One compliance function. Three ways to start.
Whether you're facing your first enterprise security review, preparing for ISO certification or trying to keep an existing programme running, Complyd becomes the compliance function behind your team.
Your team
Ships product
- Roadmap unchanged
- Evidence pulled, not authored
- One weekly touchpoint
Complyd
Owns the function
- ISMS & AIMS operated
- Auditor engagement led
- Questionnaires answered
- Risk register maintained
Your buyer
Clears the deal
- Security review passed
- Certificate on file
- Legal & DPA closed
Start where you are
Some clients need clarity. Some need certification now. Others already have a programme but no one to run it. Choose the entry point that matches your current problem.
Three ways to engage. One compliance operating model.
Run our compliance function
Virtual Compliance Officer
Your compliance function without the full time hire.
From A$5,500/month
3-month initial engagement.
AI and SaaS teams with recurring enterprise reviews, audit requirements and AI product changes that need a dedicated compliance owner.
Customer reviews progress, evidence stays current and compliance actions have a clear owner.
- Named compliance lead and operating calendar
- Up to two standard security questionnaires per month
- Evidence, risk register and compliance action maintenance
- One scoped AI or supplier change review per month
- AI agent permission, approval and incident escalation evidence
- Monthly leadership report and review meeting
- Agreed audit maintenance activities for your existing programme
The starting package covers one legal entity, one principal product or workflow and one agreed existing compliance framework. Questionnaires are limited to 250 questions in total per month, with one consolidated follow up round per questionnaire. Annual audit activities are defined in your proposal. Initial implementation, additional frameworks and expanded review volumes are scoped separately. No onboarding fees.
Get us ready for certification
Certification Sprint
From A$28,000
Fixed scope. Certification body fees separate.
Companies with a defined ISO 27001 or ISO 42001 certification requirement and a business deadline.
An implemented management system, organised evidence and support through your certification process.
- One agreed framework: ISO 27001 or ISO 42001
- Management system scope and implementation plan
- Risk assessment, treatment and policy development
- Control implementation support and evidence preparation
- Objective internal audit and management review preparation
- Certification body coordination
- Stage 1, corrective actions and Stage 2 support
Indicative project range: A$28,000–A$49,000+ depending on company size, readiness and complexity. Combined frameworks and additional implementation requirements are quoted separately. Independent certification body fees are separate, and the certification body makes the certification decision. Ongoing VCO support is a separately scoped engagement.
Show us what is required
Compliance Roadmap
A$3,500
Fixed assessment scope.
Teams that need to clarify a customer requirement, certification goal or AI governance gap before committing to implementation.
A prioritised plan with clear actions, proposed owners and a recommended delivery scope.
- Clarify the business requirement and assessment scope
- Review an agreed sample of evidence and controls
- Assess gaps against the agreed framework or requirement
- Prioritise actions, dependencies and proposed owners
- Recommend an implementation sequence and next step scope
An assessment and plan for an agreed requirement. Detailed questionnaire completion, implementation and certification delivery are scoped separately. You can start directly with a VCO engagement or Certification Sprint when the scope is already clear.
All amounts AUD, ex GST.
Coordinated delivery across four global offices through initial certification and the subsequent surveillance audit.
“Joe built out the vendor due diligence and continuous monitoring that stood up to scrutiny from our most demanding enterprise customers, leaving us with a sustainable programme the team genuinely understands.”

Founder & CEO, The Martec
Get the function without building the department
Enterprise customers increasingly expect someone to own security, governance and compliance. Hiring that capability internally is expensive, and distributing it across founders and engineers creates a second job for the people building the product.
Internal team
Recruit, onboard and manage specialist headcount.
DIY / software only
Tools collect evidence, but your team still owns the decisions, remediation and customer questions.
Complyd VCO
One accountable compliance function that runs the programme alongside your team.
What your Virtual Compliance Officer owns
Managed compliance for growing AI & SaaS companies: six areas of responsibility inside one outsourced compliance function, not thirty separate things to buy.
Enterprise trust
- Security questionnaires
- Customer due diligence
- Trust evidence
- Procurement support
- Agent permission evidence
- Incident escalation records
Certification
- ISO 27001
- ISO 42001
- Audit coordination
- Surveillance preparation
Evidence & controls
- Evidence library
- Control reviews
- Access reviews
- Management-system maintenance
AI governance
- AI system inventory
- AI risk assessments
- Model and vendor governance
- Guardrails and control mapping
- Agent approval and denied action records
Third-party risk
- Vendor due diligence
- Supplier monitoring
- Risk tracking
Governance
- Risk register
- Management review
- Compliance roadmap
- Regulatory change monitoring
Frequently Asked Questions
Which engagement should I start with?
If you're unsure what you need, start with the Compliance Roadmap. If an ISO deadline or enterprise requirement is already clear, we can scope a Certification Sprint directly. If you already have a programme and need someone to run it, start with the Virtual Compliance Officer.
Do I have to complete the Roadmap before a Certification Sprint?
No. The three engagements are different entry points. We recommend the Roadmap when the requirement or scope is still unclear.
Do I need ISO 27001 before ISO 42001?
Not necessarily. The right sequence depends on your existing controls, customer requirements and certification goals. We scope the shortest practical path rather than applying one sequence to every company.
How does Complyd work with Vanta or Drata?
Those platforms can help collect and monitor evidence. Complyd owns the judgement, implementation, certification process, remediation and customer-facing compliance work around the tooling.
Do you guarantee ISO certification?
No independent consultant should make that promise. We take ownership of readiness, implementation, evidence, internal audit and certification support. The accredited certification body makes the final certification decision.
What happens during Stage 1 and Stage 2?
We prepare the evidence, coordinate the process and support your team through both stages so you're not managing the auditor relationship alone.
What happens after certification?
The Virtual Compliance Officer can keep the programme operating through evidence maintenance, security reviews, access reviews, vendor governance, surveillance audits and ongoing AI governance.
Is the Virtual Compliance Officer priced by hours?
No. You're buying ownership of a compliance function, not a block of consulting hours. Pricing is scoped around the size and complexity of the environment.
Which industries do you work with?
Complyd is built primarily for AI, SaaS and technology companies selling into enterprise and regulated markets, including healthtech, financial services and other high-trust environments.
Not sure where to start?
Tell us what's driving the requirement. In 25 minutes we'll determine whether you need a Roadmap, a Certification Sprint or ongoing compliance ownership.
Book a Compliance Strategy Call