# Goldline Consultancy > Goldline Consultancy Ltd is a UK practice that prepares companies for ISO/IEC 27001 and ISO/IEC 42001 certification, runs independent internal audits and risk assessments, and prepares defence suppliers for Defence Cyber Certification (DCC). Led by Alfred Obeng: CISSP, PMP, ISO 27001 Senior Lead Implementer and Lead Auditor, ISO 42001 Lead Implementer and Lead Auditor. Facts that stay the same on every page: - Legal name: Goldline Consultancy Ltd. Company number 10901798 (England and Wales). Registered office: 124 City Road, London, EC1V 2NX. Contact: info@goldlineconsultancy.co.uk. - Goldline is not a certification body. Certificates come from independent, accredited certification bodies. - Goldline is not licensed for DCC. It prepares suppliers; certification comes from an independent DCC certification body. - Goldline never audits a management system it implemented, and never sells implementation and certification to the same organisation for the same scope. - First step for any engagement: a free 45 minute diagnostic, booked at https://www.goldlineconsultancy.co.uk/book-a-call ## Services - [ISO 42001 certification for UK AI companies](https://www.goldlineconsultancy.co.uk/iso-42001-certification): what ISO/IEC 42001 asks of a company building AI into a product, how it sits alongside ISO 27001, and who issues the certificate. - [ISO 27001 internal audit, clause 9.2](https://www.goldlineconsultancy.co.uk/services/iso-27001-internal-audit): an independent internal audit of an ISMS, by an auditor who did not build it. - [ISO 42001 internal audit, clause 9.2](https://www.goldlineconsultancy.co.uk/services/iso-42001-internal-audit): an independent internal audit of an AI management system. - [Independent risk assessment mapped to ISO 27001](https://www.goldlineconsultancy.co.uk/services/independent-risk-assessment): a third party assessment of a company's security, findings mapped control by control to ISO/IEC 27001, for a customer who has asked for one. - [DCC Level 0 readiness](https://www.goldlineconsultancy.co.uk/defence-cyber-certification): preparing UK defence suppliers for Defence Cyber Certification Level 0, which the MoD has asked its industry partners to achieve by 31 December 2026. - [SOC 2 readiness for UK companies](https://www.goldlineconsultancy.co.uk/soc-2-readiness): preparing a UK company for a SOC 2 examination, which a licensed CPA firm carries out. - [Does NIS2 apply to a UK company?](https://www.goldlineconsultancy.co.uk/nis2): how to tell whether the EU NIS2 directive reaches a UK company, and what ISO 27001 does and does not cover. - [AI system security testing for ISO 42001](https://www.goldlineconsultancy.co.uk/services/ai-system-security-testing): testing AI products for prompt injection, data leakage and agent misuse, with findings mapped into ISO 42001 evidence and a retest. - [Managed compliance retainer](https://www.goldlineconsultancy.co.uk/services/managed-compliance): keeping an ISO 27001 or ISO 42001 certificate current: surveillance audit support, renewals, governance upkeep and security questionnaires. - [Pre-certification readiness audit](https://www.goldlineconsultancy.co.uk/services/pre-certification-readiness-audit): a mock audit against Stage 1 and Stage 2 criteria before the certification body arrives. - [Free Statement of Applicability review](https://www.goldlineconsultancy.co.uk/statement-of-applicability-review): one ISO 27001 Statement of Applicability, marked up and returned within 48 hours. - [Pricing](https://www.goldlineconsultancy.co.uk/pricing): Goldline's published UK prices, and what a certification body charges on top. ## Explainers - [DCC versus Cyber Essentials](https://www.goldlineconsultancy.co.uk/insights/dcc-versus-cyber-essentials): how the two schemes relate, and what DCC Level 0 needs from Cyber Essentials. - [DCC Levels 0 to 3 explained](https://www.goldlineconsultancy.co.uk/insights/defence-cyber-certification-levels-explained): controls, scope and prerequisites at each DCC level. - [DEFCON 658 explained](https://www.goldlineconsultancy.co.uk/insights/defcon-658-explained-uk-tier-2-tier-3-defence-suppliers): what the MoD contract condition asks of tier 2 and tier 3 defence suppliers. - [Def Stan 05-138 explained](https://www.goldlineconsultancy.co.uk/frameworks/def-stan-05-138): the MoD cyber risk levels and control set behind DEFCON 658 and DCC. - [What a Stage 2 auditor asks about clause 9.2](https://www.goldlineconsultancy.co.uk/insights/what-a-stage-2-auditor-asks-about-clause-9-2): the internal audit evidence a certification auditor samples. - [Can your implementer audit your AIMS?](https://www.goldlineconsultancy.co.uk/insights/can-your-implementer-audit-your-aims): independence in an ISO 42001 internal audit. - [Who can issue an ISO 42001 certificate in the UK?](https://www.goldlineconsultancy.co.uk/insights/who-can-issue-an-iso-42001-certificate-uk): accreditation for ISO 42001 certification bodies, and the questions to ask one. - [ISO 27001 vs ISO 42001](https://www.goldlineconsultancy.co.uk/insights/iso-27001-vs-iso-42001): what each standard governs, where they overlap, and which to do first. - [Choosing a UKAS-accredited certification body for ISO 27001](https://www.goldlineconsultancy.co.uk/insights/choosing-iso-27001-certification-body): how to shortlist and book a certification body. - [The ISO 27001 Statement of Applicability](https://www.goldlineconsultancy.co.uk/knowledge/statement-of-applicability): what an SoA must contain for every Annex A control. - [ISO 27001 cost calculator](https://www.goldlineconsultancy.co.uk/tools/iso-27001-cost-calculator): an ISO 27001 price band and certification body estimate from four questions. ## Optional - [About Goldline](https://www.goldlineconsultancy.co.uk/about): the practice and its founder. - [Glossary](https://www.goldlineconsultancy.co.uk/knowledge/glossary): plain definitions of UK security and AI assurance terms.