Audit & compliance

Qualify the obligations. Measure the gaps. Organise the evidence.

The IKNSA Audit & compliance practice covers GDPR, NIS2, HDS, the AI Act, DORA, the CRA and related frameworks. It establishes the scope, assesses the situation, builds the trajectory and prepares the demonstrable elements.

Operational compliance

Cross-cutting and sector frameworks, connected to how things actually run.

The assessment determines the applicable scope, the priority gaps and the evidence already available. Common requirements are pooled without creating artificial equivalence between the texts.

GDPR

Data protection

Responsibilities, records of processing, legal bases, minimisation, rights, processors, security and breach management.

Goal: governed processing and well-managed processors.

NIS2

Cyber resilience

Risk governance, security measures, continuity, supply chain, incident management and notification.

Goal: prepare the scope and the evidence expected in France.

HDS

Health data

Qualification of the need, sharing of responsibilities, target architecture and migration to HDS-certified hosting services.

Goal: use a certified scope with no ambiguity of roles.

About HDS

IKNSA does not claim HDS certification. We design and support architectures on certified offerings, with a documented sharing of responsibilities. Any hosting or managed-services activity falling within the HDS scope must be carried by a certified perimeter.

Abstract architectural composition representing evidence, control and compliance
Obligations qualified, gaps prioritised, evidence organised

Our approach

From scope to evidence, without a programme running parallel to the information system.

Compliance becomes durable when it joins investment decisions, changes, operations and vendor contracts.

01

Qualify

Entities, activities, data, critical services, applicable texts and stakeholders.

02

Assess

Risks, existing controls, gaps, dependencies and available evidence.

03

Transform

Roadmap, technical measures, processes, contracts and support.

04

Demonstrate

Evidence files, exercises, management reviews and audit preparation.

Demonstrability

A policy is not proof of effectiveness.

Controls must produce dated, attributable, reviewable elements: decisions, test results, incidents, exceptions, reviews and action plans. We build this chain of evidence with the teams who actually operate the information system.

ControlExamples of evidence
Risk managementMapping, owners, decisions, treatment plans
Identities & accessReviews, entitlement records, privileged accounts, leavers
VulnerabilitiesInventory, scans, remediation times, exceptions and acceptances
ContinuityPlans, restore tests, exercises, observed RPO and RTO
SuppliersEvaluation, clauses, subcontractors, service levels, exit

Who does what

Supporting is not certifying. Preparing is not self-auditing.

We define the roles before the engagement to avoid any ambiguous promise or conflict of interest. The Audit & compliance practice is distinct from the Cybersecurity practice: they can contribute to the same programme, but their mandates, people and deliverables remain identified.

Certification bodies, regulated auditors, DPOs and technical providers keep their own responsibilities. Where formal independence is required, implementation and evaluation are not entrusted to the same actor.

Discover the Cybersecurity practice

  1. 1

    Your organisation decides and owns the risk

    Management approves the scope, the priorities and the residual risks.

  2. 2

    The Audit & compliance practice structures

    Qualification, assessment, roadmap, coordination and evidence preparation under the mandate.

  3. 3

    The accredited third party evaluates where required

    A certification body, qualified auditor or independent adviser acts within its own framework.

  4. 4

    The measures live in the information system

    The Cyber practice and the operations teams implement, test and improve the controls that fall under their mandate.

Frequently asked questions

Framing a compliance initiative.

Can you certify our GDPR or NIS2 compliance?
We can carry out an assessment, support the remediation and prepare the evidence. We do not present this support as an official certification. Where a qualified audit or a certification is needed, the competent third party is appointed separately.
How do we know whether our company falls within the scope of NIS2?
The analysis looks at the legal entity, its size, its sector, the nature of the services and the special cases provided for by the texts. In France, the transposition framework and ANSSI publications must be followed; we always date our analysis and document the assumptions.
Can GDPR, NIS2 and ISO 27001 be handled in a single trajectory?
Yes, by pooling risk governance, asset management, suppliers, incidents, continuity and evidence. The requirements specific to each framework remain identified to avoid artificial equivalence.

First conversation

Let’s discuss the next point of control for your information system.

A project to frame, operations to take over, compliance to demonstrate? Describe the context. You will get a first considered reading — not a generic brochure.