WHAT THE SECTOR GETS ASKED FOR
WHO’S ASKINGWHAT THEY WANTTHE ANSWER
Enterprise buyersIndependent assurance before contract, not promisesISO 27001 certificate and Statement of Applicability
Government agenciesAlignment with NZISM expectations and privacy obligationsAn ISMS scoped to the service they’re buying
Your engineersControls that don’t break the delivery pipelineEvidence generated by the tooling you already run
The boardRisk visible, owned and reviewedRisk register and management review that mean something
WHERE SYSTEMS FAIL HERE
FAIL-01
A policy set nobody follows
Downloaded policies describing a company you aren’t. Auditors test the control, not the document — and so do your customers’ security teams.
FAIL-02
Evidence collected in audit week
Access reviews, backups and training all reconstructed the fortnight before. The calendar we build spreads it across the year, where it belongs.
FAIL-03
Scope drawn too wide
Certifying everything costs more and proves less. We scope to the service that unblocks the deal, then extend deliberately.
NEXT STEP
Bring the questionnaire. We’ll bring the certificate.
Thirty minutes on your stack, your buyers and your timeline — and a fixed-price quote in writing.
Book a consultation0800 KAIZEN (524 936) · hello@kaizenconsulting.co.nz
