Resources · Case Studies

Case Studies

Real outcomes from our independent audits and assessments across PCI, ISO, AI and SOC. Clients are anonymised unless they’ve chosen to be named.

ISO/IEC 27001 + 27701 New Zealand first

Qrious Ltd — the first company in New Zealand to achieve “security with privacy” certification

Named client · Data & analytics
Challenge

Qrious wanted to prove, to the highest bar, that it manages both information security and personal data responsibly — not one or the other, but both together.

What we did

We delivered an integrated audit of their Information Security Management System (ISO/IEC 27001) alongside their Privacy Information Management System (ISO/IEC 27701), reusing evidence across both to keep the process efficient.

Outcome: certified to ISO/IEC 27001 and 27701 together — making Qrious Ltd the first organisation in New Zealand to hold this combined “security with privacy” certification.
PCI DSS

Keeping legacy systems compliant with compensating controls

Anonymised · Payments / merchant
Challenge

Business-critical legacy systems couldn’t meet every PCI DSS requirement directly, and replacing them outright wasn’t realistic in the timeframe.

What we did

Our QSA-led PCI DSS assessment pinpointed where requirements couldn’t be met natively, then validated robust compensating controls that satisfied the intent and rigour of each requirement.

Outcome: full PCI DSS compliance — without a costly rip-and-replace — plus a clear roadmap to modernise the legacy estate over time.
PCI DSS

From “the cloud isn’t safe for finance” to PCI DSS compliant on AWS

Anonymised · Financial services
Challenge

The client was wary of running financial services workloads on AWS, unsure whether the cloud could be secure and compliant.

What we did

Our PCI DSS assessment worked through the AWS shared-responsibility model, validated their cloud controls, and surfaced practical security improvements along the way.

Outcome: PCI DSS compliance achieved on AWS — and a measurably stronger security posture that turned cloud hesitation into confidence.
ISO/IEC 42001

Governing the adoption of AI, responsibly

Anonymised · Australian technology company
Challenge

An Australian company adopting AI needed to show customers and regulators that its AI was governed responsibly — not just deployed quickly.

What we did

We audited their AI Management System against ISO/IEC 42001, the first international standard for responsible AI governance.

Outcome: certified to ISO/IEC 42001 — an early-mover signal of trustworthy, well-governed AI adoption.
SOC 2

SOC 2 delivered in two months to meet a contract deadline

Anonymised · SaaS / technology
Challenge

A contractual clause required the client to hold a SOC 2 report within a tight, fixed window — miss it, and the customer relationship was at risk.

What we did

We ran a focused, tightly-scoped SOC 2 assessment, prioritising readiness and evidence-gathering to hit the deadline without cutting corners.

Outcome: SOC 2 achieved within two months — meeting the contractual obligation on time.