Goldline Consultancy is a UK information security and AI governance practice for software and AI companies of 5 to 250 people. We get you certified to ISO/IEC 27001 and ISO/IEC 42001, ready for SOC 2 and Defence Cyber Certification, and keep the system current afterwards, so a customer's security review closes a deal instead of stalling it.
The practitioner who scopes your work delivers it: CISSP, ISO/IEC 27001 Senior Lead Implementer and Lead Auditor, ISO/IEC 42001 Lead Implementer and Lead Auditor, PMP. UK hours, one person to call, and prices published on our site.
What we do:
• ISO 27001 and ISO 42001 implementation, Guided or Sprint, built together on one management system
• SOC 2 readiness, with the examination by a licensed CPA firm you contract
• Independent risk assessments mapped to ISO 27001, for when a customer asks for a third-party view
• Clause 9.2 internal audits of ISO 27001 and ISO 42001 systems we did not build
• AI system security testing: prompt injection, data leakage and agent misuse, with findings mapped into your ISO 42001 evidence
• DCC Level 0 readiness for UK defence suppliers
• A managed compliance retainer that keeps the certificate current without a compliance hire
• Delivery inside Vanta, Drata, Sprinto or Thoropass, or without a platform
Why companies choose Goldline:
• Independence you can show an auditor: we prepare, an accredited body certifies, and we never audit a system we implemented
• Published fixed prices, agreed at a free 45-minute diagnostic and unchanged afterwards
• One senior practitioner from scoping to certificate, not a rotating bench
• ISO 42001 by someone qualified to audit it as well as build it