Services
Halderstone Advisory
Build the capability to run a management system that works, and to keep it working when the requirements move
A management system that works between the audits
Strengthen the decisions a management system stands on: where accountability actually sits, which controls are proportionate to the risk rather than to the standard, what evidence is worth keeping, and how the organisation notices when a requirement has moved.
Overview
We start from where your system already is
Depending on your starting point, we support organisations in four clearly defined roles: from initial design to independent assurance and future-oriented development.
01
Design
Establish clear structures and accountability: frameworks, policies, roles and decision rights, designed for the management systems you already run
02
Operate
Make the system work in daily practice: assessments, operating processes, controls and the enablement of the people who carry them
03
Assure
Provide confidence and audit readiness: independent reviews of design and effectiveness, and preparation for internal and external scrutiny
04
Evolve
Keep the system effective as requirements and priorities change: monitoring developments, maturity assessments and executive sparring on strategic decisions
Disciplines & domains
The same work, cut two ways
Halderstone Advisory supports organisations from two complementary perspectives: by management system discipline and by cross-cutting capability domain. This helps you find support either in a specific field, such as information security or business continuity, or in a capability area such as governance, risk, control design, assurance, or improvement.
By discipline
By capability domain
Advisory in Artificial Intelligence
We help organisations establish practical governance for artificial intelligence across strategy, risk, control, accountability and assurance. This includes structuring AI management systems, embedding oversight into the AI lifecycle, and creating documentation and evidence that support responsible use, internal governance and external scrutiny.
01
Design
Establishing clear structures and accountability
AI governance framework and policy design, including AI Management Systems (AIMS) aligned with ISO/IEC 42001
Definition of roles, responsibilities and decision rights
AI system classification and risk categories
Integration into existing management systems (e.g. ISMS, QMS)
Design of documentation and evidence structures
02
Operate
Making AI governance work in daily practice
AI risk and system impact assessments
Operational processes for AI lifecycle management
Controls for data quality, model changes and human oversight
Incident and issue handling for AI-related risks
Enablement of key roles (management, product owners, compliance)
03
Assure
Providing confidence and audit readiness
Independent reviews of AI governance and AIMS structures
Control effectiveness and implementation checks
Outsourced internal audit based on ISO/IEC 42001
Certification readiness assessments
Supplier and third-party AI reviews
Preparation for internal and external audits
04
Evolve
Keeping governance effective as technology and regulation change
Monitoring regulatory and technological developments
Scenario analysis for future AI use cases
Maturity assessments and improvement roadmaps for AIMS
Executive sparring on strategic AI decisions
Integration of new requirements into existing systems
Advisory in Business Continuity
We help organisations build continuity arrangements that are credible, proportionate and workable under real disruption conditions. This includes governance, impact analysis, continuity strategies, response structures, exercising and evidence frameworks that strengthen resilience, support assurance and improve preparedness across critical products, services and operations.
01
Design
Establishing clear structures and accountability
Business continuity framework and policy design, including Business Continuity Management Systems (BCMS) aligned with ISO 22301
Definition of roles, responsibilities and decision rights
Structuring of governance for disruption management, recovery and crisis escalation
Identification of critical activities, dependencies and resilience priorities
Design of documentation, evidence and reporting structures
02
Operate
Making business continuity work in daily practice
Business impact analysis and continuity risk assessments
Development of continuity and recovery strategies
Operational processes for incident response, escalation and recovery coordination
Design and review of business continuity plans and related playbooks
Enablement of key roles across management, operations and support functions
03
Assure
Providing confidence and audit readiness
Independent reviews of BCMS design and implementation
Implementation and effectiveness checks for continuity arrangements
Outsourced internal audit based on ISO 22301
Certification readiness assessments
Review of testing, exercising and evidence structures
Preparation for internal and external audits
04
Evolve
Keeping business continuity effective as risks, dependencies and requirements change
Monitoring of regulatory, operational and organisational developments
Maturity assessments and improvement roadmaps for BCMS
Executive sparring on resilience priorities and continuity decisions
Integration of new business, technology or supplier dependencies into existing arrangements
Support for continual improvement and stronger cross-functional coordination
Advisory in Data Protection
We help organisations translate data protection requirements into workable governance, roles, processes and controls. This includes privacy management structures, risk-based assessments, operational integration across the data lifecycle, and documentation that supports accountability, regulatory expectations and sustainable compliance in day-to-day practice.
