Compliance decays. The certificate is a moment, the controls are a habit.
Most organisations pass an assessment and then drift, because the reviews, the evidence and the control operation all depend on somebody remembering. This is the recurring half: keeping the position true between audits. It is the wrong purchase if you have not built the controls yet, and we will tell you.

- Between auditsWhere compliance is actually lost
- Evidence continuousNot assembled in the last fortnight
- Wrong for someBuild first, then maintain
- Handover plannedWe name what would end it
Eight things that have to keep happening, and usually stop.
The reviews the standards actually name
ISO 27001 requires internal audit and management review, and both are the clauses organisations most often skip because nobody outside the programme asks for them until an assessor does. They are not paperwork: an internal audit that finds nothing every year is not being run properly, and a management review with no decisions recorded is a meeting rather than a control.
Evidence that accumulates rather than being assembled
A SOC 2 Type II report covers an observation period, typically six to twelve months, and auditors sample across it. Evidence has to exist for the whole window. The organisations that find audits painless are the ones where access reviews, change approvals and incident records fall out of normal work. The ones that find it painful reconstruct twelve months of records in a fortnight, every year.
Controls that keep operating when nobody is watching
Access reviews on a cadence, restore tests performed and recorded, vulnerability findings tracked to closure, logs reviewed by somebody, third party evidence refreshed before it expires. Each is individually small and each is individually forgotten. The recurring value here is unglamorous: making sure the things that should happen quarterly actually happen quarterly.
Watching the standards, because they move
PCI DSS moved its 51 future-dated requirements into force on 31 March 2025, and organisations that assessed during the transition and never revisited the list are non-compliant against requirements they were told they had time to prepare for. ADHICS V2 states a revision date of May 2027. ISO 27001 gained Amendment 1 in 2024. A position built two years ago and left alone is not the position you think you hold.
Keeping scope current as the business changes
A new system, an acquisition, a new market, a new processing activity or a change of supplier can all move you in or out of scope for something. This is the input organisations most reliably miss, because the trigger is a commercial decision rather than a compliance one and nobody thinks to mention it. Catching it needs somebody paying attention to the business, not just to the controls.
Answering the questions that keep arriving
Client security questionnaires, insurer proposal forms, supplier due diligence and regulator requests all draw on the same underlying evidence. Maintaining a single answer set with evidence behind each answer turns a recurring multi-day exercise into a short one, and removes the risk of two clients receiving inconsistent answers to the same question.
Surveillance and recertification, without a scramble
ISO 27001 certification runs on a three-year cycle with surveillance audits in between. SOC 2 buyers expect a report covering a recent period, so consecutive observation windows rather than gaps. External financial audit samples IT general controls annually under ISA 315. All of these are predictable dates, which means the only reason they arrive as emergencies is that nothing happened in between.
Reporting that tells leadership something true
What is genuinely operating, what has slipped, what changed in the standards, and what decision is being asked for. Not a percentage-complete figure. A compliance report that is always green is either describing an unusually well-run organisation or is not being written honestly, and the second is considerably more common than the first.
If you have not built the controls, this is the wrong purchase.
A recurring service maintaining a control set that does not exist yet bills every month for maintaining nothing. That is a straightforward waste and it is a common one, so it is worth being direct about it before describing what the service does.
- The right sequence is assess, build, then maintain. If you have never been assessed, an assessment is the first purchase and it may well conclude that your gap is small enough to close internally. If you have been assessed and have open findings, remediation is the second, and it is a project with an end rather than a retainer. Only once controls genuinely operate does maintaining them become the thing you need.
- The test we apply is simple. Can you name the controls that are supposed to be running, and did the last cycle of each actually happen? If the answer is no, you need building work, not maintenance, and we will quote for that instead. If the answer is yes but it happened because one person remembered, that is exactly what this service is for.
- There is a second wrong reason to buy this, which is to acquire an appearance of compliance without the substance. An external provider producing documents that describe controls nobody operates is a liability rather than an asset, because it survives right up until a client audit or an incident and then makes the position worse. We will not do that, and we would encourage scepticism of anyone who will.
- The honest case for this service is narrow and real: you have controls that work, obligations that recur, and nobody internally with the time or the discipline to keep them running between assessments. That is a common and legitimate position, particularly for firms too small to justify a dedicated compliance hire, and it is who this is for.
