Service Catalog

Every advisory service, fully detailed.

The complete MAST Study advisory catalog — nine services delivered across every management system we work with. Each entry lists scope, deliverables, outcomes, typical duration and the standards it covers.

Back to consulting
Coverage
SERVICES
9
STANDARDS COVERED
17+
DELIVERY MODEL
Fixed-fee or retainer
LEAD CONSULTANTS
Lead Auditor certified
Catalog index

Nine services, one integrated practice.

SVC-01
Standards Advisory

Choose the right frameworks for your business, regulatory context and growth plan — and sequence them into a coherent multi-standard roadmap instead of a stack of parallel projects.

SVC-02
Gap Assessment

A clause-by-clause diagnostic against your target standard(s) with a costed, prioritised remediation plan — the objective baseline every implementation depends on.

SVC-03
Implementation

End-to-end design and rollout of the management system — policies, procedures, controls, RACI, evidence and tooling — built with your team, not handed over as a shelf of PDFs.

SVC-04
Risk & Controls

An ISO 31000 risk methodology that plugs into Annex A, NIST and sectoral control libraries — with treatment plans your risk owners can actually operate.

SVC-05
Internal Audit

Independent internal audits run by certified Lead Auditors — with findings written to be closed, not filed, and management review packs that stand up to external scrutiny.

SVC-06
Certification Readiness

Stage-1 and Stage-2 dry runs, evidence libraries and auditor liaison — so the external certification audit is a formality, not a surprise.

SVC-07
Integrated Management System

Merge ISO 27001, 27701, 22301, 9001, 14001, 45001 and 42001 into a single integrated system — audited once, demonstrated many times.

SVC-08
vCISO / vDPO on Retainer

Fractional Chief Information Security Officer and Data Protection Officer services — senior operator time without a senior operator's fixed cost.

SVC-09
KPI & Reporting

Board-ready compliance dashboards, maturity scoring and continual improvement cycles — reporting that drives decisions, not just fills slides.

SVC-0101 / 09

Standards Advisory

Choose the right frameworks for your business, regulatory context and growth plan — and sequence them into a coherent multi-standard roadmap instead of a stack of parallel projects.

Typical duration
3–6 weeks
Applies to
ISO/IEC 27001ISO/IEC 27701ISO/IEC 42001ISO 22301ISO 9001ISO 14001ISO 45001ISO 37301GDPRUAE PDPLKSA PDPL
Scope of work
  • Regulatory & framework applicability analysis (ISO, GDPR/PDPL, sectoral).
  • Target operating model for compliance, security, privacy and AI governance.
  • Multi-standard integration strategy and phased roadmap (12–36 months).
  • Business case, budget model and board-level positioning.
Deliverables
  • Framework applicability matrix
  • Compliance target operating model
  • Multi-year integrated roadmap
  • Executive briefing pack
Outcomes
  • Single source of truth for what to certify, when and why.
  • Clear ownership across CISO, DPO, Quality and Risk functions.
  • Reduced duplication across audits and control frameworks.

Ready to scope standards advisory for your organisation?

SVC-0202 / 09

Gap Assessment

A clause-by-clause diagnostic against your target standard(s) with a costed, prioritised remediation plan — the objective baseline every implementation depends on.

Typical duration
4–6 weeks
Applies to
ISO/IEC 27001ISO/IEC 27701ISO/IEC 42001ISO 22301ISO 9001ISO 14001ISO 45001ISO/IEC 20000-1ISO 37301GDPRUAE PDPLKSA PDPLNIST CSF / 800-53
Scope of work
  • Document review, control walkthroughs and stakeholder interviews.
  • Clause-by-clause conformance scoring against target standard(s).
  • Prioritised gaps by risk, effort and audit impact.
  • Phased remediation plan with owners, dependencies and estimates.
Deliverables
  • Gap assessment report (clause-mapped)
  • Findings register with severity
  • Remediation roadmap (costed & sequenced)
  • Executive readout deck
Outcomes
  • Realistic view of certification readiness and effort to close.
  • Defensible prioritisation for leadership and budget owners.
  • Baseline to measure programme progress against.

