Audit & certification
First-, second- and third-party audits across ISO/IEC 27001, 27701, 22301, 20000-1, 42001, ISO 9001 and 56001, plus SOC 1, SOC 2 and CSA STAR.
Rome, Italy/Audit & Assurance/Governance, Risk, Compliance
Senior Information Security & Cyber Security Consultant · Qualified Third-Party Lead Auditor
I assess and certify the management systems organisations rely on to stay secure, resilient and compliant. Work spans third-party certification audits under Accredia and international accreditation, advisory on EU digital regulation — NIS2, DORA and the AI Act — and the governance of artificial intelligence under ISO/IEC 42001. Engineering background, auditor's discipline.
What I am engaged for
First-, second- and third-party audits across ISO/IEC 27001, 27701, 22301, 20000-1, 42001, ISO 9001 and 56001, plus SOC 1, SOC 2 and CSA STAR.
Gap analysis, remediation design and compliance monitoring for NIS2, DORA, GDPR, the Data Act and the EU AI Act — with NIST CSF, CIS Controls v8 and ENISA guidance as working references.
Design and audit of AI management systems under ISO/IEC 42001 and 42005 and the NIST AI RMF, including the attack surface of enterprise AI and agentic architectures.
Qualified inspector for a Type-A cybersecurity inspection body under ISO/IEC 17020: technical inspections, architectural assessment and conformity evaluation.
Third-party qualifications
| Standard / scheme | Qualified since | Accredited scopes | Accreditation |
|---|---|---|---|
| ISO/IEC 27001:2022also 2013 edition | Feb 2021 | ISC01 Information technology · ISC02 Banking & financial services · ISC03 Telecommunications · ISC04 Healthcare · ISC05 Education |
Accredia / International |
| ISO/IEC 27701:2019Privacy information management | Apr 2024 | ISC01 Information technology · ISC05 Education |
Accredia / International |
| CSA STAR CertificationCloud Security Alliance | Aug 2022 | ISC01 Information technology |
Accredia / CSA STAR |
| ISO/IEC 27017 & 27018Cloud security, PII in public clouds | Feb 2021 | Cloud security and protection of personally identifiable information (ICT) | Bureau Veritas scheme |
| ISO 22301:2019Business continuity | Feb 2023 | BCC33 Information technology · BCC34 Engineering services · BCC29 Wholesale & retail · BCC35 Other services |
Bureau Veritas scheme |
| ISO/IEC 20000-1:2018IT service management | Feb 2021 | 20K01 Information technology |
Bureau Veritas scheme |
| ISO 9001:2015Quality management | Feb 2021 | EA 33 IT · EA 31 Telecommunications · EA 34 Engineering services · EA 37 Education · EA 35 Other services · EA 29 (B, C, E) Wholesale & retail |
Accredia / International |
| ISO/IEC 42001:2023AI management systems | Nov 2024 | Artificial intelligence management system (AIMS) | Bureau Veritas scheme |
| ISO 56001:2024 & 56002Innovation management | Feb 2023 | Innovation management systems | Bureau Veritas scheme |
| ISO 31000:2018Risk management | Feb 2023 | Risk management guidelines | Bureau Veritas scheme |
Third-party lead auditor activity carried out on behalf of Bureau Veritas Italia under Accredia and international accreditation. Scope codes follow the accreditation sector classifications for each scheme.
Qualified inspector for a Type-A inspection body, performing technical inspections, architectural assessments and conformity evaluations.
Evaluation of internal controls and Trust Services Criteria — security, availability and confidentiality — for service organisations.
Independent review of third-party audit dossiers and membership of the technical committees that grant certification.
Direct experience of Accredia witness and office audits for the initial granting and maintenance of ICT certification schemes.
ISACA
Securing enterprise AI architectures, identifying machine-learning attack surfaces and applying AI models to security operations.
Verify on CredlyISACA
Auditing and benchmarking AI systems, data pipelines, bias and explainability, and their alignment with regulation.
Verify on CredlyCloud Security Alliance
Cloud architecture security, identity and access management, cloud risk governance, encryption and incident response.
Verify on CredlyISACA
The benchmark credential for auditing IT governance, infrastructure, systems acquisition, continuity and information asset protection.
Verify on CredlyISACA
Information security governance, programme development, risk management and incident response at executive level.
Verify on CredlyISACA
Identification and evaluation of enterprise IT risk, mitigation strategy and the monitoring of IT controls.
Verify on CredlyProject Management Institute
Initiating, planning, executing, monitoring and closing complex technology and business programmes.
Verify on CredlyFull history on LinkedIn
Engineering foundation
The most reliable way to reach me — and the complete professional history — is my LinkedIn profile.