Playbooks

How I actually run these.

Step-by-step methodologies behind every implementation. Not theory — the exact system I follow.

How I run an ISO 27001 implementation in 90 days

From kickoff to certification audit in 12 weeks. Covers gap assessment, risk methodology, documentation sprint, control implementation, internal audit, and management review — with exact deliverables at each stage.

Read the playbook

How I run an ISO 42001 (AI governance) implementation

Standing up an AI management system from scratch. Covers AI inventory, impact assessment, AI risk methodology, policy development, and integration with existing ISO 27001 controls.

Read the playbook

The 90-day ISO 27001 playbook

Weeks 1–2 Gap Assessment & Scoping

Understand the current state, define ISMS scope, identify interested parties.

Weeks 3–4 Risk Assessment

Establish risk methodology, identify and score risks, select treatments.

Weeks 5–8 Documentation Sprint

Write policies, procedures, SoA, and supporting documents.

Weeks 9–10 Control Implementation

Implement and evidence Annex A controls across the organisation.

Week 11 Internal Audit

Conduct the internal audit, log findings, raise corrective actions.

Week 12 Management Review & Audit Prep

Run management review, finalise evidence, brief the team for Stage 1.

These playbooks are the backbone of every engagement. Want to see one applied end-to-end?

See the Reference Build