One consultant, from scoping to your audit.
Veraeth Advisory is a solo governance, risk and compliance consultancy practice. This is the intended size, and the practice is not being grown into a bigger firm. This means that you will be dealing with the person in charge of your work, not delegated around an office or prioritised based on how much you're paying.
New to any of this? ISO 27001 in plain English explains what the work is, who issues the certificate, and why it cannot be the consultant who built the system.
Advising a client who has just been asked for it? For IT providers and advisors sets out what I take on, what I never touch, and why the technical remediation comes back to you.
Fixed scope, fixed price.
Fixed scope, fixed price
Every engagement is priced before it starts and ends with named documents in your hands. No retainers, no hourly meter, and no second phase you did not agree to.
Written around how you work
Policies short enough that your team reads them, specific to how your team actually works, and owned by named people. An auditor tests a policy by asking your staff about it, so that is the test it has to pass.
If you don't need me, I'll say so
Some companies can get certified with a good checklist and a spare afternoon a week. If that's you, the scoping call ends with advice and no proposal.
Where the judgment comes from.
None of this started in information security. Eight years of records and document control inside a legal practice, two years inside AI training operations, and a psychology degree that turned out to be about how people behave around rules.
Eight years inside a law firm
Infrastructure, hiring, internal documentation and document control for a professional legal practice, in an administrative and analytical capacity rather than as legal counsel. Including the security of privileged client files, because in a firm that size somebody has to own it. That is where the habit of getting records right first time comes from.
Two years inside AI training data
Multimodal training and evaluation data for frontier generative-AI models, working to client quality rubrics under strict confidentiality. Having seen how training data is actually produced is where my interest in ISO/IEC 42001 and AI governance comes from.
Bachelor's degree in Psychology
Why people ignore rules they agreed to, and how they get talked into things. That is where most control frameworks fail. A policy nobody follows becomes a finding at the audit.
The credentials, and how to check them.
Every credential below links to its issuer's verification record. The better proof is the published engagement: thirty-five documents, open in full.
PECB Certified ISO/IEC 27001 Lead Implementer
The implementer credential for the standard this practice is built on: planning, implementing, and maintaining an ISMS.
Google Cybersecurity Professional Certificate
Grounding in the technical side of the controls the paperwork governs: networks, systems, detection and response. Delivery discipline comes from the Google Project Management certificate alongside it, which is what keeps delivery to the timeline quoted.
A published, end-to-end engagement
Thirty-five finished documents from a complete engagement, published in full. A real client's set can never be published, so the company in this one is invented and nothing in it is held back.
Bring what you're being asked for.
Either way you find out which service fits, what it costs, and whether you need a consultant at all.