Compliance & Audit Readiness
Compliance handled practically, not theoretically — we focus on what the auditor will actually test and get the evidence in order before they ask.
Compliance work tends to go one of two ways: a thorough process that leaves you prepared, or a documentation exercise that looks good until someone tests it. We work toward the first. We look at your actual environment, identify where the real gaps are, and get the evidence in order. Not just the paperwork.
We help businesses meet their obligations under frameworks like the Privacy Act 2020 and the controls that insurers and auditors commonly test — without turning it into a multi-month consulting engagement. We're not a compliance certification body, and we don't claim to be. What we do is prepare you practically for what's coming, so the audit isn't a surprise.
- Gap analysis against the controls your auditor or insurer is likely to test
- Privacy Act 2020 obligations reviewed and documented, so you know where you stand
- Evidence collation and policy documentation, organised in a format auditors can actually use
- Security framework mapping where required (common frameworks understood, not claimed as certifications)
- Remediation plan for genuine gaps, with work prioritised by risk and audit exposure
- Support during the audit or review itself, so questions get answered correctly
Quick questions
Are you certified in these frameworks yourselves?
We help clients meet their obligations; we don't hold compliance certifications on their behalf. What we bring is practical experience preparing NZ businesses for audits and insurer reviews, and a working knowledge of what the controls mean in a real environment.
We've got a compliance deadline in six weeks. Can you help in time?
Depends on where you're starting from. Six weeks is tight but workable for most environments if we start immediately and the gaps aren't severe. Tell us what the deadline is and what you've already got in place, and we'll give you a straight answer about what's achievable.
What's the difference between being audit-ready and being compliant?
Audit-ready means the evidence exists, it's organised and it reflects what you actually do. Compliance is the state you're in when the audit confirms it. We get you to audit-ready. The auditor or certifying body confirms the compliance.
A plan you can read, from people you can phone.
IT advisory, compliance and project consulting for businesses that want honest answers. No bureaucracy, no account managers in the way — just direct access to the people doing the work, with pricing agreed before anything starts. All of Improve →
Need this sorted?
Tell us what you need. A real person replies — not a bot, not a call centre.