Services

Halderstone Advisory

Build the capability to run a management system that works, and to keep it working when the requirements move

A management system that works between the audits

Strengthen the decisions a management system stands on: where accountability actually sits, which controls are proportionate to the risk rather than to the standard, what evidence is worth keeping, and how the organisation notices when a requirement has moved.

Overview

We start from where your system already is

Depending on your starting point, we support organisations in four clearly defined roles: from initial design to independent assurance and future-oriented development.

  1. 01

    Design

    Establish clear structures and accountability: frameworks, policies, roles and decision rights, designed for the management systems you already run

  2. 02

    Operate

    Make the system work in daily practice: assessments, operating processes, controls and the enablement of the people who carry them

  3. 03

    Assure

    Provide confidence and audit readiness: independent reviews of design and effectiveness, and preparation for internal and external scrutiny

  4. 04

    Evolve

    Keep the system effective as requirements and priorities change: monitoring developments, maturity assessments and executive sparring on strategic decisions

Disciplines & domains

The same work, cut two ways

Halderstone Advisory supports organisations from two complementary perspectives: by management system discipline and by cross-cutting capability domain. This helps you find support either in a specific field, such as information security or business continuity, or in a capability area such as governance, risk, control design, assurance, or improvement.

Advisory in Artificial Intelligence

We help organisations establish practical governance for artificial intelligence across strategy, risk, control, accountability and assurance. This includes structuring AI management systems, embedding oversight into the AI lifecycle, and creating documentation and evidence that support responsible use, internal governance and external scrutiny.

  1. 01

    Design

    Establishing clear structures and accountability

    AI governance framework and policy design, including AI Management Systems (AIMS) aligned with ISO/IEC 42001

    Definition of roles, responsibilities and decision rights

    AI system classification and risk categories

    Integration into existing management systems (e.g. ISMS, QMS)

    Design of documentation and evidence structures

  2. 02

    Operate

    Making AI governance work in daily practice

    AI risk and system impact assessments

    Operational processes for AI lifecycle management

    Controls for data quality, model changes and human oversight

    Incident and issue handling for AI-related risks

    Enablement of key roles (management, product owners, compliance)

  3. 03

    Assure

    Providing confidence and audit readiness

    Independent reviews of AI governance and AIMS structures

    Control effectiveness and implementation checks

    Outsourced internal audit based on ISO/IEC 42001

    Certification readiness assessments

    Supplier and third-party AI reviews

    Preparation for internal and external audits

  4. 04

    Evolve

    Keeping governance effective as technology and regulation change

    Monitoring regulatory and technological developments

    Scenario analysis for future AI use cases

    Maturity assessments and improvement roadmaps for AIMS

    Executive sparring on strategic AI decisions

    Integration of new requirements into existing systems

Advisory in Business Continuity

We help organisations build continuity arrangements that are credible, proportionate and workable under real disruption conditions. This includes governance, impact analysis, continuity strategies, response structures, exercising and evidence frameworks that strengthen resilience, support assurance and improve preparedness across critical products, services and operations.

  1. 01

    Design

    Establishing clear structures and accountability

    Business continuity framework and policy design, including Business Continuity Management Systems (BCMS) aligned with ISO 22301

    Definition of roles, responsibilities and decision rights

    Structuring of governance for disruption management, recovery and crisis escalation

    Identification of critical activities, dependencies and resilience priorities

    Design of documentation, evidence and reporting structures

  2. 02

    Operate

    Making business continuity work in daily practice

    Business impact analysis and continuity risk assessments

    Development of continuity and recovery strategies

    Operational processes for incident response, escalation and recovery coordination

    Design and review of business continuity plans and related playbooks

    Enablement of key roles across management, operations and support functions

  3. 03

    Assure

    Providing confidence and audit readiness

    Independent reviews of BCMS design and implementation

    Implementation and effectiveness checks for continuity arrangements

    Outsourced internal audit based on ISO 22301

    Certification readiness assessments

    Review of testing, exercising and evidence structures

    Preparation for internal and external audits

  4. 04

    Evolve

    Keeping business continuity effective as risks, dependencies and requirements change

