RuleHouse GRC Governance · Risk · Compliance Book a scoping call

Compliance that survives
the year after the audit.

An independent risk, compliance and information security advisory practice for mid-size enterprises. We build one control set, map it across every framework you are answerable to, and hand it over as something your teams can actually run — not a binder that expires the week the auditor leaves.

Map once, satisfy many One control library cross-walked across ISO, SOC 2, GDPR and DPDP — not four parallel programmes.
Fixed scope, fixed fee Every engagement is priced and bounded before it starts. No open-ended retainers.
Artefacts you own Editable documents, registers and trackers — with the reasoning written down, not locked in a platform.
Senior-only delivery The advisor who scopes your engagement is the one who does the work and faces your auditor.
Frameworks covered
  • ISO/IEC 27001:2022
  • SOC 2 — AICPA TSC
  • GDPR (EU) 2016/679
  • DPDP Act, 2023
  • ISO/IEC 42001:2023
  • NIST AI RMF
Services

Seven engagements, each with a defined finish

Every service below is a scope of work with named deliverables and a clear end point. Open “What’s included” on any card for the full detail.

ISO/IEC 27001 certification

From undefined scope to a certificate you can put in front of any enterprise buyer.

  • Statement of Applicability written from your real risk assessment
  • Policy set drafted to how your teams actually operate
  • Stage 1 and Stage 2 support through to closure
  • ISO/IEC 27001:2022
  • 93 Annex A controls
  • ISO/IEC 27002
What’s included
  • ISMS scope, context, interested parties and measurable objectives
  • Risk assessment methodology, register and treatment plans
  • Full policy, standard and procedure set
  • Internal audit programme and management review pack
  • Certification body liaison and nonconformity closure

SOC 2 readiness

A clean Type I, then an observation window your evidence can actually withstand.

  • Criteria mapping and system description
  • Evidence cadence sized to the Type II window
  • Auditor liaison through fieldwork
  • AICPA TSC
  • CC1–CC9
  • Type I & Type II
What’s included
  • Trust services category selection and system description
  • Control design against each applicable criterion
  • Evidence collection calendar with named owners
  • Pre-audit walkthroughs and exception remediation
  • Cross-walk to ISO 27001 so controls are written once, not twice

GDPR programme

The records a supervisory authority asks for, and the workflows your teams run weekly.

  • Data mapping and Records of Processing Activities
  • DPIA methodology and completed high-risk assessments
  • 72-hour breach playbook and DSAR workflow
  • Art. 30 RoPA
  • Art. 28
  • Art. 32
  • Art. 35 DPIA
  • Chapter V
What’s included
  • Lawful basis analysis, privacy notices and consent capture
  • Processor agreements, SCCs and transfer impact assessments
  • Retention schedule and erasure standard
  • Data subject request handling end to end
  • Accountability evidence pack for the regulator

India DPDP Act readiness

A programme built for the Act itself — not a re-badged GDPR file.

  • Consent notice design and consent manager integration
  • Data principal rights and grievance redressal workflow
  • Significant Data Fiduciary readiness where it applies
  • DPDP Act, 2023
  • Consent & notice
  • SDF duties
What’s included
  • Applicability and Data Fiduciary / Processor role assessment
  • Notice, consent and children’s data handling design
  • Nomination, correction and erasure request handling
  • DPO appointment, independent audit and impact assessment for SDFs
  • Breach intimation procedure and retention standards

AI governance

An honest inventory first, then rules that tell people which AI uses need review.

  • AI use-case inventory including shadow adoption
  • Risk classification and prohibited-use boundaries
  • Management system build toward ISO/IEC 42001
  • ISO/IEC 42001:2023
  • NIST AI RMF 1.0
  • EU AI Act tiers
What’s included
  • Use-case register across business units and vendors
  • Model, vendor and training-data due diligence standard
  • Human oversight, disclosure and acceptable-use policy
  • Evaluation, monitoring and incident handling for deployed models
  • Board reporting on AI risk posture

Third-party risk management

Diligence effort spent where a supplier can actually hurt you — and nowhere else.

  • Tiering by data access, criticality and concentration
  • Tier-appropriate questionnaire and assessor guidance
  • Security schedules and exit terms for contracts
  • Vendor tiering
  • SIG · CAIQ
  • SOC 2 report review
  • Fourth-party
What’s included
  • Tiering model and onboarding gate
  • Due diligence pack per tier, with scoring and escalation
  • SOC 2 / ISO certificate review including carve-outs and CUECs
  • Continuous monitoring and reassessment cycle
  • Concentration risk, exit planning and offboarding

Internal GRC tooling

The discipline of a GRC platform without the licence, the partner or the rollout.

