A normal guy, auditing normal people and normal processes. Tony believes good evidence beats a thick policy manual, a five-minute chat with the team tells you more than a fifty-page procedure, and an audit should leave people more confident, not less.
He works across ISO 27001, ISO 27701 and ISO 42001, and he sees the same thing every week: good people doing good work, who just need to show it. That is what Tony is about.
A policy says what you meant. A record shows what you did. Tony always asks for the second.
The real process lives with the person who runs it every day, so that is who Tony talks to first.
Findings are free advice with a deadline. A good audit leaves a team clearer and stronger, not anxious.
One short, practical line from the real world of ISO audits, posted every Friday on LinkedIn, X and Facebook, and collected here.
Policies tell me what you meant. Records tell me what you did.
New quote every Friday. Follow Cybercontrols on LinkedIn to catch the next one.
Practical, evidence-led ISO 27001, 27701 and 42001 support from a team that is certified itself. A 30-minute call, no obligation and no sales deck.