Four commitments, including one that limits our own revenue.
We will tell you this is the wrong purchase when it is
If your controls do not yet exist, you need assessment and remediation, which are projects with an end, not a recurring service. We would rather quote for those and pick up the maintenance later, or not at all, than bill monthly for maintaining a control set that has not been built. This is the most common correction we make in a first conversation about this service.
We build evidence into normal work, not into our own reports
The objective is that approvals get captured where the work happens, reviews sit on a calendar with owners, and change records are produced as changes are made. Evidence that only exists because we assemble it is evidence that disappears when we do, which makes the arrangement harder to leave than it should be. We are explicitly trying to avoid that.
We report what has slipped, not a percentage
Compliance reporting that is always green is usually not being written honestly. Where a review was missed, an action is overdue or a control has stopped operating, that appears in the report with the reason. You are paying for an accurate picture, and an inaccurate reassuring one is worse than no report because it delays the decision that would fix it.
We define what would end the arrangement
A compliance hire, an internal person growing into the role, or a position stable enough to need only periodic input. We agree that at the outset and work toward it. Ask any provider of a recurring service what would make them unnecessary; the answer tells you whose interest the arrangement is designed around, and you should ask us the same question.
Six situations where ongoing support is the right answer.
A firm that certified and then lost momentum
The most common. The programme had a deadline, everyone worked hard, the certificate arrived and attention moved elsewhere. Eighteen months later the internal audit has not happened, the access reviews lapsed and the surveillance audit is approaching. This is exactly what the service exists for and the first few months are usually a catch-up rather than a steady state.
An organisation too small to justify a compliance hire
The obligations are real and recurring, and they do not amount to a full-time role. Splitting them across IT, finance and operations means each assumes another is handling it, which is how cadence slips without anyone deciding to drop it. An external arrangement with a named owner is usually cheaper and more reliable than a fractional internal one.
A regulated firm with supervisory expectations
Where the regulator expects evidence of ongoing oversight rather than a point-in-time position, the recurring work is the obligation. For firms under Central Bank requirements, an independent technology audit function is named explicitly in the applicable articles, and that is a recurring role rather than an annual event.
A healthcare entity under ADHICS
The standard states a revision date of May 2027 on a three-year cycle, and the control domains require continuing practice rather than one-time implementation. Entities that treated the original alignment as a project and stopped there tend to find their evidence has decayed well before any revision arrives.
A company answering questionnaires constantly
If client security questionnaires arrive most months and consume senior time each time, maintaining a single answer set with evidence behind it is worth the arrangement on its own. The secondary benefit matters too: consistent answers across clients, and no claims the organisation cannot actually evidence.
A business carrying more than one framework
ISO 27001 alongside SOC 2, or a sector standard alongside a client-driven certification. The underlying evidence overlaps heavily, and running them as separate programmes duplicates effort continuously rather than once. Consolidating the recurring work across frameworks is usually where the arrangement pays for itself.
What actually happens between assessments.
| Feature | Maintained | Certified then drifted |
|---|---|---|
Internal audit performed and finding real issues | Yes | Nominal or skipped |
Management review held with decisions recorded | Yes | Missed |
Access reviews completing and removing access | Yes | Lapsed |
Restore tested within the year | Yes | Assumed to work |
Evidence exists across the whole period | Yes | Reconstructed before the audit |
Standards changes picked up | Yes | Position is two versions old |
Scope updated as the business changed | Yes | Unchanged since day one |
Client questionnaires answered from a maintained set | Yes | Ad hoc each time |
Surveillance audit experience | Routine | A fortnight of panic |
Survives a customer deep-dive audit | Yes | Unlikely |
Three adjacent things, and how to tell them apart.
| Audit | Virtual CISO | Compliance as a service | |
|---|---|---|---|
| What it answers | Where do we stand | What should we decide | Is it still true |
| Shape | Point in time | Ongoing governance | Ongoing operation |
| Main output | Findings and a plan | Decisions and reporting | Evidence and cadence |
| Owns risk acceptance | No | Advises on it | No |
| Talks to the board | Occasionally | Regularly | Through the CISO or leadership |
| Runs internal audit and management review | No | Oversees | Yes |
| Maintains the evidence pack | No | No | Yes |
| Handles client questionnaires | No | Sets the position | Answers them |
| Right when controls do not exist yet | Yes, start here | Sometimes | No |
| Right when controls exist but drift | Not really | Partly | Yes |
Five stages, and the first one may end the conversation.