01
Design
Establishing clear data protection governance and accountability
Data protection governance framework and policy design
Definition of roles and responsibilities (e.g. controller, processor, DPO)
DPIA methodology and risk classification
Design of data inventories and processing records
Integration into existing management systems and governance structures
Design of documentation and evidence structures
02
Operate
Embedding data protection into daily practice
Execution of Data Protection Impact Assessments (DPIAs) and risk assessments
Operational processes for data protection lifecycle management
Handling of data subject requests
Incident and breach handling processes
Supplier onboarding and data processing agreements and controls
Enablement of key roles (management, legal, IT, business)
03
Assure
Providing confidence and audit readiness
Independent reviews of data protection governance
Compliance and implementation effectiveness checks
Review of Data Protection Impact Assessments (DPIAs) and other documentation
Supplier and third-party data protection reviews
Preparation for internal and external audits or regulatory reviews
04
Evolve
Keeping data protection effective as requirements and practices change
Monitoring regulatory developments and guidance
Maturity assessments and improvement roadmaps
Integration of new use cases and technologies
Scenario analysis for cross-border data processing
Executive sparring on strategic data protection decisions
Advisory in Environmental Management
We help organisations turn environmental commitments and compliance obligations into structured management practice. This includes governance, aspect and impact assessment, operational integration, performance monitoring and improvement mechanisms that make environmental management more consistent, auditable and aligned with business reality.
01
Design
Establishing clear structures and accountability
Environmental management framework and policy design, including Environmental Management Systems (EMS) aligned with ISO 14001
Definition of roles, responsibilities and decision rights
Identification of environmental aspects, obligations and risk areas
Integration into existing management systems and governance structures
Design of documentation, evidence and reporting structures
02
Operate
Making environmental management work in daily practice
Environmental aspects and impacts assessments
Operational controls for significant environmental issues
Processes for legal obligations, change management and incident handling
Monitoring arrangements for objectives, performance indicators and compliance activities
Enablement of key roles across management, operations and support functions
03
Assure
Providing confidence and audit readiness
Independent reviews of EMS design and implementation
Control effectiveness and implementation checks
Outsourced internal audit based on ISO 14001
Certification readiness assessments
Review of compliance processes, evidence and management review inputs
Preparation for internal and external audits
04
Evolve
Keeping environmental management effective as expectations and conditions change
Monitoring of regulatory, stakeholder and business developments
Maturity assessments and improvement roadmaps for EMS
Executive sparring on environmental priorities and management decisions
Integration of new requirements into existing systems and processes
Support for continual improvement and stronger cross-functional coordination
Advisory in Information Security
We help organisations strengthen information security through clear governance, risk-based prioritisation and practical control integration. This includes designing and improving ISMS structures, embedding security into operational processes, clarifying ownership and evidence, and creating an approach that supports assurance, audit readiness and effective decision-making.
01
Design
Establishing clear security governance and control structures
Information security governance and policy framework design
Definition of roles, responsibilities and decision rights
Risk assessment methodology and risk treatment approach
Security architecture and control design
Integration into existing management systems (e.g. QMS, privacy, AI governance)
Design of documentation and evidence structures
02
Operate
Making information security work in daily practice
Information security risk assessments and regular updates
Implementation of security controls and procedures
Supplier and third-party security requirements and onboarding
Incident and vulnerability handling processes
Security awareness and role enablement
Operational support for ISMS processes
03
Assure
Providing confidence and audit readiness
Independent reviews of information security governance
Control effectiveness and implementation checks
Internal audits (ISO/IEC 27001 or integrated systems)
Supplier and third-party security reviews
Audit readiness assessments and preparation support
04
Evolve
Keeping security effective as risks and environments change
Continuous risk monitoring and reassessment
Maturity assessments and improvement roadmaps
Integration of new regulatory or contractual requirements
Scenario analysis for emerging threats
Executive sparring on strategic security decisions
Advisory in Quality Management
We help organisations design and improve quality management in a way that supports reliable delivery, effective control and continual improvement. This includes governance structures, process design, performance evaluation, root-cause-oriented improvement and evidence frameworks that strengthen both operational quality and audit readiness.
01
Design
Creating clear structures for quality and operational control
Quality management framework and policy design
Definition of process ownership, roles and responsibilities
Design of process landscapes and interfaces
Risk-based quality planning and objectives
Integration with other management systems (e.g. ISMS, EMS)
Design of documentation and evidence structures
02
Operate
Making quality management work in daily practice
Operationalisation of processes and controls
Support for process owners and management
Handling of nonconformities and corrective actions
Performance indicators and quality reporting
Support for continuous improvement initiatives
Enablement of leadership and key operational roles
03
Assure
Providing confidence and audit readiness
Internal audits and independent system reviews
Effectiveness checks of processes and controls
Audit readiness assessments
Support for certification and surveillance audits
Supplier and process audits
04
Evolve
Developing quality systems as the organisation grows
Maturity assessments and improvement roadmaps
Integration of new services, products or organisational units
Scenario analysis for growth, outsourcing or restructuring
Executive sparring on operational excellence and governance
Continuous improvement system optimisation
Advisory in Governance & Strategic Framing
We support you in designing governance and strategic framing that provide clear direction, define responsibilities, and anticipate change. This ensures that management systems actively guide decisions, remain aligned over time, and do not become static or purely descriptive.