Ready to scope gap assessment for your organisation?

SVC-0303 / 09

Implementation

End-to-end design and rollout of the management system — policies, procedures, controls, RACI, evidence and tooling — built with your team, not handed over as a shelf of PDFs.

Typical duration
4–9 months
Applies to
ISO/IEC 27001ISO/IEC 27701ISO/IEC 42001ISO 22301ISO 9001ISO 14001ISO 45001ISO/IEC 20000-1ISO 37301
Scope of work
  • Management system architecture and documentation set.
  • Control design, RACI and evidence workflows.
  • Tooling selection and configuration (GRC, IAM, DLP, SIEM, DPIA).
  • Awareness, role-based training and go-live coaching.
Deliverables
  • Full policy & procedure library
  • Statement of Applicability (SoA)
  • Control operating procedures & evidence templates
  • Awareness programme & training records
Outcomes
  • Operating management system, not just documentation.
  • Clear control ownership and evidence generation cadence.
  • Ready for internal audit within 60–90 days of go-live.

Ready to scope implementation for your organisation?

SVC-0404 / 09

Risk & Controls

An ISO 31000 risk methodology that plugs into Annex A, NIST and sectoral control libraries — with treatment plans your risk owners can actually operate.

Typical duration
6–10 weeks
Applies to
ISO 31000ISO/IEC 27001ISO/IEC 27005ISO 22301NIST CSF / 800-53COBIT 2019
Scope of work
  • Enterprise risk framework, appetite statement and taxonomy.
  • Asset, threat and vulnerability modelling.
  • Control library mapping (Annex A, NIST, COBIT, sectoral).
  • Risk register operation, KRI catalogue and treatment tracking.
Deliverables
  • Risk management framework & methodology
  • Enterprise risk register with treatment plans
  • Cross-framework control mapping
  • KRI dashboard & escalation runbook
Outcomes
  • Board-defensible risk posture and appetite alignment.
  • One control library that satisfies multiple standards.
  • Traceable link from risk → control → evidence.

Ready to scope risk & controls for your organisation?

SVC-0505 / 09

Internal Audit

Independent internal audits run by certified Lead Auditors — with findings written to be closed, not filed, and management review packs that stand up to external scrutiny.

Typical duration
Ongoing (annual programme) or point-in-time
Applies to
ISO 19011ISO/IEC 27001ISO/IEC 27701ISO/IEC 42001ISO 22301ISO 9001ISO 14001ISO 45001ISO 37301
Scope of work
  • Annual internal audit programme design (risk-based).
  • Audit planning, fieldwork, sampling and evidence review.
  • Findings, non-conformity and CAPA management.
  • Management review inputs, minutes and outputs pack.
Deliverables
  • Internal audit programme & schedule
  • Audit reports with rated findings
  • CAPA tracker and closure evidence
  • Management review pack
Outcomes
  • Real issues found and fixed before the certification body arrives.
  • Independent assurance to the audit committee.
  • Demonstrable continual improvement cycle.

Ready to scope internal audit for your organisation?

SVC-0606 / 09

Certification Readiness

Stage-1 and Stage-2 dry runs, evidence libraries and auditor liaison — so the external certification audit is a formality, not a surprise.

Typical duration
6–10 weeks pre-audit + on-site support
Applies to
ISO/IEC 27001ISO/IEC 27701ISO/IEC 42001ISO 22301ISO 9001ISO 14001ISO 45001ISO/IEC 20000-1ISO 37301
Scope of work
  • Stage-1 readiness review and documentation dry run.
  • Stage-2 dry run with sampling, interviews and evidence walkthroughs.
  • Evidence library curation and audit trail hygiene.
  • Certification body liaison and on-site audit support.
  • Post-audit non-conformity closure and follow-up.
Deliverables
  • Stage-1 & Stage-2 readiness reports
  • Curated evidence library
  • Interviewee coaching pack
  • Post-audit closure plan
Outcomes
  • First-attempt Stage-2 pass with minimal non-conformities.
  • Confident, well-prepared interviewees.
  • Clean recertification cycle every three years.

