International consulting

The law changes at
the border. The standard does not

We implement certifiable management systems built on ISO/IEC standards for organisations across Latin America, the United States and Europe. An ISO/IEC 27001 implemented in Lima, Mexico City or Madrid is precisely the same standard, with the same clauses and the same controls.

See what you can engage

Consulting in Chile
International
What you will find here

Management systems, not local compliance

This catalogue covers international standards, and nothing else. It does not include any country's legislation — neither ours nor yours. You and your counsel know your local regulation, and we are not going to pretend otherwise from another continent.

What we do build is the management system that regulation later rests on. It is the part that does not change from one country to the next: context analysis, scope, asset inventory, risk assessment, controls and their evidence, internal audit and management review. A regulator asking you for appropriate technical and organisational measures finds its answer there, whatever the rule demanding it happens to be called.

 We implement and support the audit. Certification is issued by an accredited body, never by the consultant

That separation is a rule of the accreditation standards themselves, so be wary of anyone offering both: a consultant who also certifies would be auditing their own work. We leave the system standing, train your internal auditors and are there on audit day; the certificate is issued by whoever is entitled to issue it.

Where we work

Perú · Colombia · Ecuador · México · Argentina · Bolivia · Brasil · Uruguay · Paraguay · Panamá · Costa Rica · Estados Unidos · España

Where from

Santiago, Chile, remotely. Chilean hours overlap the full working day across the Americas and reach into the European afternoon, so meetings land inside both parties' business hours without anyone getting up at dawn.

Your country not on the list? Write to us anyway. The list is where we have already worked, not a border.

The catalogue

Inventory of Management Systems

Presented the way any asset is presented inside a management system: with its identifier, its reference standard, who verifies that it exists and who is going to ask you for it. Click a row to see what it covers.

SG-01 Information securityISMS ISO/IEC 27001:2022 Accredited body Corporate clients and tenders

The information security management system. Clauses 4 to 10 and the 93 Annex A controls, grouped into four themes: organisational, people, physical and technological. This is the standard corporate clients and tenders ask for when they want proof that their supplier manages risk.

Two-stage initial audit, annual surveillance and recertification in year three.

SG-02 Information privacyPIMS ISO/IEC 27701 Accredited body Privacy regulators and processing agreements

Extends the security system to the processing of personal data: controller and processor roles, records of processing activities, impact assessments, data subject rights and supplier agreements. It ships with an explicit mapping to the European General Data Protection Regulation.

Built on top of SG-01, not instead of it.

SG-03 Artificial intelligenceAIMS ISO/IEC 42001:2023 Accredited body Audit committees and clients with AI in their chain

The first certifiable AI management standard. Inventory of AI systems, impact assessment, model lifecycle control, training data governance and human oversight. It answers the question every audit committee is asking today: who answers for what the model decides.

Shares the records of processing and the impact assessment with SG-02.

SG-04 QualityQMS ISO 9001:2015 Accredited body Public tenders and large buyers

The most widely demanded management system standard in the world, in tenders and in contracts with large buyers. Process approach and risk-based thinking: the company understood as connected processes, each with an owner, its indicators and what can go wrong in it.

The usual way in: whoever holds it implements the others far faster.

SG-05 Business continuityBCMS ISO 22301:2019 Accredited body Sector regulators and critical clients

What happens when something goes down, and how long you can afford it to last. Business impact analysis, recovery time objectives, continuity strategies, response plans and — the part almost nobody does — the exercise proving the plan works before you need it.

It is also what SG-01 expects to find behind its continuity controls.

SG-06 IT serviceSMS ISO/IEC 20000-1:2018 Accredited body Managed service clients

The service management system: catalogue and service levels, incident and problem management, change and release, capacity and availability. For managed service providers whose clients require them to demonstrate how they operate, not merely to promise it.

Aligns with ITIL, which is a body of good practice and not an auditable standard.

All six share the same high-level structure: if you already have one in place, the context, the roles, document control and internal audit are reused rather than duplicated. That is why the second system always costs less than the first.

