Independent assurance & assessment

An audit is only worth having if the person running it is willing to tell you something you would rather not hear. We assess what you have built, evidence what we find, and hand you a report you can act on.

What we are, and what we are not

ZULTIV provides independent assurance, internal audit and readiness assessment. We are not an accredited certification body, we do not issue ISO certificates, and we do not act as a registrar.

That separation is the point. Because we are not the body that will certify you, we have no reason to soften a finding, and because we are not your implementer, we have no work of our own to defend. You get an honest read on where you stand before a certification body, a regulator or a customer forms their own.

Category 01

Internal audits

Clause 9.2 requires an internal audit programme. Running it with your own people is allowed, and often the wrong call, nobody audits the system they built with a straight face.

ISO/IEC 27001 Internal Audit

A full internal audit of your ISMS against ISO/IEC 27001:2022, clauses 4 to 10 and the Annex A controls declared in your Statement of Applicability.

Discuss this

ISO 22301 Internal Audit

Business continuity management audited against ISO 22301: BIA, recovery objectives, continuity strategy, and whether the exercises actually test anything.

Discuss this

ISO 9001 Internal Audit

Quality management system audit against ISO 9001: process interactions, risk-based thinking, and evidence of improvement rather than intention.

Discuss this

Category 02

Readiness & assessment

Before the certification audit, the customer security review or the regulator's question, find out what the answer is going to be.

HIPAA Readiness

Administrative, physical and technical safeguards reviewed against the HIPAA Security and Privacy Rules, with a gap register you can work through.

Discuss this

SOC 2 Readiness

Trust Services Criteria walked control by control, so your CPA firm's examination is not the moment you discover the evidence does not exist.

Discuss this

Risk & Compliance Assessment

A structured look at your risk universe and control environment against the obligations that actually apply to you, including India's DPDP Act.

Discuss this

Third-Party / Vendor Assessment

Your suppliers hold your data and your uptime. We assess them properly, on evidence, rather than on a returned questionnaire nobody read.

View service

How we work

The same method, every engagement

No two organisations look alike, but the discipline does not change. Every assessment we run follows ISO 19011 audit principles: evidence-based, impartial, and reported in language you can hand to a board.

01: Scope

We agree what is in scope, what is deliberately out, and what "good" looks like before anything is examined.

02: Examine

Documents, interviews, system evidence and sampling, enough to reach a conclusion that survives challenge.

03: Report

Findings with the requirement, the evidence and the gap kept separate, each graded and each traceable.

04: Close

A prioritised remediation path, and a follow-up review when you are ready to show the gaps are shut.

What you receive

Deliverables, not opinions

Assessment report

Scope, method, sample, and every finding with its evidence trail, written so a third party can follow your reasoning without you in the room.

Gap and risk register

Each gap mapped to the clause or criterion it breaches, graded, and ranked by the risk it actually carries rather than how easy it is to fix.

Remediation roadmap

A sequenced plan with owners and realistic effort, plus a management summary your leadership will read to the end.

Questions

Before you engage us

No. Certification is issued by an accredited certification body, and ZULTIV is not one. What we do is get you ready for that body and audit you the way they will, and, separately, run the internal audit programme the standard requires you to have.

Not on the same scope, and we will say so up front. Auditing your own implementation destroys the independence that makes the audit worth anything. Where we have advised on implementation, we will tell you to have the internal audit run by someone else, and vice versa.

It depends entirely on scope, headcount and how many sites or systems are in play. A focused readiness review can be a few days; a full internal audit of a multi-site ISMS is longer. We scope it before quoting, and the scope is written down.

Yes, most document review and many interviews work well remotely. Physical controls, site security and anything requiring observation are better done on site, and we will tell you which parts of your scope fall into that category.

Entirely. Engagements run under a signed confidentiality agreement, findings are shared only with the people you nominate, and we do not use client names as references without written permission.

Request an assessment

Tell us what you need assessed

Describe the scope in your own words: a system, a standard, a customer's security questionnaire, or just a deadline you have been handed. We will tell you what it takes.

WhatsApp Us instead

Everything you share is treated as confidential. We reply within one business day, Monday to Friday.