Insights

Notes from the audit floor: what standards actually require, where implementations usually fail, and what changed in the frameworks you have to answer to.

Featured

Latest from ZULTIV

Reading a Statement of Applicability the way an auditor does

Most SoAs are written to be filed, not read. Here is what a lead auditor checks first, and the three inconsistencies that show up almost every time.

In preparation

Your vendor's ISO certificate does not cover what you think it does

Scope statements are where supplier assurance quietly falls apart. A short guide to reading one properly before you accept it as evidence.

In preparation

Browse

By category

Six streams, each written by someone who works in it. New articles publish as they are written, we would rather post six good pieces a year than a weekly filler.

Cybersecurity

Controls that work, controls that only look like they work, and the incidents that tell the difference.

ISO Standards

Clause-level readings of ISO/IEC 27001, ISO 9001, ISO 22301 and the transitions between editions.

AI Governance

ISO/IEC 42001, AI impact assessment, and what regulators are converging on across jurisdictions.

GRC

Governance, risk and compliance as a working discipline rather than a spreadsheet nobody opens.

Privacy

ISO/IEC 27701, India's DPDP Act, GDPR, and the gap between a privacy policy and a privacy programme.

Audit & Compliance

Technique: sampling, evidence, writing findings that hold, and closing meetings that do not turn into negotiations.

Need help implementing or assessing a requirement?

Reading about a clause is one thing. Evidencing it in front of an auditor is another. That is the part we do.