    Monitoring of regulatory, operational and organisational developments

    Maturity assessments and improvement roadmaps for BCMS

    Executive sparring on resilience priorities and continuity decisions

    Integration of new business, technology or supplier dependencies into existing arrangements

    Support for continual improvement and stronger cross-functional coordination

Advisory in Data Protection

We help organisations translate data protection requirements into workable governance, roles, processes and controls. This includes privacy management structures, risk-based assessments, operational integration across the data lifecycle, and documentation that supports accountability, regulatory expectations and sustainable compliance in day-to-day practice.

  1. 01

    Design

    Establishing clear data protection governance and accountability

    Data protection governance framework and policy design

    Definition of roles and responsibilities (e.g. controller, processor, DPO)

    DPIA methodology and risk classification

    Design of data inventories and processing records

    Integration into existing management systems and governance structures

    Design of documentation and evidence structures

  2. 02

    Operate

    Embedding data protection into daily practice

    Execution of Data Protection Impact Assessments (DPIAs) and risk assessments

    Operational processes for data protection lifecycle management

    Handling of data subject requests

    Incident and breach handling processes

    Supplier onboarding and data processing agreements and controls

    Enablement of key roles (management, legal, IT, business)

  3. 03

    Assure

    Providing confidence and audit readiness

    Independent reviews of data protection governance

    Compliance and implementation effectiveness checks

    Review of Data Protection Impact Assessments (DPIAs) and other documentation

    Supplier and third-party data protection reviews

    Preparation for internal and external audits or regulatory reviews

  4. 04

    Evolve

    Keeping data protection effective as requirements and practices change

    Monitoring regulatory developments and guidance

    Maturity assessments and improvement roadmaps

    Integration of new use cases and technologies

    Scenario analysis for cross-border data processing

    Executive sparring on strategic data protection decisions

Advisory in Environmental Management

We help organisations turn environmental commitments and compliance obligations into structured management practice. This includes governance, aspect and impact assessment, operational integration, performance monitoring and improvement mechanisms that make environmental management more consistent, auditable and aligned with business reality.

  1. 01

    Design

    Establishing clear structures and accountability

    Environmental management framework and policy design, including Environmental Management Systems (EMS) aligned with ISO 14001

    Definition of roles, responsibilities and decision rights

    Identification of environmental aspects, obligations and risk areas

    Integration into existing management systems and governance structures

    Design of documentation, evidence and reporting structures

  2. 02

    Operate

    Making environmental management work in daily practice

    Environmental aspects and impacts assessments

    Operational controls for significant environmental issues

    Processes for legal obligations, change management and incident handling

    Monitoring arrangements for objectives, performance indicators and compliance activities

    Enablement of key roles across management, operations and support functions

  3. 03

    Assure

    Providing confidence and audit readiness

    Independent reviews of EMS design and implementation

    Control effectiveness and implementation checks

    Outsourced internal audit based on ISO 14001

    Certification readiness assessments

    Review of compliance processes, evidence and management review inputs

    Preparation for internal and external audits

  4. 04

    Evolve

    Keeping environmental management effective as expectations and conditions change

    Monitoring of regulatory, stakeholder and business developments

    Maturity assessments and improvement roadmaps for EMS

    Executive sparring on environmental priorities and management decisions

    Integration of new requirements into existing systems and processes

    Support for continual improvement and stronger cross-functional coordination

Advisory in Information Security

We help organisations strengthen information security through clear governance, risk-based prioritisation and practical control integration. This includes designing and improving ISMS structures, embedding security into operational processes, clarifying ownership and evidence, and creating an approach that supports assurance, audit readiness and effective decision-making.

