Skip to main content
Preview Your Audit
A series by JJ Milner · 12 chapters

The Compliance Industrial Complex

Rethinking ISO 27001 from first principles.

ISO 27001 is 93 controls. The standard itself can be read carefully in an afternoon. So why does certification routinely take twelve to eighteen months, cost six figures, and produce a binder that nobody opens between annual surveillance audits? This series is about that question — and about what compliance looks like if you build it the other way round, from evidence backwards instead of policy documents forwards. Twelve chapters. One argument.

II

Architecture

What evidence, platforms, controls, and risk look like rebuilt from first principles.

III

Operation

What that architecture does when an auditor arrives, when something breaks, and when your competitor doesn't have it.

Coda · in development · June 2026

The Trust Centre

Publishing compliance without publishing your IP.

A regulator emails. They are conducting a thematic review and would like to see your ISO 27001 evidence — not the certificate, the evidence — in forty-eight hours. The Trust Centre is the public surface where all of the above becomes visible without giving away the engineering that makes it work. In development now; arriving late June 2026.

See what the auditor would find. In 30 minutes.

Same questions a real ISO 27001 auditor asks. Immediate gap analysis.

Start your audit preview