Ready to scope certification readiness for your organisation?

SVC-0707 / 09

Integrated Management System

Merge ISO 27001, 27701, 22301, 9001, 14001, 45001 and 42001 into a single integrated system — audited once, demonstrated many times.

Typical duration
6–12 months (depending on scope)
Applies to
ISO/IEC 27001ISO/IEC 27701ISO/IEC 42001ISO 22301ISO 9001ISO 14001ISO 45001
Scope of work
  • Annex SL harmonisation across in-scope standards.
  • Unified policy, risk, control and evidence architecture.
  • Single management review, internal audit and CAPA process.
  • Combined certification audit planning with the certification body.
Deliverables
  • Integrated management system manual
  • Unified control library & evidence set
  • Combined internal audit programme
  • Integrated management review pack
Outcomes
  • 60%+ overlap harvested across standards.
  • One team, one calendar, one evidence set.
  • Lower audit fatigue and lower total cost of compliance.

Ready to scope integrated management system for your organisation?

SVC-0808 / 09

vCISO / vDPO on Retainer

Fractional Chief Information Security Officer and Data Protection Officer services — senior operator time without a senior operator's fixed cost.

Typical duration
Retainer — typically 2–8 days per month
Applies to
ISO/IEC 27001ISO/IEC 27701ISO/IEC 42001GDPRUAE PDPLKSA PDPLNIST CSF / 800-53
Scope of work
  • Monthly steering, risk oversight and control governance.
  • Incident response leadership and regulator liaison.
  • Board and audit committee reporting.
  • Programme management for security, privacy and AI initiatives.
  • DPO statutory duties: DPIAs, ROPA oversight, DSAR governance, breach notification.
Deliverables
  • Monthly steering pack & KRI report
  • Quarterly board briefing
  • Incident playbooks & tabletop exercises
  • DPO statutory register & regulator correspondence
Outcomes
  • Named, accountable senior owner at fractional cost.
  • Continuous programme oversight between audits.
  • Regulator-facing DPO role fully covered.

Ready to scope vciso / vdpo on retainer for your organisation?

SVC-0909 / 09

KPI & Reporting

Board-ready compliance dashboards, maturity scoring and continual improvement cycles — reporting that drives decisions, not just fills slides.

Typical duration
6–8 weeks build + ongoing operation
Applies to
ISO/IEC 27001ISO/IEC 27004ISO/IEC 27701ISO/IEC 42001ISO 22301ISO 9001ISO 37301
Scope of work
  • KPI/KRI catalogue design across security, privacy, AI, quality and BCM.
  • Maturity model definition and scoring (CMMI-aligned).
  • Automated data pipelines from GRC, IAM, SIEM and ticketing tools.
  • Board, audit committee and regulator report templates.
  • Continual improvement cadence and objective setting.
Deliverables
  • KPI & KRI catalogue
  • Maturity model & scorecard
  • Live compliance dashboard
  • Board, audit committee & regulator report templates
Outcomes
  • Decision-grade reporting instead of heatmap theatre.
  • Objective, tracked maturity progression year on year.
  • Evidence of continual improvement for external auditors.

Ready to scope kpi & reporting for your organisation?

Applied across

Every management system we consult on.

ISO/IEC 27001ISO/IEC 27701ISO/IEC 42001ISO 22301ISO 9001ISO 14001ISO 45001ISO/IEC 20000-1ISO 37301ISO 31000ISO 55001ISO 56002GDPRUAE PDPLKSA PDPLNIST CSF / 800-53COBIT 2019
Next step

Scope your engagement in a 30-minute call.

Tell us the standards you're targeting and where you are today — we'll come back with a shortlist of services, a phased plan and an indicative budget.

Contact us