Skip to main content

/ Delivery team and assurance

Who does the work is agreed before the work begins.

Every Aegentra engagement has an accountable lead. The written scope identifies the delivery functions required, who is assigned to them, what each function is responsible for and where implementation, internal audit and certification remain separate.

/ Delivery model

Named accountability, with support matched to the scope.

Aegentra does not use a generic headcount claim as a substitute for an engagement plan. A role may be performed by the principal consultant or by an appropriately engaged specialist. The written scope identifies the people assigned, the function each will perform and the relationship relevant to that assignment.

Not every engagement uses every role. Additional functions are included only where the agreed work requires them, and responsibility stays with the person assigned to that function.

/ Role registry

Functions assigned to the engagement.

These are delivery functions, not a claim that every function is always a separate employee or appears on every scope.

Role

Principal consultant — Harry Sidhu

Engagement scoping, implementation leadership and accountable delivery oversight.

Responsibility

Confirms the written scope, delivery boundary, assigned roles and client responsibilities.

Evidence disclosed

Current company-authorised role and engagement accountability.

Role

Assigned auditor

Separately scoped ISO management-system internal audits where objectivity can be protected.

Responsibility

Plans fieldwork, samples evidence and retains responsibility for audit judgements and conclusions.

Evidence disclosed

Identity, relevant competence and prior involvement are confirmed for the engagement before fieldwork.

Role

Implementation or technical specialist

Control, platform or subject-matter work only where the agreed scope requires additional depth.

Responsibility

Performs the specialist function recorded in the scope without taking responsibility outside that function.

Evidence disclosed

The function, relationship, responsibility and relevant competence are disclosed before specialist work begins.

Role

Quality review

Engagements where a separate review function is included in the written scope.

Responsibility

Checks that requirements, evidence, findings and conclusions remain traceable before an agreed report is issued.

Evidence disclosed

The review responsibility and assigned person are recorded for the engagement.

Harry Sidhu is accountable for engagement scoping and delivery oversight. The written proposal identifies the people assigned to your engagement, their responsibilities and the relevant competence evidence. Where internal audit is included, prior involvement and impartiality are checked before fieldwork begins.

/ Delivery team capability

Experienced and qualified for complex assurance work

Aegentra’s delivery team combines senior experience across IT audit, cybersecurity governance, enterprise risk, internal controls and management systems.

Qualifications, professional credentials and formal training held across Aegentra’s delivery team.

Team qualifications and credentials

Management systems and audit

  • ISO/IEC 27001 Lead Implementer
  • PECB ISO/IEC 27001 Lead Auditor
  • ISO/IEC 42001 Lead Auditor
  • CISA — Certified Information Systems Auditor
  • ISM Auditor

Cybersecurity and cloud

  • CISSP — Certified Information Systems Security Professional
  • CISM — Certified Information Security Manager
  • Certificate of Cloud Security Knowledge (CCSK)
  • OSCP+ — OffSec Certified Professional Plus

Service delivery and specialist training

  • ITIL Expert
  • PRINCE2
  • Mastering Generative AI for Cybersecurity Certificate
  • Essential Eight Assessment Course certificate — TAFEcyber

Further training and audit qualifications across the team include ISO/IEC 42001 Lead Implementer training, ASD ISM General and Technical audit codes, ISO/IEC 27017 and ISO/IEC 27018 audit codes, and ISO 9001 and ISO 19011 audit qualifications.

Personnel security clearance

NV1 Security Clearance

NV1 security clearance is held within the team. It is a personnel clearance, not a company accreditation or government endorsement. Any clearance requirement and the assigned consultant’s current status are confirmed for the engagement.

Credentials are held across the team and matched to assigned roles. Your proposal identifies the consultants, their responsibilities and the relevant qualification evidence before work begins.

Aegentra’s delivery team brings more than two decades of professional experience across IT audit, cybersecurity governance, enterprise risk and internal controls. Across their professional careers, team members have delivered 2,000+ hours of ISO, ASD ISM and GRC audit work across 70+ organisations in government, finance, healthcare, defence, manufacturing, technology, not-for-profit and logistics.

For every engagement, Aegentra selects the team members whose experience and qualifications match the agreed scope. Your proposal identifies the accountable lead, supporting consultants, responsibilities, independence requirements and applicable qualification evidence before work begins.

Specialist functions available by agreed scope

Available by agreed scope

Senior information security and GRC auditor

Supports agreed information-security audit, security-governance, technology-risk, IT-control and assurance work.

Relevant subject areas

  • ISO 27001
  • ISO 27017
  • ISO 27018
  • ASD ISM
  • NIST Cybersecurity Framework
  • SOX and ITGC

Confirmed before assignment

Before assignment, Aegentra confirms the consultant’s identity, relationship, scope-relevant experience, current credential evidence, availability, prior involvement and conflicts.

Available by agreed scope

Integrated management systems consultant

Supports agreed management-system design, documentation, risk, compliance, implementation and internal-audit work.

Relevant subject areas

  • ISO 27001
  • ISO 9001
  • ISO 14001
  • ISO 45001
  • ISO 17025
  • ISO 31000

Confirmed before assignment

Before assignment, Aegentra confirms the consultant’s identity, relationship, scope-relevant experience and training evidence, availability, prior involvement and conflicts.

Qualifications and experience are held across the delivery team and matched to assigned roles; this does not mean every team member holds every credential. If the required competence, current qualification evidence, availability or objectivity cannot be confirmed, that person is not assigned.

/ Independence and decision rights

Building, auditing and certifying are different responsibilities.

Implementation

The implementation scope identifies what Aegentra will build, configure or document and what remains the client’s responsibility.

Internal audit

Internal-audit work is accepted only after the intended scope, prior involvement, objectivity and assigned audit responsibilities are checked.

Certification

Aegentra does not issue ISO certification. An independent accredited certification body performs the certification audit and makes the decision.

/ Before delivery begins

The assignment follows a checkable path.

  1. Scope agreed
  2. Conflicts checked
  3. Roles assigned
  4. Evidence confirmed

Ask for the assigned roles, responsibilities and assurance boundary in your written proposal before approving the engagement.

Discuss your scope