

Certification Support
Certification Support
Structured towards certification – confidently through all phases of the audit.
A certification builds trust with customers, partners, and authorities – and demonstrates that your organisation manages information security or AI in a structured and effective way.Regardless of whether it concerns information security (e.g. ISO/IEC 27001 or BSI IT-Grundschutz), AI governance (ISO/IEC 42001), or industry-specific requirements such as TISAX – what matters is targeted and structured preparation for the audit.
Assessment and Preparation
Before the actual audit, the question is whether the organisation is truly ready. In this phase, the existing implementation is reviewed once more in a structured way and compared against the requirements of the relevant standard.Together, we clarify whether all relevant aspects have been addressed and whether the implementation will withstand the expectations of an audit. The goal is to identify potential gaps early and close them proactively, before they become visible during the audit.Further information: Conducting Internal Audits
Preparation for the Audit
In addition to the technical implementation, organisational preparation plays a decisive role in the success of an audit.This includes in particular the structured preparation of upcoming appointments: relevant documents are coordinated, interview participants identified and prepared for discussions, and the audit process is reviewed together.An important component is also the targeted preparation of the people involved. Selected interview participants are briefed in advance to build confidence in handling the audit questions and to conduct the discussions in a structured manner.This creates confidence in dealing with the audit situation and a clear framework for the entire audit.Further information: Information Security ConsultingFurther information: AI Management Systems & Governance
Support During the Audit
During the audit itself, the focus is above all on maintaining an overview and being able to respond appropriately to the audit requirements.Support is provided in the background – with the aim of giving you confidence in dealing with the audit situation. Questions can be contextualised, answers prepared in a structured way, and important notes recorded and secured directly. This ensures that no relevant information is lost during the audit and that everything is available for the follow-up.
Follow-Up and Further Development
The process is usually not complete once the audit is finished. Findings and observations need to be assessed and translated into concrete measures.In the follow-up, the results are evaluated together, prioritised, and processed in a structured manner. It is important to analyse root causes, define appropriate measures, and prepare the required evidence.The focus is not only on successfully completing the certification, but on sustainably developing the management system and optimally preparing for future audits.
Selection of Certification Bodies
If desired, support can also be provided in selecting appropriate certification bodies or auditors.Through my own experience as an auditor, I have a thorough understanding of different approaches and requirements, enabling a selection that fits the organisation and the specific project.
Interested in certification?
Schedule an appointment //
A certification builds trust with customers, partners, and authorities – and demonstrates that your organisation manages information security or AI in a structured and effective way.Regardless of whether it concerns information security (e.g. ISO/IEC 27001 or BSI IT-Grundschutz), AI governance (ISO/IEC 42001), or industry-specific requirements such as TISAX – what matters is targeted and structured preparation for the audit.
Assessment and Preparation
Before the actual audit, the question is whether the organisation is truly ready. In this phase, the existing implementation is reviewed once more in a structured way and compared against the requirements of the relevant standard.Together, we clarify whether all relevant aspects have been addressed and whether the implementation will withstand the expectations of an audit. The goal is to identify potential gaps early and close them proactively, before they become visible during the audit.Further information: Conducting Internal Audits
Preparation for the Audit
In addition to the technical implementation, organisational preparation plays a decisive role in the success of an audit.This includes in particular the structured preparation of upcoming appointments: relevant documents are coordinated, interview participants identified and prepared for discussions, and the audit process is reviewed together.An important component is also the targeted preparation of the people involved. Selected interview participants are briefed in advance to build confidence in handling the audit questions and to conduct the discussions in a structured manner.This creates confidence in dealing with the audit situation and a clear framework for the entire audit.Further information: Information Security ConsultingFurther information: AI Management Systems & Governance
Support During the Audit
During the audit itself, the focus is above all on maintaining an overview and being able to respond appropriately to the audit requirements.Support is provided in the background – with the aim of giving you confidence in dealing with the audit situation. Questions can be contextualised, answers prepared in a structured way, and important notes recorded and secured directly. This ensures that no relevant information is lost during the audit and that everything is available for the follow-up.
Follow-Up and Further Development
The process is usually not complete once the audit is finished. Findings and observations need to be assessed and translated into concrete measures.In the follow-up, the results are evaluated together, prioritised, and processed in a structured manner. It is important to analyse root causes, define appropriate measures, and prepare the required evidence.The focus is not only on successfully completing the certification, but on sustainably developing the management system and optimally preparing for future audits.
Selection of Certification Bodies
If desired, support can also be provided in selecting appropriate certification bodies or auditors.Through my own experience as an auditor, I have a thorough understanding of different approaches and requirements, enabling a selection that fits the organisation and the specific project.
Interested in certification?
Schedule an appointment //
André Scherwinski
Your independent advisor for information security.
André Scherwinski | Sollschwitz 66A | 02997 Wittichenau
André Scherwinski | Sollschwitz 66A | 02997 Wittichenau