Services
Halderstone Audit Services
Find out whether your system is working as intended, while there is still time to do something about it
Findings people act on, not a report that files itself
Every conclusion rests on corroborated evidence across multiple sources and methods, and the reporting is built for decisions and improvement. It is the same discipline our academy trains auditors in.
Overview
We assess whether your system works as intended
Halderstone Audit Services supports organisations with independent assessments across selected management system disciplines. These services help you understand whether governance structures, controls, processes, and compliance arrangements are working as intended.
Engagement types
Internal audits
Readiness assessments
Supplier reviews
Governance reviews
Compliance reviews
Integrated audits across management systems
By discipline
The method is the same; what is at stake is not
What changes between disciplines is what is at stake and which requirements bind: an information security audit and an environmental audit ask different questions of different evidence. Planning, corroboration and reporting do not.
By discipline
Artificial Intelligence
An AI governance audit asks whether the oversight bites: whether the risks identified are the ones the deployed systems actually create, whether the controls hold across a change of model or supplier, and whether anyone would notice if they stopped working.
Supported frameworks
ISO/IEC 42001
EU AI Act
NIST AI RMF
OECD AI Principles
Internal AI governance frameworks
Business Continuity
A BCM system audit asks whether the arrangements would hold: whether the impact analysis still matches the business, whether the strategies close the gap it identifies, and whether the exercises were hard enough to fail.
Supported frameworks
ISO 22301
ISO 22313
NIST SP 800-34
DORA
Organisation-specific continuity frameworks
Data Protection
A privacy programme audit follows the risk to people rather than the paperwork: whether that risk drives the controls, whether the controls survive a change of purpose or supplier, and whether the reviews would find a gap before a data subject does.
Supported frameworks
EU GDPR
Swiss Federal Act on Data Protection (FADP)
ISO/IEC 27701
ISO/IEC 27001 and ISO/IEC 27002
NIST Privacy Framework
Organisation-specific privacy and data protection frameworks
Environmental Management
An EMS audit looks past compliance to effect: whether the significant aspects drive the objectives, whether operational control changes what happens on site, and whether the reviews would catch a drift before someone outside does.
Supported frameworks
ISO 14001
ISO 14004
ISO 14031
EMAS
Organisation-specific environmental management and compliance frameworks
Information Security
An ISMS audit tests effectiveness rather than coverage: whether the risks named are the risks actually run, whether the controls chosen against them reduce the exposure, and whether the reviews would notice if they stopped working.
Supported frameworks
ISO/IEC 27001 and ISO/IEC 27002
ISO/IEC 27005
NIST Cybersecurity Framework
CIS Controls
DORA
Organisation-specific information security frameworks
Quality Management
A QMS audit asks whether the system changes what happens: whether the quality objectives reach the processes that deliver them, whether the controls on those processes hold when volume rises, and whether an improvement changed a result.
Supported frameworks
ISO 9001
ISO 9004
ISO 19011
Customer-specific quality requirements
Industry-specific quality management frameworks
Organisation-specific quality management frameworks
Why Halderstone
Independence and evidence are not things an audit can borrow
An audit is worth what its evidence can carry. What follows is how conclusions are built here, and which engagements we decline in order to keep them worth something.
Our approach
Audit planning informed by risks, objectives, and the intended use of audit results
Audit activities aligned with recognised auditing principles and guidance, including ISO 19011 where appropriate
Findings based on objective evidence obtained through interviews, documentation review, observation, and sampling
Conclusions supported by corroboration across multiple evidence sources and audit methods
Practical reporting focused on decision-making, assurance, and continual improvement
What we deliberately do not do
Audit management systems we have designed or built ourselves
Take advisory mandates that arise from our own audit findings
Accept engagements where the selection of samples, evidence or interview partners is prescribed to us rather than driven by the audit objectives
Draw conclusions from interviews alone, without corroborating evidence
Related advisory services
What comes after the findings, and who may do it
An audit gives you an independent answer and stops there. Advisory is the other half of the work: helping you design, implement, operate, and improve the systems and controls an audit assesses.
The two stay apart on the same system: we do not audit what we have built, and we do not take on the improvement work our own findings call for. Reviewing our own design would be reviewing ourselves, and selling the remedy would give us an interest in the finding. Beyond that, we avoid conflicts of interest as a matter of course.
Discuss your audit challenge
A short conversation to understand your current situation and discuss possible next steps.
Halderstone Academy
Halderstone Academy offers focused training modules on relevant audit capabilities.