What the work actually looked like
Completed engagement summaries and clearly labelled illustrative scenarios from Aegentra’s governance and assurance practice. Read about selected scopes, methods and reported outcomes from completed work, alongside constructed examples that explain the approach. Each record identifies which kind it is.
The Enterprise Deal That Exposed a Security Governance Gap
ISO/IEC 27001 · ISMS implementation · August 2026 · ILLUSTRATIVE COMPOSITE — not a client engagement
An illustrative composite scenario showing how a 68-person Australian B2B SaaS provider could turn fragmented controls into a working ISO/IEC 27001:2022 information security management system.
- 12 weeks — Readiness programme
- 31 — Priority remediation actions
- 9 — High risks identified
- 84 / 93 — Annex A controls applicable
Read the full the enterprise deal that exposed a security governance gap. Service: ISO 27001 implementation.
A Clause 9.2 internal audit, met with evidence
ISO 27001 · Clause 9.2 · July 2026
A small Australian technology company certified to ISO/IEC 27001:2022 needed an independent internal audit before its first surveillance audit, and could not run one in-house without breaching the impartiality requirement. All of Clauses 4 to 10 and a risk-based sample of 47 Annex A controls were audited across 73 lines of enquiry.
- 0 — Nonconformities
- 73 — Lines of enquiry
- 47 — Annex A controls
- 4 business days — Closing meeting to final report
Read the full a clause 9.2 internal audit, met with evidence. Service: ISO 27001 internal audit.
ISO 42001 certification under pressure
ISO/IEC 42001 · Certification readiness · August 2026
A mid-market SaaS provider had eight weeks to correct an AI management system built too closely from its ISO 27001 framework. The recovery programme rebuilt the AI inventory, risk method, impact assessments, accountability and supplier controls before the external audit.
- 8 weeks — To external audit
- 0 — Major nonconformities
- 2 — OFIs pre-identified
- ~180 — Staff
Read the full iso 42001 certification under pressure. Service: ISO 42001 internal audit.
The AI policy was signed by the board. The AI committee did not exist.
ISO/IEC 42001 · AI management system · August 2026 · ILLUSTRATIVE COMPOSITE — not a client engagement
An illustrative composite engagement: an underwriting and claims administration provider held a board-approved AI policy, a certified model provider and a documented human-in-the-loop control. On inspection all three were worth very little. Eight AI governance mistakes, and the nine months of work that answered an insurer principal’s operational risk review.
- 9 months — Gap assessment to certification
- 9 of 23 — Candidate systems in scope
- 71% — Model concurrence, down from 94%
- 11 — AI incidents surfaced in month one
Read the full the ai policy was signed by the board. the ai committee did not exist.. Service: ISO 42001 implementation.
How these are written — what you should be able to check
The scope is stated, not implied
What was in scope, what was sampled and on what basis. A result means nothing without the scope it was measured over — "no findings" across two controls is not the same claim as "no findings" across forty-seven.
Figures are identified by record type.
Engagement records describe completed work and report figures from that engagement. Illustrative composites use constructed scenarios to explain an approach and are labelled accordingly. Neither an individual result nor an illustrative figure is a guarantee for another organisation.
Method over outcome
Outcomes belong to the client and the day they were measured. What an engagement can genuinely demonstrate is method — the evidence obtained, the reasoning recorded, and whether matters raised were tested before being reported.
No client is named
Aegentra publishes no client name, logo or identifying detail without written approval on file. Anonymity is the default, not a gap.
These engagement summaries and illustrative scenarios explain work within Aegentra’s governance, risk and compliance practice—principally ISO 27001 implementation, ISO 27001 internal audit, ISO 42001 and SOC 2 readiness.
Want an engagement that reads like these? Fixed fee, scope agreed before the work starts, and a report you can hand to your certification body — talk to a senior consultant, or start with governance, risk and compliance.