  • One control library mapped across every framework in scope
  • Risk register with scoring, treatment and acceptance workflow
  • Testing calendar and evidence library, built in tools you own
  • Control library
  • Risk register
  • Evidence library
  • Board reporting
What’s included
  • Unified control library with framework cross-walk
  • Risk scoring model, treatment plans and exception workflow
  • Control testing tracker with owners, frequency and status roll-up
  • Evidence library structured the way auditors sample it
  • Handover with the logic documented and the team trained
Coverage

Why one control set beats four programmes

The same eight control domains carry most of the weight across every framework mid-size enterprises face. Build them once, evidence them once, and each audit becomes a mapping exercise rather than a fresh project.

Control domain ISO 27001 SOC 2 GDPR DPDP Act ISO 42001 EU AI Act
Governance & policy
Risk management
Access control
Third-party management
Data protection & privacy
Incident & breach response
AI oversight
Evidence & internal audit
Direct requirement Partial or related requirement Not addressed Indicative — confirmed against your scope during baseline.
How we work

Four phases, in this order, every time

Most stalled programmes design controls before they know what is already running, then spend the remediation budget twice. The sequence is the method.

1

Baseline

What exists versus what the framework asks — established from evidence and system walkthroughs, not a self-assessment questionnaire.

Output · scored gap register
2

Design

One control set covering every framework in scope, sized to your headcount and tooling. Written once, cross-referenced everywhere.

Output · control library & policies
3

Implement

Delivered alongside your engineering, IT and legal teams, in the systems they already use — documentation an auditor accepts and an engineer still follows in month nine.

Output · operating controls
4

Sustain

Testing calendar, evidence cadence, register reviews and management reporting — the rhythm that keeps the certificate honest between surveillance audits.

Output · assurance calendar
Engagements

Three ways to bring us in

Scope, duration and fee are agreed before work starts — and written into the statement of work.

Fixed scope · 4–8 weeks

Readiness assessment

One framework, assessed end to end, so you know how far the certification date really is before you commit budget to it.

  • Gap register scored by severity
  • Prioritised remediation plan with effort estimates
  • Realistic timeline and internal resourcing view
  • Executive read-out session

₹1,25,000 – ₹2,00,000 depending on scope

Named outcome · milestone-billed

Project delivery

A defined build with a defined finish, billed against milestones you can hold us to.

  • ISMS built and taken through certification
  • GDPR or DPDP Act programme stood up
  • Third-party risk function rebuilt from tiering upward
  • Internal GRC toolset delivered and handed over

Fixed fee, scoped per engagement

Deliverables

What is on your desk when we leave

Every engagement ends in artefacts you own outright, in editable formats, with the reasoning documented.

About the practice

One senior advisor, not a pyramid

Large firms sell you a partner and staff the work with juniors. This practice is deliberately small: the person who scopes your engagement is the person who writes your Statement of Applicability and sits across from your auditor.

That limits how many clients we take at once, and it is the point. Mid-size enterprises rarely need a standing compliance department — they need a specialist for the months it takes to build the programme, and a predictable retainer to keep it standing afterwards.

We work as an extension of your team, under your NDA, and we are equally willing to tell you a control is not worth implementing. Independence is the only thing an advisor actually sells.

On the name. Every framework you answer to — ISO 27001, SOC 2, the DPDP Act — is a set of rules somebody else wrote. The work is turning them into rules your business can actually live by, and keeping the house in order once they are in place.

Principal
Sumeet Mohapatra
Focus
SOC 2 · ISO/IEC 27001 · GDPR & DPDPA · AI governance · Third-party risk
Engagement
Remote-first; on-site for audits and workshops
Based in
Bangalore, India
Common questions

Before you get in touch

How long does ISO 27001 or SOC 2 actually take?

For a mid-size organisation with reasonable IT hygiene, expect four to six months from baseline to certification audit for ISO 27001, and a three to six month observation window for a SOC 2 Type II on top of readiness work. The honest answer depends on how much already exists — which is exactly what the readiness assessment establishes before you commit to a date.

We already have GDPR in place. Do we need a separate DPDP Act programme?

You need a separate design, not a separate programme. Much of the security and vendor work carries over, but consent architecture, the notice regime, children’s data, grievance redressal and the Significant Data Fiduciary obligations diverge enough that a re-badged GDPR file will not hold up. We map what transfers and build only the delta.

Do we need to buy a GRC platform first?

Usually not, and rarely at this stage. Platforms enforce a process you have not designed yet. We build the control library, register and evidence structure in tools you already own; if you later move to a platform, that structure is what you import — and the migration is far cheaper than an implementation from scratch.

Will you work with our existing auditor or certification body?

Yes. We remain independent of the audit itself — we do not certify our own work — but we prepare your teams for walkthroughs, respond to information requests, and manage nonconformity closure. If you have not selected a certification body yet, we can help you shortlist and compare.

What do you need from us to start?

A signed NDA, a named internal sponsor, and access to the people who run your systems. The first two weeks are largely interviews and evidence review; the demand on your team is front-loaded and tapers as the control set takes shape.

Contact

Start with the obligation, not the framework.

Tell us what is forcing the issue — a customer contract, a regulator, a failed questionnaire, a board paper due — and we will tell you the shortest defensible route to it. Scoping calls run 45 minutes and cost nothing.

ResponseWithin one business day