Services

Halderstone Audit Services

Find out whether your system is working as intended, while there is still time to do something about it

Findings people act on, not a report that files itself

Every conclusion rests on corroborated evidence across multiple sources and methods, and the reporting is built for decisions and improvement. It is the same discipline our academy trains auditors in.

Overview

We assess whether your system works as intended

Halderstone Audit Services supports organisations with independent assessments across selected management system disciplines. These services help you understand whether governance structures, controls, processes, and compliance arrangements are working as intended.

Engagement types

Internal audits

Readiness assessments

Supplier reviews

Governance reviews

Compliance reviews

Integrated audits across management systems

By discipline

The method is the same; what is at stake is not

What changes between disciplines is what is at stake and which requirements bind: an information security audit and an environmental audit ask different questions of different evidence. Planning, corroboration and reporting do not.

Artificial Intelligence

An AI governance audit asks whether the oversight bites: whether the risks identified are the ones the deployed systems actually create, whether the controls hold across a change of model or supplier, and whether anyone would notice if they stopped working.

Supported frameworks

ISO/IEC 42001

EU AI Act

NIST AI RMF

OECD AI Principles

Internal AI governance frameworks

Business Continuity

A BCM system audit asks whether the arrangements would hold: whether the impact analysis still matches the business, whether the strategies close the gap it identifies, and whether the exercises were hard enough to fail.

Supported frameworks

ISO 22301

ISO 22313

NIST SP 800-34

DORA

Organisation-specific continuity frameworks

Data Protection

A privacy programme audit follows the risk to people rather than the paperwork: whether that risk drives the controls, whether the controls survive a change of purpose or supplier, and whether the reviews would find a gap before a data subject does.

Supported frameworks

EU GDPR

Swiss Federal Act on Data Protection (FADP)

ISO/IEC 27701

ISO/IEC 27001 and ISO/IEC 27002

NIST Privacy Framework

Organisation-specific privacy and data protection frameworks

Environmental Management

An EMS audit looks past compliance to effect: whether the significant aspects drive the objectives, whether operational control changes what happens on site, and whether the reviews would catch a drift before someone outside does.

Supported frameworks

ISO 14001

ISO 14004

ISO 14031

EMAS

Organisation-specific environmental management and compliance frameworks

Information Security

An ISMS audit tests effectiveness rather than coverage: whether the risks named are the risks actually run, whether the controls chosen against them reduce the exposure, and whether the reviews would notice if they stopped working.

Supported frameworks

ISO/IEC 27001 and ISO/IEC 27002

ISO/IEC 27005

NIST Cybersecurity Framework

CIS Controls

DORA

Organisation-specific information security frameworks

Quality Management

A QMS audit asks whether the system changes what happens: whether the quality objectives reach the processes that deliver them, whether the controls on those processes hold when volume rises, and whether an improvement changed a result.

Supported frameworks

ISO 9001

ISO 9004

ISO 19011

Customer-specific quality requirements

Industry-specific quality management frameworks

Organisation-specific quality management frameworks

Why Halderstone

Independence and evidence are not things an audit can borrow

An audit is worth what its evidence can carry. What follows is how conclusions are built here, and which engagements we decline in order to keep them worth something.

Our approach

Audit planning informed by risks, objectives, and the intended use of audit results

Audit activities aligned with recognised auditing principles and guidance, including ISO 19011 where appropriate

Findings based on objective evidence obtained through interviews, documentation review, observation, and sampling

Conclusions supported by corroboration across multiple evidence sources and audit methods

Practical reporting focused on decision-making, assurance, and continual improvement

What we deliberately do not do

Audit management systems we have designed or built ourselves

Take advisory mandates that arise from our own audit findings

Accept engagements where the selection of samples, evidence or interview partners is prescribed to us rather than driven by the audit objectives

Draw conclusions from interviews alone, without corroborating evidence

Related advisory services

What comes after the findings, and who may do it

An audit gives you an independent answer and stops there. Advisory is the other half of the work: helping you design, implement, operate, and improve the systems and controls an audit assesses.

The two stay apart on the same system: we do not audit what we have built, and we do not take on the improvement work our own findings call for. Reviewing our own design would be reviewing ourselves, and selling the remedy would give us an interest in the finding. Beyond that, we avoid conflicts of interest as a matter of course.

How advisory works →

Discuss your audit challenge

A short conversation to understand your current situation and discuss possible next steps.

Halderstone Academy

Halderstone Academy offers focused training modules on relevant audit capabilities.

Free · no obligation

Thirty minutes to understand what should be assessed and against which requirements. No preparation needed on your side.

Length
30 minutes
Where
Video call · link sent by email
Afterwards
Possible next steps, in writing

Prefer to write instead?

Pick a timeYour details

Times shown in
Zurich

The calendar cannot be reached just now. Please send a written brief instead.

Nothing suitable?