prospects were demanding ISO 27001 certification. The company had informal practices but no ISMS, risk register, or documented controls.
What we did
- Annex A control gap assessment across all applicable domains
- Asset and risk register built with business-owner interviews
- Review of existing vendor, access, and change-management practices
Key findings
High
No formal risk treatment process or management review cadence.
High
Access reviews and offboarding performed ad hoc, with orphaned accounts found.
Medium
Supplier due-diligence undocumented for critical processors.
Remediation
- ISMS scope, policy set, and Statement of Applicability drafted
- Quarterly access review and structured offboarding checklist implemented
- Internal audit and management review cycles run before the external stage 1