Beyond the standard

Register of Reference Frameworks

The same inventory, for what cannot be certified. There is no such thing as a «NIST certificate» or a «GDPR certificate», however often they are sold, which is why none of them appears below as a programme you can engage on its own. The last column is what we do instead: map them onto the management system already in place, because a control implemented once answers several at a time.

MR-01 Cybersecurity Framework 2.0CSF NIST · United States Voluntary framework SG-01

Version 2.0, released in 2024, added Govern to the five original functions: govern, identify, protect, detect, respond and recover. It maps cleanly onto Annex A of ISO/IEC 27001, so it lets you report in the language a board or a US client expects without standing up a second system.

Not certifiable: no body audits against it.

MR-02 SP 800-53 Rev. 5800-53 NIST · United States Control catalogue SG-01

The US federal government's catalogue of security and privacy controls, and the foundation FedRAMP is built on. Relevant if you sell to a federal agency, or to a contractor passing its requirements down to you by contract.

Used to extend the Statement of Applicability, not to replace it.

MR-03 Regulation (EU) 2016/679RGPD European Union Legal instrument SG-02

It reaches anyone offering goods or services to people in the European Union, even without an establishment there. Records of processing activities, impact assessments, breach notification within 72 hours and a data protection officer where required. ISO/IEC 27701 was written to leave all of that in place and evidenced.

It is law, not a technical standard: you comply with it, you do not certify against it. Your counsel has the last word.

MR-04 Trust Services CriteriaSOC 2 AICPA · United States Attestation report SG-01

Not a certification: a report issued by a CPA firm, Type I on the design of the controls or Type II on how they operated over a period. Almost every SaaS buyer in the United States asks for it.

We prepare the evidence; the report is signed by the auditor, never by the consultant.

MR-05 Critical Security Controls v8.1CIS Center for Internet Security Technical controls SG-01

Eighteen controls ordered by real-world priority and split across three implementation groups, from the most basic to the most demanding. It is the most concrete item on this list: where ISO 27001 says what must be covered, CIS says where to start on Monday.

Most useful in the first quarter, when gaps need closing and time is short.

MR-06 Risk managementISO 31000 ISO Guidance, not auditable SG-01 … SG-06

Neither certified nor audited against: it is the guidance the method comes from — how risk is identified, analysed and treated. It is what makes the ISO/IEC 27001 risk assessment something more than a colour-coded spreadsheet, and the same methodology then serves the other systems.

It runs across the whole inventory: all six systems require risk assessment.

Beyond the project

Roles Delivered as a Service

A system certified last year and left unattended since will not pass its surveillance audit. These two roles are what keeps it alive: the same function as an in-house post, with agreed monthly hours and without a full-time executive salary.

RL-01 Information security leadershipVirtual CISO Risk, controls and audits 15 / 20 hrs/month In the proposal

The security leadership function as a service, for organisations that need it but cannot justify a full-time post. It keeps the system alive between audits: risk review, follow-up on the treatment plan, security committee, management review, and the technical counterpart when a client sends its supplier questionnaire or when there is an incident.

It does not transfer ownership of the risk: that stays with the board, and no standard allows it to be delegated.

RL-02 Data protection leadershipVirtual DPO Processing, impact and rights 15 / 20 hrs/month In the proposal

The data protection function, for those required to appoint one or who simply need someone to answer for it. It maintains the records of processing activities, leads impact assessments, handles data subject rights, reviews processor agreements and acts as the contact point for the relevant supervisory authority.

The formal appointment is made by your organisation before your authority; we take on the function and the work.

Both roles together come in 10% cheaper than separately: the context, the asset inventory and the risk assessment are done once and serve both. Engagements run for 3, 6, 12 or 24 months, billed monthly.

Price the role
How remote delivery works

A Remote Project You Do Not Notice

Management system consulting is interviews, documents and evidence. Almost none of that improves by sharing a room, and the little that does is concentrated and planned.

Meetings on your clock

Discovery interviews are scheduled inside your team's working day, not ours. They are recorded and summarised, because the person who missed the risk session is always the one who had the answer.

A repository, not an attachment

All documentation lives in a shared space with version and access control. No policies circulating by email in their third revision, which is how two different truths turn up on audit day.

