← All assessments
For teams standing up governance for SOC 2, ISO or a raise · fixed-fee assessment

The policy set an auditor or investor expects.

An auditor or investor asks for your policy set — and you’ve got a folder of half-finished Google Docs.

Your current policies reviewed against the suite a software and technology company actually needs, the gaps rated by risk, and a board-ready set mapped to how you work — with a rollout plan, delivered in about a week.

✓ Put-right-or-refund guarantee. Fixed scope, fixed fee · report in about a week · Enterprise scoped on a free intro call.

representative layout
Internal Policies Review

Your policy review

  • Findings & summary1 p
  • Gap listrisk-rated
  • Priority mark-upsboard-ready · ×5
  • Rollout planowner · sign-off
  • ISO 27001 / SOC 2 mappingincluded
  • Walkthrough call60 min
Findings — extract
HighInfoSec policy unapproved — no management sign-offfix · 1 wk
MedWhistleblowing channel undocumentedfix · 2 wks
LowPolicy review cadence lapsed (12 months)at renewal
Fix-first roadmap
SCORE · Gaps foundcurrent as of July 2026
What you get

Two ways to run it.

Standard is a fixed price you buy directly. Enterprise covers multiple entities and hands-on rollout, scoped on a short call.

Standard · €3,200

The policies you’re missing

  • Your current policies reviewed against the suite a software and technology company actually needs
  • A gap list — what’s missing, outdated or unenforceable — each rated by risk
  • Your 5 priority policies marked up against the standard — the 5 that matter most
  • A rollout plan: who owns each policy, how it’s signed off and where it lives
  • A written report and a walkthrough call

Fixed scope — one company, the core policy suite · report in about a week

Book now — €3,200

✓ Put-right-or-refund — revised until right, or refunded in full (14 days)

Enterprise · from €5,900

Org-wide rollout

  • Everything in Standard, plus:
  • Multiple entities, products or business units
  • Hands-on rollout, training and sign-off tracking
  • Ongoing upkeep as your business and the rules change

Scoped to your estate

How it works

From access to roadmap in about a week.

How every assessment runs
01 · intake
Scope confirmed

You share access and context; we agree the scope in writing before any work starts.

02 · analysis
Classified & scored

We test your setup against the obligations that bind you — each finding cited, rated by risk and effort.

03 · report
Board-ready findings

A written report: findings, a scored rating and a prioritised fix-first roadmap.

04 · walkthrough
Live call

We talk through the findings, the priorities and your questions.

05 · follow-up
Yours to keep

The report, roadmap and relevant kit templates — plus a review a month on.

Working with your team

Enterprise and retained work can run in a shared Slack or Microsoft Teams channel — hand-offs where your team already works, our side archived on Proton.

The deliverable

A report you can take to the board.

What lands in your inbox.

A written, board-ready report (PDF) — your policy set checked against the full reference suite, gaps risk-rated, your five priority policies marked up (Word, tracked changes), an ISO 27001 / SOC 2 control mapping and a rollout plan — plus a 60-minute walkthrough call.

Representative layout.

Example findings

  • — “Whistleblowing: no internal channel · statutory at your headcount · policy marked up in Word, ready to adopt.”
  • — “Information security policy references a VPN retired last year · risk High / effort Low.”
  • — “Thirteen-policy board set expected; you hold seven, four stale, none signed off.”
A consultant building your policy suite from scratch bills for weeks.

The review, the gap list and a board-ready set mapped to ISO 27001 and SOC 2 — mapped to how you work — as a fixed €3,200, in about a week. Put-right-or-refund, in writing.

Who does the work
SENIOR
EXPERT

You work with the person behind the templates: 15 years across contracts, GDPR, IP and the AI Act — 10,000+ contracts and corporate documents reviewed, 1,000+ deals negotiated, a recent USD 40M+ exit managed end to end. Consulting clients work with the founder directly, by name.

Fixed scope, fixed fee, agreed up front · not legal advice · no lawyer–client relationship

Want the DIY version first? The Internal Policies Pack — the same substance, done yourself for a fraction of the price.

See the kit

Already own the Internal Policies Pack? Its fee is credited in full against this assessment.

Scope — what €3,200 buys, and the limits

Limits — 15 documents in, deep redlines on 5. Not included — writing new policies from scratch (that's the Internal Policies Pack).

The policy menu

Wherever you are with your policies, here’s what fits.

