Capabilities

What the engagement covers

Scope is agreed before work begins. Most mandates draw on part of this list rather than all of it.

  • Enterprise risk identification and assessment
  • Internal control design and testing
  • ISO 27001, ISO 9001 and ISO 20000-1 readiness
  • Information security policy and data governance
  • Compliance frameworks and monitoring
  • Governance structures and review mechanisms

Questions

Common questions

Yes. Innate holds ISO 27001, ISO 9001 and ISO 20000-1, so the readiness work is based on frameworks we operate rather than only advise on.

It depends on the current state of documentation and controls. We scope it after an initial gap assessment rather than quoting a standard timeline.

Start with the problem, not the proposal

A short conversation is usually enough to establish whether Innate is the right firm for the work. Where we are not, we will say so.