On site when it matters

If your scope includes facilities that have to be seen — a data centre, a plant — a visit is planned and quoted separately, with its costs in plain view. It is not buried in the price paid by those who do not need it.

Contract and confidentiality

A confidentiality agreement before the first interview, and a contract setting out scope, deliverables, milestones and currency of payment. The law governing the contract is agreed with you, not imposed on you.

Progress in the open

A board showing how far each gap has been closed and who owns each action. The board should be able to answer «where are we?» without asking anyone for a report.

Internal auditors of your own

In the final phase we train auditors inside your organisation. It is a requirement of the standard, and it is also what decides whether the system survives its second year: if internal audit always depends on an outsider, it happens once and is abandoned.

What you can engage

Information Security — ISO/IEC 27001

The gap assessment can be engaged on its own: it is a useful diagnosis in itself and commits you to nothing. The scope and deliverables are set out in the proposal.

ISO/IEC 27001:2022

Information Security

  • Gap assessment Gap assessment
  • Regulatory implementation Gap closure and evidence
  • Gap assessment + implementation Both services, together
    −15%

How the value is determined

International proposals are quoted in US dollars (USD), net. The value of each project comes from four factors:

  • Scope: which standards are included, and how many processes, systems and suppliers fall inside the management system.
  • Size and sites: people to interview, number of locations, and whether the scope spans more than one country.
  • Maturity: how much already exists —policies, records, controls in operation— and how much has to be built from scratch.
  • Timeline: the certification or compliance date you need, and the effort it takes to sustain it.
Find out what yours costs, today

Build your scope in the quote builder and get the proposal with figures in dollars within 24 business hours. No meeting first, and no details needed until the end.

Build my quote
What you can engage

The Other Programmes

The last panel combines privacy and AI governance into a single project: they share the records of processing and the impact assessment, which is why they cost less together than apart.

Privacy Governance

ISO 27701

  • Gap assessment Gap assessment
  • Regulatory implementation Gap closure and evidence
  • Gap assessment + implementation Both services, together
    −15%

AI Governance

ISO 42001

  • Gap assessment Gap assessment
  • Regulatory implementation Gap closure and evidence
  • Gap assessment + implementation Both services, together
    −15%

Quality Management

ISO 9001

  • Gap assessment Gap assessment
  • Regulatory implementation Gap closure and evidence
  • Gap assessment + implementation Both services, together
    −15%

Business Continuity

ISO 22301

  • Gap assessment Gap assessment
  • Regulatory implementation Gap closure and evidence
  • Gap assessment + implementation Both services, together
    −15%

IT Service Management

ISO 20000-1

  • Gap assessment Gap assessment
  • Regulatory implementation Gap closure and evidence
  • Gap assessment + implementation Both services, together
    −15%

ISO 27701 + ISO 42001, integrated

One single project, not 2 por separado

  • Gap assessment Gap assessment
    −20%
  • Regulatory implementation Gap closure and evidence
    −20%
  • Gap assessment + implementation Both services, together
    −15%

How the value is determined

International proposals are quoted in US dollars (USD), net. The value of each project comes from four factors:

  • Scope: which standards are included, and how many processes, systems and suppliers fall inside the management system.
  • Size and sites: people to interview, number of locations, and whether the scope spans more than one country.
  • Maturity: how much already exists —policies, records, controls in operation— and how much has to be built from scratch.
  • Timeline: the certification or compliance date you need, and the effort it takes to sustain it.
Find out what yours costs, today

Build your scope in the quote builder and get the proposal with figures in dollars within 24 business hours. No meeting first, and no details needed until the end.

Build my quote
Next step

Start with a 30-Minute Call

No cost and no sales deck. Tell us which country you operate in, which standard is being asked of you and who is asking — a client, an investor, a regulator — because that changes the scope and the timeline more than the size of the company does. If you already have an audit date committed, say so at the start: it changes the order of the phases.

Book the call Operating in Chile? See that catalogue
Basket 0 products

Your basket is empty

Add regulatory documentation packs or plans
Complete purchase
Contact and payment details
1Contact
2Summary
3Payment
Add to basket?