Pick the one that matches where you are — each stands alone, buy in any order or on its own. Your team does the work with our templates; that’s why this costs a fraction of a consultancy.

Check yourself — free
Internal Policies Gap-CheckScores your policy pack and points to the fix, free.Open ›
Get assessedyou’re here
Internal Policies Review · €3,200Up to 15 policies reviewed, 5 marked up, ISO/SOC 2 mapped.On this page
Get the documents
Internal Policies Pack · €690Thirteen board-ready policies with a live adoption and evidence console.Open ›
Get it done, keep it current
Fractional · a free intro callOngoing upkeep, or a policy-set briefing call.Open ›
Eligibility, up front

Can we take this directly?

Three questions

1 · WHOSE RULES APPLY?

  • You’re established in the EU/EEA or the UK, or you target those marketsyes — delivered directly by the founder. Measuring what you have against what a regulation requires is compliance work, not reserved legal practice, which is why a senior assessment is available here at a fraction of a consultancy — lawfully, and in the open.
  • Another regime → tell us which in the enquiry. Most assessment work is open on the same basis; a few markets reserve formal advice on local law to admitted lawyers. We confirm within one business day, before any charge.

2 · WHAT THE ASSESSMENT PRODUCES

  • A findings report — your actual position measured against the Articles, cited, severity-ranked, with a prioritised remediation roadmap and the evidence trail behind each finding → that’s exactly what we deliver.
  • Something you can hand over — to a buyer’s diligence team, an enterprise procurement reviewer, or your board, without translating it first.

3 · WHERE THE LINE SITS

  • Reserved work → representation before a supervisory authority, regulator or court; conducting litigation; filings or notifications made on your behalf; notarial acts; a formal legal opinion in a market that restricts who may give one. That’s an admitted lawyer, and we’ll say so and route you rather than blur the line — introduced and coordinated by us, contracted by you directly.
  • Statutory appointments → naming a DPO, an Article 27 EU Representative or an AI Act Authorised Representative is a separate engagement with its own terms and its own liability, not something an assessment includes. If the assessment finds you need one, we’ll tell you — and we can take the role under a separate mandate.
  • Privilege → an assessment report is a written record of where you currently stand, and it is not covered by legal professional privilege. For most readiness work that’s the point — it’s evidence you’re looking honestly. Where there’s live investigation, complaint or litigation exposure, that calculus changes, and we’ll say so before we write rather than after.
  • What it is and isn’t → an assessment is a dated snapshot against the law as it stands on the day. It doesn’t itself make you compliant, and it doesn’t bind a regulator’s view.

We are not a law firm and don’t hold ourselves out as one. No court work, no filings, no regulated titles, no privilege. Tell us where you’re established and what needs assessing — scope is confirmed within one business day, and you’re never charged before it is.

Questions

Before you book.

We have some policies already — is this still useful?

Yes — that’s the starting point. We review what you have against the suite a software and technology company needs, tell you what’s missing, outdated or unenforceable, and fill the gaps with a coherent, board-ready set.

Will this satisfy a SOC 2 or ISO auditor?

The set is mapped to ISO 27001 and SOC 2, and the rollout plan is built to evidence approval and adoption — which is what auditors actually test.

Is this restricted legal advice?

No. This is a fixed-scope commercial compliance assessment — structured information and expert analysis of your posture — not legal advice, a formal legal opinion, or representation before a regulator. It’s run by a senior practitioner; no lawyer–client relationship or privilege is created, and Xprofesso LLC is not a law firm.

What we’ll do: assess your setup against the policy set procurement and investors expect, score it, and hand you a prioritised, fix-first roadmap plus the templates to close the gaps — where you stand, and what to do next.

What we won’t: give jurisdiction-specific employment-law opinions, handle HR casework, act for you before a supervisory authority or regulator, or give an opinion on whether a measure is legally sufficient under a specific law. Where you need a regulated professional, we say so and point you to a licensed lawyer.

What if I’m not happy with it?

Put-right-or-refund guarantee — if the report falls short, say so within 14 days of delivery: we revise it until it’s right or refund the fee in full.

Direct line · reply within one business day

Ask about scope before you book

One message — no account, no call required. It lands in our Proton inbox.

Proton (Switzerland) · no ad-tech · purged after 12 months

Prefer to talk it through? Book a free 20-minute intro call ›

Hand the auditor a real policy set.