  1. 01

    Design

    Establishing clear security governance and control structures

    Information security governance and policy framework design

    Definition of roles, responsibilities and decision rights

    Risk assessment methodology and risk treatment approach

    Security architecture and control design

    Integration into existing management systems (e.g. QMS, privacy, AI governance)

    Design of documentation and evidence structures

  2. 02

    Operate

    Making information security work in daily practice

    Information security risk assessments and regular updates

    Implementation of security controls and procedures

    Supplier and third-party security requirements and onboarding

    Incident and vulnerability handling processes

    Security awareness and role enablement

    Operational support for ISMS processes

  3. 03

    Assure

    Providing confidence and audit readiness

    Independent reviews of information security governance

    Control effectiveness and implementation checks

    Internal audits (ISO/IEC 27001 or integrated systems)

    Supplier and third-party security reviews

    Audit readiness assessments and preparation support

  4. 04

    Evolve

    Keeping security effective as risks and environments change

    Continuous risk monitoring and reassessment

    Maturity assessments and improvement roadmaps

    Integration of new regulatory or contractual requirements

    Scenario analysis for emerging threats

    Executive sparring on strategic security decisions

Advisory in Quality Management

We help organisations design and improve quality management in a way that supports reliable delivery, effective control and continual improvement. This includes governance structures, process design, performance evaluation, root-cause-oriented improvement and evidence frameworks that strengthen both operational quality and audit readiness.

  1. 01

    Design

    Creating clear structures for quality and operational control

    Quality management framework and policy design

    Definition of process ownership, roles and responsibilities

    Design of process landscapes and interfaces

    Risk-based quality planning and objectives

    Integration with other management systems (e.g. ISMS, EMS)

    Design of documentation and evidence structures

  2. 02

    Operate

    Making quality management work in daily practice

    Operationalisation of processes and controls

    Support for process owners and management

    Handling of nonconformities and corrective actions

    Performance indicators and quality reporting

    Support for continuous improvement initiatives

    Enablement of leadership and key operational roles

  3. 03

    Assure

    Providing confidence and audit readiness

    Internal audits and independent system reviews

    Effectiveness checks of processes and controls

    Audit readiness assessments

    Support for certification and surveillance audits

    Supplier and process audits

  4. 04

    Evolve

    Developing quality systems as the organisation grows

    Maturity assessments and improvement roadmaps

    Integration of new services, products or organisational units

    Scenario analysis for growth, outsourcing or restructuring

    Executive sparring on operational excellence and governance

    Continuous improvement system optimisation

Advisory in Governance & Strategic Framing

We support you in designing governance and strategic framing that provide clear direction, define responsibilities, and anticipate change. This ensures that management systems actively guide decisions, remain aligned over time, and do not become static or purely descriptive.

  1. 01

    Design

    Establishing effective governance and strategic framing

    Establish governance structures and decision-making frameworks

    Define roles, responsibilities, and accountabilities

    Define scope and positioning of management systems

    Align governance with business objectives and requirements

    Design escalation paths and decision authorities

  2. 02

    Operate

    Running governance and decision-making in practice

    Establish governance forums and decision-making routines

    Prepare decision inputs, agendas, and supporting materials

    Clarify roles, responsibilities, and escalation paths

    Maintain governance documentation and decision records

    Support leadership alignment and oversight

  3. 03

    Assure

    Evaluating governance effectiveness and decision practices

    Conduct independent reviews of governance structures and decision processes

    Assess role clarity, accountability, and escalation effectiveness

    Evaluate alignment between strategy, governance, and operations

    Review decision quality, consistency, and documentation

    Prepare governance assessments for leadership and boards

  4. 04

    Evolve

    Evolving governance and strategic direction over time

    Refine governance structures and decision frameworks

    Adapt roles, responsibilities, and escalation models

    Align with changing business priorities and external requirements

    Integrate emerging developments into strategic framing

    Provide executive sparring on governance and strategic direction

Advisory in Risk, Impact & Harm Analysis

We support you in building a structured approach to risk and foresight that identifies what truly matters, assesses potential impact, and enables informed prioritisation and preparedness in uncertain and evolving environments.

