Our Process

A disciplined six-phase assessment methodology.

Designed to produce clear evidence, defensible observations, and practical remediation priorities.

01

Discovery & Scoping

Define objectives, requirements, systems, locations, data flows, users, contractors, and engagement boundaries.

02

Documentation Review

Evaluate policies, procedures, agreements, access records, training materials, incidents, and prior findings.

03

Interviews & Walkthroughs

Validate how controls operate across business, privacy, security, IT, facilities, and records functions.

04

Control Testing

Review samples and operational evidence to determine whether controls are consistently performed and monitored.

05

Gap & Risk Analysis

Classify missing, weak, inconsistent, or unsupported controls based on risk and audit exposure.

06

Reporting & Remediation

Deliver findings, recommendations, ownership guidance, target dates, and evidence expectations for closure.