← All services

ISMS / PIMS / AIMS: Gap Assessment, Implementation & Audit

Structured gap assessment and implementation support for ISO 27001 (ISMS), ISO 27701 (PIMS), and ISO 42001 (AIMS). We build control frameworks, evidence trails, and audit-ready documentation — not template decks that fail under scrutiny.

ISO 27001ISO 27701ISO 42001Gap Assessment

We map controls to your operating reality — not a generic template imported from another organisation. Certification is the outcome of control maturity your auditors can verify.

For regulator-mandated information security audits under NRB or NIA — rather than ISO certification — see Information Security Audit — NRB & NIA Regulatory Compliance.

Who this is for

Banks, FinTechs, insurers, and IT service organisations in Nepal preparing for ISO/IEC 27001:2022 certification — or extending to ISO/IEC 27701 (privacy) or ISO/IEC 42001 (AI management). Also suited to teams with an existing ISMS that need a credible gap assessment before internal audit or certification body review.

Methodology

  1. 01

    Gap Assessment

    Baseline your current controls against the applicable standard clauses and Annex A controls, with evidence review and stakeholder interviews.

  2. 02

    Remediation Roadmap

    Prioritised plan mapping gaps to owners, timelines, and resource needs — sequenced for certification readiness, not checkbox closure.

  3. 03

    Implementation Support

    Hands-on support building policies, procedures, risk treatment, and operational controls aligned to how your organisation actually works.

  4. 04

    Internal Audit

    Independent internal audit against the standard before the certification body arrives — findings you can fix, not surprises.

  5. 05

    External Audit Coordination

    Support through stage 1 and stage 2 certification audits, including evidence preparation and auditor response.

What you get

  • Gap assessment report with clause-level findings and maturity ratings
  • Remediation roadmap with prioritised actions and ownership
  • ISMS / PIMS / AIMS documentation pack (policies, procedures, SoA)
  • Risk assessment and risk treatment plan
  • Internal audit report and corrective action tracker
  • Certification readiness brief for leadership and the certification body
Plan your certification roadmap

Or email contact@trinitytech.com.np