Governance · Risk · Evidence · Assurance

Move from compliance pressure to defensible confidence.

I help organizations turn obligations, risk, controls, and audit evidence into a management system leaders can govern—practical in operation, credible under scrutiny, and capable of improving after the audit is over.

Advisory, independent assurance, and official CB audit mandates worldwide.

01Risk before paperwork
02Ownership before evidence
03Effectiveness before status
04Improvement after assurance

When the control environment looks stronger than it operates.

Most assurance failures are not caused by a missing spreadsheet. They begin with unclear ownership, weak evidence, fragmented obligations, and decisions no one is prepared to make.

01

Compliance without confidence

Policies and control mappings exist, but leadership cannot determine whether controls operate effectively or reduce material risk.

02

Audit-driven firefighting

Evidence is assembled at the last moment, findings repeat, and remediation lacks ownership, priority, or a sustainable management rhythm.

03

Unclear accountability

Risk, security, technology, privacy, continuity, legal, and business teams interpret obligations differently and decisions stall between functions.

04

Framework overload

Multiple standards, regulations, contractual requirements, and customer questionnaires create duplicated work without one coherent control system.

05

Weak risk translation

Technical issues, control gaps, and compliance exceptions are not translated into business exposure, treatment decisions, and residual-risk acceptance.

06

Point-in-time assurance

The organization passes periodic reviews but lacks continuous evidence, meaningful metrics, and governance capable of detecting control deterioration.

Governance and assurance across the full control lifecycle.

Service components can be combined into one program or scoped as focused projects, reviews, readiness initiatives, or assurance mandates.

A

Governance & operating models

Security mandates, committee structures, policy architecture, decision rights, control ownership, risk acceptance, exception management, and executive reporting.

  • Governance model
  • Policies & responsibilities
  • Committees & escalation
  • Executive reporting
B

Enterprise risk & treatment

Risk methods, asset and process context, scenarios, registers, treatment plans, residual risk, appetite and tolerance, and decision-focused reporting.

  • Risk methodology
  • Risk register
  • Treatment governance
  • Residual-risk decisions
C

Management systems

ISMS, BCMS, PIMS, and related management-system design, implementation, integration, maintenance, readiness, internal audit, and continual improvement.

  • ISMS
  • BCMS
  • PIMS
  • Integrated systems
D

Framework & regulatory alignment

Practical alignment across standards, regulations, industry frameworks, contractual requirements, customer assurance, and sector-specific control expectations.

  • Control mapping
  • Obligation register
  • Cross-framework rationalization
  • Compliance roadmap
E

Control & evidence architecture

Control objectives, evidence ownership, test procedures, data sources, sampling logic, traceability, retention, quality review, and assurance-ready reporting.

  • Control library
  • Evidence catalogue
  • Testing model
  • Traceability
F

Audit readiness & remediation

Scope validation, gap and maturity assessment, audit preparation, finding analysis, corrective-action governance, closure evidence, and management review.

  • Readiness assessment
  • Audit preparation
  • Corrective actions
  • Closure assurance
G

Third-party & customer assurance

Supplier and partner risk, due diligence, contractual controls, oversight tiers, customer security responses, evidence reuse, and exception management.

  • Third-party risk
  • Due diligence
  • Contractual controls
  • Customer assurance
H

Continuous assurance & metrics

Control-health indicators, leading and lagging measures, governance dashboards, recurring evidence review, assurance planning, and continual improvement.

  • Control metrics
  • Assurance plan
  • Governance dashboards
  • Continual improvement

Integrated systems that survive real operations.

The objective is not to operate separate compliance islands. It is to build a coherent management structure for risk, evidence, accountability, resilience, and improvement.

ISMSISO/IEC 27001

Information Security Management

Govern information-security risk, controls, accountability, evidence, and continual improvement through an integrated management system.

BCMSISO 22301

Business Continuity Management

Connect business impact, continuity strategies, plans, exercises, crisis governance, recovery capability, and management assurance.

PIMSISO/IEC 27701

Privacy Information Management

Extend information-security governance into privacy roles, processing controls, evidence, accountability, and applicable data-protection obligations.

IMSRisk-led integration

Integrated & specialist systems

Rationalize overlapping management systems and specialist obligations so governance, evidence, audit, and improvement do not operate in separate silos.

Common alignment contexts

ISO/IEC 27001ISO 22301ISO/IEC 27701ISO/IEC 42001ISO 27005 / 27035ISO 31000NIST CSF / RMFPCI DSSSWIFT CSCFCSA CCM / STARSOC 2RNSINIS2DORAIEC 62443Privacy & contractual obligations

Choose the mandate before evaluating the evidence.