  1. 01

    Design

    Establishing structured risk and foresight capabilities

    Establish risk management frameworks and processes

    Define risk categories, criteria, and risk appetite

    Design scenario analysis and uncertainty approaches

    Integrate risk practices into strategy and planning

    Design risk reporting and decision-support structures

  2. 02

    Operate

    Applying risk and foresight in daily operations

    Perform risk identification, assessment, and prioritisation

    Conduct scenario analysis and uncertainty assessments

    Maintain and update risk registers

    Integrate risk practices into projects and operations

    Provide risk reporting and decision support for management

  3. 03

    Assure

    Assessing risk and foresight effectiveness

    Conduct independent reviews of risk management frameworks and practices

    Evaluate risk identification, assessment, and prioritisation quality

    Review scenario analyses and underlying assumptions

    Assess integration of risk into decision-making and planning

    Prepare risk maturity assessments and management reporting

  4. 04

    Evolve

    Developing risk and foresight capabilities for future readiness

    Monitor risks and emerging developments continuously

    Refresh scenarios and forward-looking risk analyses

    Adapt risk frameworks to organisational and external change

    Integrate foresight into strategy and decision-making

    Provide executive sparring on uncertainty, resilience, and preparedness

Advisory in Control & Operational Design

We support you in translating assessed risks and governance decisions into proportionate treatment measures, operational controls, and clear responsibilities embedded in daily work.

  1. 01

    Design

    Designing practical risk treatments and operational controls

    Translate risk decisions into control measures

    Define control objectives, types, and responsibilities

    Design process-integrated control points

    Align controls with workflows and system interfaces

    Structure operational documentation and procedures

  2. 02

    Operate

    Executing controls in real operational workflows

    Implement control measures and procedures

    Execute controls within business processes and workflows

    Monitor control performance and operational effectiveness

    Handle exceptions, deviations, and control failures

    Provide operational support across process interfaces and teams

  3. 03

    Assure

    Assessing control effectiveness and operational execution

    Conduct control effectiveness reviews and implementation checks

    Evaluate control design against risk and operational context

    Test control execution across processes and systems

    Review control evidence, traceability, and documentation

    Identify gaps, weaknesses, and improvement actions

  4. 04

    Evolve

    Improving controls and operational design over time

    Improve control measures and operational practices continuously

    Adapt controls to changing risks, processes, and systems

    Integrate new requirements into control frameworks

    Optimise process interfaces and control effectiveness

    Support scalable and resilient operational design

Advisory in Assurance, Audit & Evidence

We support you in strengthening assurance and audit approaches that go beyond checklists, focusing on meaningful evidence, credible evaluation, and clear conclusions about the effectiveness of governance and operational measures.

  1. 01

    Design

    Designing assurance and audit approaches

    Define assurance scope, objectives, and principles

    Establish audit frameworks, programmes, and methodologies

    Design evidence models and evaluation criteria

    Define roles, independence, and reporting lines

    Integrate assurance into governance and management processes

  2. 02

    Operate

    Executing audits and assurance reviews

    Plan audits, scope engagements, and define sampling approaches

    Conduct interviews, walkthroughs, and control testing

    Collect and validate evidence

    Document findings, ratings, and recommendations

    Communicate results and support follow-up actions

  3. 03

    Assure

    Assessing assurance systems and audit quality

    Conduct independent reviews of assurance frameworks and audit programmes

    Evaluate audit methodologies, sampling, and testing approaches

    Assess evidence quality, sufficiency, and traceability

    Review audit conclusions, ratings, and reporting consistency

    Prepare assurance maturity assessments and improvement recommendations

  4. 04

    Evolve

    Improving assurance systems and audit capabilities

    Improve assurance frameworks and audit programmes continuously

    Enhance audit methodologies and testing approaches

    Integrate new requirements into assurance and audit practices

    Develop audit capabilities, tools, and approaches

    Provide executive sparring on assurance strategy and positioning

Advisory in Change, Integration & Improvement

We support you in structuring change and improvement efforts so they are effectively implemented, embedded in the organisation, and sustained over time as part of normal operations.