- 1
Establish whether this is the right purchase
Which frameworks apply, what controls are supposed to be operating, and whether the last cycle of each actually happened. Where the answer is that controls have not been built, we say so and quote for assessment and remediation instead. That is a project with an end, and it should be finished before any recurring arrangement starts.
- 2
Map the recurring obligations across every framework
What has to happen, how often, who owns it and what evidence it produces. Consolidated across frameworks rather than tracked separately, since the underlying activities overlap heavily. This calendar is the substance of the service and it is yours, so it remains useful if you later bring the work in-house.
- 3
Fix the evidence flow before running the cadence
Wherever possible, evidence should be a byproduct of normal work rather than something collected on request. Approvals captured where work happens, reviews recorded as they are completed, change records generated as changes are made. This is the difference between a service that reduces effort and one that simply moves it.
- 4
Operate the cycle, and report honestly
Reviews run, evidence maintained, third party documentation refreshed, standards changes monitored, questionnaires answered from the maintained set. Reporting leads with what has slipped and what decision is needed, not with a completion figure. Where a cycle was missed, the report says so and why.
- 5
Support the assessment, then work toward handover
Surveillance audits, recertification, external audit sampling and client deep dives handled from evidence that already exists. Alongside that, deliberate progress toward the point where you need us less, whether that is an internal hire or a position stable enough for periodic input. Priority response applies throughout, P1 within 5 minutes, P2 within 10, P3 within 30.
What organisations ask about ongoing compliance support.
Fifteen questions, and you can answer most of them today.
Is it still happening
- When was your last internal audit, and what did it find?An internal audit that finds nothing is not being run properly.
- When was the last management review, and were decisions recorded?Required by ISO 27001 and routinely skipped.
- Did the last access review cycle actually complete?And did it remove anything.
- Has a restore been tested and documented this year?Backup reports are not restore evidence.
- Are vulnerability findings tracked to closure with dates?Scanning without remediation evidence proves nothing.
Is your position current
- Have you addressed the PCI requirements effective from March 2025?They are no longer future-dated.
- Is your ISO documentation on the 2022 edition with Amendment 1?The 2013 transition closed in October 2025.
- Has anything changed in the business that moves your scope?New system, acquisition, market, supplier or processing activity.
- Is third party evidence still in date?Certificates expire, attestation reports cover a past period.
- Would your next surveillance audit be routine or a scramble?An honest answer here is diagnostic.
Who owns it
- Is one named person accountable for the recurring obligations?Not a committee, and not "IT" generally.
- Does that person have time allocated, or is it on top of a job?The most common reason cadence slips.
- Would it survive that person leaving?Undocumented compliance knowledge walks out with them.
- Does evidence accumulate from normal work?The single best predictor of a painless audit.
- Does anybody report honestly when something has slipped?Always-green reporting is a warning sign, not a good one.
The pages around this one.
Virtual CISO in Dubai
The governance half: who decides risk appetite, which frameworks to pursue, and who answers the board and the regulator.
IT audit services in Dubai
The point-in-time assessment that establishes where you stand, which is the right first purchase if your controls are not yet built.
ISO 27001 certification in the UAE
The framework whose recurring clauses, internal audit and management review, are the ones most often skipped after certification.
Answer one question before you buy anything recurring.
Can you name the controls that are supposed to be running, and did the last cycle of each actually happen? If not, you need assessment and remediation first, and we will say so rather than starting a retainer over a control set that has not been built.
Related Services
Explore more solutions that work great with this service
Virtual CISO Dubai
Security governance and accountability, not more tools
IT Audit Services Dubai
Assessment, technical test or certification, scoped properly
ISO 27001 Certification UAE
The 2022 edition, and whether you should certify at all
SOC 2 Readiness UAE
Type II preparation, and when ISO 27001 fits better
Access Rights Review
Certification that removes access, not one that gets approved
ADHICS V2 Compliance
The Abu Dhabi healthcare standard, read from the source
CBUAE IT Requirements
Which Rulebook articles actually bind your licence
IT General Controls
What your external auditor tests, and the evidence they sample