Each pathway has a different purpose, responsibility model, and impartiality requirement. They are deliberately not blended into one ambiguous service.

01

Build and prepare

Advisory & readiness

Design or improve governance, risk, controls, management systems, evidence, remediation, and readiness for customer, regulatory, internal, or certification scrutiny.

02

Evaluate and report

Independent assessment & assurance

Assess against defined criteria, test design and operating evidence, identify gaps and residual risk, and provide impartial findings and executive-level conclusions.

03

Audit through an accredited CB

Official certification audit

Perform formal third-party certification audits through engagements with accredited certification bodies, particularly across ISMS, BCMS, and PIMS, plus other standards within the approved audit scope.

04

Correct and sustain

Post-finding improvement

Structure corrective actions, root-cause analysis, ownership, closure evidence, management review, and continual improvement under a separate non-conflicting mandate.

Official certification-audit boundary

Formal certification audits are performed only through engagements with accredited certification bodies and within the applicable approved audit scope. The certification body controls the certification process and makes the certification decision; TaherAmine.org does not independently issue certificates.

From requirement to repeatable confidence.

A traceable sequence connecting business context, evidence evaluation, risk decisions, remediation, and continual improvement.

  1. 01

    Frame

    Clarify scope, stakeholders, business context, obligations, criteria, boundaries, and the decisions assurance must support.

  2. 02

    Map

    Connect risks, obligations, controls, owners, evidence sources, tests, dependencies, and reporting expectations.

  3. 03

    Evaluate

    Assess design, implementation, operating evidence, exceptions, findings, root causes, and residual exposure.

  4. 04

    Decide

    Prioritize treatment, assign accountability, report limitations, and secure appropriate risk, acceptance, or escalation decisions.

  5. 05

    Sustain

    Establish metrics, evidence cadence, assurance planning, management review, and continual-improvement governance.

Artifacts that support decisions—not document volume.

Deliverables are selected according to scope and engagement type. Formal certification-audit outputs are governed by the certification body’s process.

  1. 01

    Governance and responsibility model

  2. 02

    Risk methodology, register, and treatment plan

  3. 03

    Management-system scope and architecture

  4. 04

    Policy, process, and control framework

  5. 05

    Obligation and cross-framework mapping

  6. 06

    Control and evidence catalogue

  7. 07

    Gap, maturity, or readiness assessment

  8. 08

    Internal-audit and assurance program

  9. 09

    Findings and corrective-action register

  10. 10

    Executive dashboard and management-review pack

  11. 11

    Certification-audit plan and reports when acting through a CB

  12. 12

    Continual-improvement roadmap

Before readiness, assurance, or audit begins.

Clear answers about certification, scope, impartiality, frameworks, and credible assurance outcomes.

Can you help us prepare for ISO certification?

Yes. Advisory and readiness work can cover management-system scope, risk, policies, processes, controls, evidence, internal audit, management review, remediation, and certification preparation. The scope is defined around the organization’s actual context rather than a document checklist.

Can you personally conduct the official certification audit?

Yes, when engaged by an accredited certification body and when the standard, sector, geography, competence, and impartiality conditions fall within the approved audit scope. The certification body governs the formal audit and makes the certification decision.

Does TaherAmine.org issue ISO certificates?

No. TaherAmine.org does not independently issue management-system certificates. Official audits are conducted through accredited certification-body engagements, and certificate issuance remains the certification body’s responsibility.

Can the same person implement our system and certify it?

Not under a conflicting arrangement. Advisory/readiness and official certification-audit responsibilities must be separated in accordance with certification-body rules, impartiality requirements, and applicable professional obligations.

Do you work with frameworks beyond ISO standards?

Yes. Engagements can align or rationalize ISO standards with NIST, PCI DSS, SWIFT CSCF, CSA CCM/STAR, SOC 2, RNSI, NIS2, DORA, IEC 62443, privacy, contractual, and sector-specific requirements.

Will you guarantee certification or a clean audit result?

No. A credible advisor or auditor cannot guarantee an assurance conclusion, certification decision, or absence of findings. The work improves governance, readiness, evidence quality, and decision confidence without prejudging an independent outcome.

What must your governance or assurance system prove?

Share the obligation, audit pressure, risk concern, target standard, evidence challenge, or transformation objective. We can determine the appropriate advisory, assurance, or certification-body pathway.

Start a confidential conversation