  1. 01

    Design

    Structuring implementation and improvement approaches

    Define change and improvement frameworks

    Design implementation roadmaps and transition approaches

    Structure roles, responsibilities, and governance for change

    Integrate change into existing management systems and processes

    Define success criteria, metrics, and feedback mechanisms

  2. 02

    Operate

    Driving change and improvement initiatives

    Execute implementation activities across teams and functions

    Track progress, manage dependencies, and handle issues

    Coordinate stakeholders and support alignment

    Deliver communication, training, and role enablement

    Embed changes into operational practice

  3. 03

    Assure

    Evaluating implementation and improvement effectiveness

    Review implementation progress and outcome achievement

    Assess adoption, integration, and sustainability of changes

    Evaluate improvement initiatives against defined objectives

    Identify barriers, gaps, and corrective actions

    Report on effectiveness and improvement performance

  4. 04

    Evolve

    Strengthening change and improvement capabilities

    Improve change and implementation approaches continuously

    Adapt frameworks to organisational and strategic evolution

    Integrate lessons learned into future initiatives

    Develop improvement roadmaps and capabilities

    Support long-term adoption and organisational resilience

Advisory in Strategic Decision & Value Architecture

We support you in applying structured decision analysis to make assumptions explicit, compare alternatives systematically, and develop defensible recommendations in situations with competing objectives and incomplete information.

  1. 01

    Design

    Establishing structured decision-making approaches

    Define decision scope, objectives, and framing

    Design decision processes and evaluation frameworks

    Structure criteria, trade-offs, and value drivers

    Integrate scenarios, assumptions, and uncertainty

    Design decision documentation and communication formats

  2. 02

    Operate

    Running structured decision processes

    Structure decisions and provide facilitation support

    Develop and compare decision alternatives

    Apply evaluation criteria and trade-off analysis

    Analyse assumptions, scenarios, and uncertainty

    Prepare decision materials and management recommendations

  3. 03

    Assure

    Assessing decision quality and analytical rigour

    Review decision processes and structuring approaches

    Evaluate assumptions, scenarios, and uncertainty treatment

    Assess criteria, trade-offs, and evaluation logic

    Review decision documentation and transparency

    Identify biases, gaps, and improvement opportunities

  4. 04

    Evolve

    Advancing decision-making capabilities over time

    Improve decision frameworks and practices continuously

    Integrate new methods, models, and analytical approaches

    Adapt decision processes to changing contexts

    Refresh scenarios and refine assumptions

    Provide executive sparring on strategic decisions and long-term value

Why Halderstone

The aim is that you stop needing us

Advisory ends. What it leaves behind should not depend on us being reachable. What follows is how we work towards that, and which mandates we decline because they work against it.

Our approach

Engagements scoped to what your organisation can carry, not to what a framework lists

Policies, roles and decision rights written for how your organisation actually decides

The people who will run the system are part of the engagement, not its audience

Structures your team can maintain and change without us

Advice pointed at a design that survives independent scrutiny

What we deliberately do not do

Operate the system instead of enabling your people to run it

Hand over templates instead of helping you decide

Accept mandates where top management does not intend to carry the system, unless aligning them is the mandate itself

Take advisory mandates that arise from our own audit findings

Related audit services

What checks the result, and who may do it

Advisory helps you build and improve the system. An audit is the independent check on whether it works, and deliberately not the same engagement.

The two stay apart on the same system: we do not audit what we have built, and we do not take on the improvement work our own findings call for. Reviewing our own design would be reviewing ourselves, and selling the remedy would give us an interest in the finding. Beyond that, we avoid conflicts of interest as a matter of course.

How audits work →

Discuss your challenge

A short conversation to understand your current situation and discuss possible next steps.

Halderstone Academy

Halderstone Academy offers focused training modules on related topics.

The model behind it

The disciplines and capability domains above are the capability framework, the vocabulary behind every module and track.

Free · no obligation

Thirty minutes to understand your situation and what you are trying to achieve. No preparation needed on your side.

Length
30 minutes
Where
Video call · link sent by email
Afterwards
Possible next steps, in writing

Prefer to write instead?

Pick a timeYour details

Times shown in
Zurich

The calendar cannot be reached just now. Please send a written brief instead.

Nothing suitable?