01
Design
Establishing effective governance and strategic framing
Establish governance structures and decision-making frameworks
Define roles, responsibilities, and accountabilities
Define scope and positioning of management systems
Align governance with business objectives and requirements
Design escalation paths and decision authorities
02
Operate
Running governance and decision-making in practice
Establish governance forums and decision-making routines
Prepare decision inputs, agendas, and supporting materials
Clarify roles, responsibilities, and escalation paths
Maintain governance documentation and decision records
Support leadership alignment and oversight
03
Assure
Evaluating governance effectiveness and decision practices
Conduct independent reviews of governance structures and decision processes
Assess role clarity, accountability, and escalation effectiveness
Evaluate alignment between strategy, governance, and operations
Review decision quality, consistency, and documentation
Prepare governance assessments for leadership and boards
04
Evolve
Evolving governance and strategic direction over time
Refine governance structures and decision frameworks
Adapt roles, responsibilities, and escalation models
Align with changing business priorities and external requirements
Integrate emerging developments into strategic framing
Provide executive sparring on governance and strategic direction
Advisory in Risk, Impact & Harm Analysis
We support you in building a structured approach to risk and foresight that identifies what truly matters, assesses potential impact, and enables informed prioritisation and preparedness in uncertain and evolving environments.
01
Design
Establishing structured risk and foresight capabilities
Establish risk management frameworks and processes
Define risk categories, criteria, and risk appetite
Design scenario analysis and uncertainty approaches
Integrate risk practices into strategy and planning
Design risk reporting and decision-support structures
02
Operate
Applying risk and foresight in daily operations
Perform risk identification, assessment, and prioritisation
Conduct scenario analysis and uncertainty assessments
Maintain and update risk registers
Integrate risk practices into projects and operations
Provide risk reporting and decision support for management
03
Assure
Assessing risk and foresight effectiveness
Conduct independent reviews of risk management frameworks and practices
Evaluate risk identification, assessment, and prioritisation quality
Review scenario analyses and underlying assumptions
Assess integration of risk into decision-making and planning
Prepare risk maturity assessments and management reporting
04
Evolve
Developing risk and foresight capabilities for future readiness
Monitor risks and emerging developments continuously
Refresh scenarios and forward-looking risk analyses
Adapt risk frameworks to organisational and external change
Integrate foresight into strategy and decision-making
Provide executive sparring on uncertainty, resilience, and preparedness
Advisory in Control & Operational Design
We support you in translating assessed risks and governance decisions into proportionate treatment measures, operational controls, and clear responsibilities embedded in daily work.
01
Design
Designing practical risk treatments and operational controls
Translate risk decisions into control measures
Define control objectives, types, and responsibilities
Design process-integrated control points
Align controls with workflows and system interfaces
Structure operational documentation and procedures
02
Operate
Executing controls in real operational workflows
Implement control measures and procedures
Execute controls within business processes and workflows
Monitor control performance and operational effectiveness
Handle exceptions, deviations, and control failures
Provide operational support across process interfaces and teams
03
Assure
Assessing control effectiveness and operational execution
Conduct control effectiveness reviews and implementation checks
Evaluate control design against risk and operational context
Test control execution across processes and systems
Review control evidence, traceability, and documentation
Identify gaps, weaknesses, and improvement actions
04
Evolve
Improving controls and operational design over time
Improve control measures and operational practices continuously
Adapt controls to changing risks, processes, and systems
Integrate new requirements into control frameworks
Optimise process interfaces and control effectiveness
Support scalable and resilient operational design
Advisory in Assurance, Audit & Evidence
We support you in strengthening assurance and audit approaches that go beyond checklists, focusing on meaningful evidence, credible evaluation, and clear conclusions about the effectiveness of governance and operational measures.
