Advisory

Ongoing advisory

Framework implementation is a beginning. We support the operating rhythm that keeps risk decisions current, controls effective, and evidence ready as the organization changes.

The mandate

Keep the program useful after the milestone.

Sustain security and compliance through fractional leadership, control monitoring, and continuous improvement.

Discuss this work

How we help

  • Fractional security leadership
  • Continuous control review
  • Annual management system cycles
  • Remediation program oversight
  • Management and board reporting

What the work produces

  • Clear cadence for review and improvement
  • Management visibility into control health
  • A program that adapts to change

Common questions

Clarify the mandate before delivery.

What continues after a certificate or SOC 2 report is issued?

The organization still needs to operate controls, monitor exceptions, review risks, update documentation, and prepare for the next assessment period or surveillance cycle.

What decisions should remain with management?

Management should own risk acceptance, policy approval, resource allocation, and statements to auditors, customers, and regulators. Advisory support can provide analysis and coordination.

How should the advisory scope change as the business grows?

Reassess service boundaries, locations, suppliers, product changes, and new AI uses at agreed triggers. Update owners and evidence expectations before a changed service enters the next assessment.

Primary references

Work with Normstone

Let’s build what stands up to scrutiny.

Tell us what you need to achieve. We’ll help define the right first step.

Start a conversation