Management questions before an audit
Readiness is not a document count. What matters is whether the organisation understands the risks and dependencies behind its controls, what evidence actually exists, and where a management decision is still missing.
- What assumptions underpin the proposed approach?
- Which technical questions remain open, and who can decide them?
- What evidence exists today, and what is only planned?
- Where must work with auditors, implementation partners or legal advisers be clearly bounded?
Experience, stated precisely
Publicly listed project experience includes ISO 27001/27017/27018, a DORA gap analysis and audits by supervisors, KPMG and BDO. In one Malta case, customer assets were migrated under supervision in 2023 to a platform certified to ISO 27001.
These facts describe previous work. They do not mean Jürgen Röck provides certification or guarantees an audit outcome.
Independent contribution, not a certification mandate
A focused review of a readiness decision, sparring before an audit or clearly bounded support during a critical phase may be agreed. Scope is explicit. Certification, general implementation, legal advice and operational team management are outside the current offer.
A considered next step
Clarify the question before choosing the scope.
An initial conversation is for clarifying the issue, the available information and the boundaries. If another format is a better fit, that will be said plainly.