01
Design
Designing assurance and audit approaches
Define assurance scope, objectives, and principles
Establish audit frameworks, programmes, and methodologies
Design evidence models and evaluation criteria
Define roles, independence, and reporting lines
Integrate assurance into governance and management processes
02
Operate
Executing audits and assurance reviews
Plan audits, scope engagements, and define sampling approaches
Conduct interviews, walkthroughs, and control testing
Collect and validate evidence
Document findings, ratings, and recommendations
Communicate results and support follow-up actions
03
Assure
Assessing assurance systems and audit quality
Conduct independent reviews of assurance frameworks and audit programmes
Evaluate audit methodologies, sampling, and testing approaches
Assess evidence quality, sufficiency, and traceability
Review audit conclusions, ratings, and reporting consistency
Prepare assurance maturity assessments and improvement recommendations
04
Evolve
Improving assurance systems and audit capabilities
Improve assurance frameworks and audit programmes continuously
Enhance audit methodologies and testing approaches
Integrate new requirements into assurance and audit practices
Develop audit capabilities, tools, and approaches
Provide executive sparring on assurance strategy and positioning
Advisory in Change, Integration & Improvement
We support you in structuring change and improvement efforts so they are effectively implemented, embedded in the organisation, and sustained over time as part of normal operations.
01
Design
Structuring implementation and improvement approaches
Define change and improvement frameworks
Design implementation roadmaps and transition approaches
Structure roles, responsibilities, and governance for change
Integrate change into existing management systems and processes
Define success criteria, metrics, and feedback mechanisms
02
Operate
Driving change and improvement initiatives
Execute implementation activities across teams and functions
Track progress, manage dependencies, and handle issues
Coordinate stakeholders and support alignment
Deliver communication, training, and role enablement
Embed changes into operational practice
03
Assure
Evaluating implementation and improvement effectiveness
Review implementation progress and outcome achievement
Assess adoption, integration, and sustainability of changes
Evaluate improvement initiatives against defined objectives
Identify barriers, gaps, and corrective actions
Report on effectiveness and improvement performance
04
Evolve
Strengthening change and improvement capabilities
Improve change and implementation approaches continuously
Adapt frameworks to organisational and strategic evolution
Integrate lessons learned into future initiatives
Develop improvement roadmaps and capabilities
Support long-term adoption and organisational resilience
Advisory in Strategic Decision & Value Architecture
We support you in applying structured decision analysis to make assumptions explicit, compare alternatives systematically, and develop defensible recommendations in situations with competing objectives and incomplete information.
01
Design
Establishing structured decision-making approaches
Define decision scope, objectives, and framing
Design decision processes and evaluation frameworks
Structure criteria, trade-offs, and value drivers
Integrate scenarios, assumptions, and uncertainty
Design decision documentation and communication formats
02
Operate
Running structured decision processes
Structure decisions and provide facilitation support
Develop and compare decision alternatives
Apply evaluation criteria and trade-off analysis
Analyse assumptions, scenarios, and uncertainty
Prepare decision materials and management recommendations
03
Assure
Assessing decision quality and analytical rigour
Review decision processes and structuring approaches
Evaluate assumptions, scenarios, and uncertainty treatment
Assess criteria, trade-offs, and evaluation logic
Review decision documentation and transparency
Identify biases, gaps, and improvement opportunities
04
Evolve
Advancing decision-making capabilities over time
Improve decision frameworks and practices continuously
Integrate new methods, models, and analytical approaches
Adapt decision processes to changing contexts
Refresh scenarios and refine assumptions
Provide executive sparring on strategic decisions and long-term value
Why Halderstone
The aim is that you stop needing us
Advisory ends. What it leaves behind should not depend on us being reachable. What follows is how we work towards that, and which mandates we decline because they work against it.
Our approach
Engagements scoped to what your organisation can carry, not to what a framework lists
Policies, roles and decision rights written for how your organisation actually decides
The people who will run the system are part of the engagement, not its audience
Structures your team can maintain and change without us
Advice pointed at a design that survives independent scrutiny
What we deliberately do not do
Operate the system instead of enabling your people to run it
Hand over templates instead of helping you decide
Accept mandates where top management does not intend to carry the system, unless aligning them is the mandate itself
Take advisory mandates that arise from our own audit findings
Related audit services
What checks the result, and who may do it
Advisory helps you build and improve the system. An audit is the independent check on whether it works, and deliberately not the same engagement.
The two stay apart on the same system: we do not audit what we have built, and we do not take on the improvement work our own findings call for. Reviewing our own design would be reviewing ourselves, and selling the remedy would give us an interest in the finding. Beyond that, we avoid conflicts of interest as a matter of course.
Discuss your challenge
A short conversation to understand your current situation and discuss possible next steps.
Halderstone Academy
Halderstone Academy offers focused training modules on related topics.
The model behind it
The disciplines and capability domains above are the capability framework, the vocabulary behind every module and track.