Case Studies
Real outcomes from our independent audits and assessments across PCI, ISO, AI and SOC. Clients are anonymised unless they’ve chosen to be named.
Qrious Ltd — the first company in New Zealand to achieve “security with privacy” certification
Qrious wanted to prove, to the highest bar, that it manages both information security and personal data responsibly — not one or the other, but both together.
We delivered an integrated audit of their Information Security Management System (ISO/IEC 27001) alongside their Privacy Information Management System (ISO/IEC 27701), reusing evidence across both to keep the process efficient.
Keeping legacy systems compliant with compensating controls
Business-critical legacy systems couldn’t meet every PCI DSS requirement directly, and replacing them outright wasn’t realistic in the timeframe.
Our QSA-led PCI DSS assessment pinpointed where requirements couldn’t be met natively, then validated robust compensating controls that satisfied the intent and rigour of each requirement.
From “the cloud isn’t safe for finance” to PCI DSS compliant on AWS
The client was wary of running financial services workloads on AWS, unsure whether the cloud could be secure and compliant.
Our PCI DSS assessment worked through the AWS shared-responsibility model, validated their cloud controls, and surfaced practical security improvements along the way.
Governing the adoption of AI, responsibly
An Australian company adopting AI needed to show customers and regulators that its AI was governed responsibly — not just deployed quickly.
We audited their AI Management System against ISO/IEC 42001, the first international standard for responsible AI governance.
SOC 2 delivered in two months to meet a contract deadline
A contractual clause required the client to hold a SOC 2 report within a tight, fixed window — miss it, and the customer relationship was at risk.
We ran a focused, tightly-scoped SOC 2 assessment, prioritising readiness and evidence-gathering to hit the deadline without cutting corners.
