Recent examples of practical, audit-ready security work
Over the past three years, Caracara Intelligence has supported organisations across multiple sectors with the design, operation, and improvement of their information security and governance frameworks.
Our work focuses on building practical, audit-ready systems that reflect how organisations actually operate — not template-driven compliance or documentation created purely for certification. We work closely with leadership and operational teams to assess risk, strengthen governance, and embed sustainable security practices.
Below are selected examples of recent engagements that show how we help organisations achieve measurable, defensible outcomes under audit and scrutiny.
Examples of the work delivered
Nine-Day ISO 27001 & ISO 9001 Recertification Recovery
A UK organisation was approaching its combined ISO 27001 and ISO 9001 recertification audit when the Chief Operating Officer, who had also been acting as Information Security Manager, was due to leave. Working alongside a local managed service provider, Caracara Intelligence took ownership of the ISMS with only nine days remaining before the external audit.
The challenge
- Only nine days remained before the recertification audit
- The existing Information Security Manager was leaving the organisation
- The ISMS had lapsed and no longer clearly reflected operational reality
- ISO-related documents were dispersed across a wider policies SharePoint site
- Two minor nonconformities from the previous audit still required closure
- A new security owner needed a clear and practical handover
What we found
- Documentation needed to be audited against how the organisation actually operated
- The Statement of Applicability required a full ISO 27001:2022 update
- Annex A controls, relevant clauses, legal requirements, and evidence locations were not presented clearly
- Core ISMS information was fragmented and difficult to navigate
- Ownership and ongoing management responsibilities needed to be formalised
The solution
- Audited the organisation and reconciled documented controls with operational reality
- Reworked the ISMS documentation to align with ISO 27001:2022 and certification-audit expectations
- Created dedicated ISMS manuals so key information was clear, coherent, and easy to maintain
- Rebuilt the Statement of Applicability for the 2022 control structure
- Added legal-requirement references, a supporting key, and clear evidence-location fields
- Closed the two minor nonconformities carried forward from the previous audit
How it was delivered
- Created a dedicated ISMS area in SharePoint and separated relevant records from unrelated policies
- Prepared a practical responsibility and handover document for the incoming security owner
- Introduced the external auditor to the new security lead and supported the transition
- Led the organisation through the audit and coordinated evidence and responses
- Provided support across the combined audit, including ISO 9001 matters outside the original remit
- Successful ISO 27001 and ISO 9001 recertification
- No major or minor nonconformities raised during the audit
- Only two opportunities for improvement, both relating to ISO 9001 evidence for SMART objectives and training
- The external auditor praised the renewed ISMS structure and supporting documentation
- A dedicated, maintainable SharePoint ISMS with clearer evidence and ownership
- A structured handover enabling the new security owner to manage ongoing responsibilities
This engagement demonstrates rapid ISMS recovery, practical document and evidence restructuring, leadership transition support, and successful management of a combined recertification audit under significant time pressure.
Full Three-Year ISO 27001 Recertification & ISMS Refresh
An organisation that had maintained ISO 27001 certification for approximately ten years was approaching its full three-year recertification audit with British Assessment Bureau. The Information Security Management System had evolved organically over time, while documentation remained largely aligned to the previous version of the standard and no longer consistently reflected current requirements or operational practice.
This was not a routine surveillance visit. It was the organisation’s full recertification assessment under UKAS-accredited certification, requiring the effectiveness, maintenance, and continued suitability of the complete ISMS to withstand detailed external audit scrutiny.
The challenge
- Prepare the complete ISMS for a full three-year recertification audit
- Replace documentation still aligned to the previous standard
- Remove accumulated legacy policies and procedures with unclear relevance
- Address limited recent internal audit coverage
- Bring risk documentation back into line with operational reality
- Demonstrate that the ISMS was effective, maintained, and embedded across the organisation
What we found
- Policies and procedures referencing superseded controls
- A Statement of Applicability requiring full review and restructuring
- Risk assessments requiring stakeholder validation and clearer treatment ownership
- An internal audit programme needing refresh to reflect current scope and risk
- Legacy documentation that obscured the evidence relevant to certification
- Opportunities to improve ownership, structure, and audit defensibility across the ISMS
The solution
- Completed a structured ISO 27001:2022 gap analysis across the full ISMS
- Updated, rationalised, and reissued the documentation set
- Reviewed and rebuilt the Statement of Applicability
- Refreshed the risk register with stakeholder input and clearer ownership
- Re-established the internal audit programme
- Strengthened the evidence base supporting the operation of key controls
- Acted as fractional Information Security Manager throughout the recertification cycle
How it was delivered
- Worked directly with leadership and operational teams
- Aligned the ISMS with how the organisation actually operated
- Removed obsolete material and clarified document ownership
- Validated risk, controls, and evidence with relevant stakeholders
- Prepared the organisation for detailed external audit questioning
- Maintained a focus on practical evidence, sustainability, and audit defensibility
- Successful completion of the full three-year ISO 27001 recertification audit
- Certification maintained following assessment by British Assessment Bureau
- Zero major nonconformities
- Zero minor nonconformities
- Zero opportunities for improvement
- A streamlined, current, and defensible ISO 27001:2022-aligned ISMS
- Clear ownership of policies, risks, controls, and supporting evidence
- Improved confidence in the ISMS as a living and sustainable management system
A completely clean outcome at a full recertification audit provided strong independent validation of the quality, effectiveness, and audit readiness of the refreshed ISMS.
ISO 27001:2017 to ISO 27001:2022 Transition & Uplift
An organisation was operating an established ISO 27001 ISMS aligned to the 2017 standard, but needed to transition to the 2022 revision while maintaining certification and meeting evolving customer and regulatory expectations.
The challenge
- Uplift the ISMS without disrupting day-to-day operations
- Maintain leadership engagement through the transition
- Ensure full compliance with the updated standard
- Refresh the internal audit approach to match the new control structure
What we found
- New and revised control requirements needed structured review
- Policy language and document structure required updating
- Governance documentation needed clearer alignment to operational reality
- The organisation required practical support to manage the transition efficiently
The solution
- Full ISO 27001:2022 gap analysis across the existing ISMS
- Updated and reissued affected documentation
- Aligned policies, procedures, and records to the 2022 control framework
- Reviewed the ISMS holistically for consistency and completeness
- Acted as fractional Information Security Manager throughout the uplift
How it was delivered
- Worked directly with the leadership team to review and approve updates
- Recommended proportionate changes rather than unnecessary bureaucracy
- Embedded changes into normal business operations
- Maintained a focus on audit readiness and sustainability
- Successful transition from ISO 27001:2017 to ISO 27001:2022
- An ISMS updated in line with current risks and operational practice
- Leadership-approved governance documentation
- Improved audit readiness and clarity of control ownership
- Confidence that the ISMS could be maintained sustainably going forward
All engagements were delivered in alignment with ISO 27001 certification requirements and focused on practical, defensible implementation rather than template-led compliance activity.
Need similar support for certification, uplift, or governance improvement?
Get in touch to discuss how Caracara Intelligence can support your organisation with practical, audit-ready information security work.
