How I actually run these.
Step-by-step methodologies behind every implementation. Not theory — the exact system I follow.
How I run an ISO 27001 implementation in 90 days
From kickoff to certification audit in 12 weeks. Covers gap assessment, risk methodology, documentation sprint, control implementation, internal audit, and management review — with exact deliverables at each stage.
Read the playbookHow I run an ISO 42001 (AI governance) implementation
Standing up an AI management system from scratch. Covers AI inventory, impact assessment, AI risk methodology, policy development, and integration with existing ISO 27001 controls.
Read the playbookThe 90-day ISO 27001 playbook
Understand the current state, define ISMS scope, identify interested parties.
Establish risk methodology, identify and score risks, select treatments.
Write policies, procedures, SoA, and supporting documents.
Implement and evidence Annex A controls across the organisation.
Conduct the internal audit, log findings, raise corrective actions.
Run management review, finalise evidence, brief the team for Stage 1.
These playbooks are the backbone of every engagement. Want to see one applied end-to-end?
See the Reference Build