Fabrizio Capaldi — Information Security

Rome, Italy/Audit & Assurance/Governance, Risk, Compliance

Fabrizio Capaldi

Senior Information Security & Cyber Security Consultant · Qualified Third-Party Lead Auditor


I assess and certify the management systems organisations rely on to stay secure, resilient and compliant. Work spans third-party certification audits under Accredia and international accreditation, advisory on EU digital regulation — NIS2, DORA and the AI Act — and the governance of artificial intelligence under ISO/IEC 42001. Engineering background, auditor's discipline.

10Lead auditor schemes
7International certifications
2008In IT & security since

Areas of practice

What I am engaged for

01 / AUDIT

Audit & certification

First-, second- and third-party audits across ISO/IEC 27001, 27701, 22301, 20000-1, 42001, ISO 9001 and 56001, plus SOC 1, SOC 2 and CSA STAR.

02 / REGULATION

EU digital compliance

Gap analysis, remediation design and compliance monitoring for NIS2, DORA, GDPR, the Data Act and the EU AI Act — with NIST CSF, CIS Controls v8 and ENISA guidance as working references.

03 / AI

AI governance & security

Design and audit of AI management systems under ISO/IEC 42001 and 42005 and the NIST AI RMF, including the attack surface of enterprise AI and agentic architectures.

04 / INSPECTION

Inspection & assurance

Qualified inspector for a Type-A cybersecurity inspection body under ISO/IEC 17020: technical inspections, architectural assessment and conformity evaluation.

Lead auditor register

Third-party qualifications

Standard / scheme Qualified since Accredited scopes Accreditation
ISO/IEC 27001:2022also 2013 edition Feb 2021 ISC01 Information technology · ISC02 Banking & financial services · ISC03 Telecommunications · ISC04 Healthcare · ISC05 Education Accredia / International
ISO/IEC 27701:2019Privacy information management Apr 2024 ISC01 Information technology · ISC05 Education Accredia / International
CSA STAR CertificationCloud Security Alliance Aug 2022 ISC01 Information technology Accredia / CSA STAR
ISO/IEC 27017 & 27018Cloud security, PII in public clouds Feb 2021 Cloud security and protection of personally identifiable information (ICT) Bureau Veritas scheme
ISO 22301:2019Business continuity Feb 2023 BCC33 Information technology · BCC34 Engineering services · BCC29 Wholesale & retail · BCC35 Other services Bureau Veritas scheme
ISO/IEC 20000-1:2018IT service management Feb 2021 20K01 Information technology Bureau Veritas scheme
ISO 9001:2015Quality management Feb 2021 EA 33 IT · EA 31 Telecommunications · EA 34 Engineering services · EA 37 Education · EA 35 Other services · EA 29 (B, C, E) Wholesale & retail Accredia / International
ISO/IEC 42001:2023AI management systems Nov 2024 Artificial intelligence management system (AIMS) Bureau Veritas scheme
ISO 56001:2024 & 56002Innovation management Feb 2023 Innovation management systems Bureau Veritas scheme
ISO 31000:2018Risk management Feb 2023 Risk management guidelines Bureau Veritas scheme

Third-party lead auditor activity carried out on behalf of Bureau Veritas Italia under Accredia and international accreditation. Scope codes follow the accreditation sector classifications for each scheme.

ISO/IEC 17020 cybersecurity inspector

Qualified inspector for a Type-A inspection body, performing technical inspections, architectural assessments and conformity evaluations.

ISAE 3402 / SOC 1 / SOC 2

Evaluation of internal controls and Trust Services Criteria — security, availability and confidentiality — for service organisations.

Technical review & certification decisions

Independent review of third-party audit dossiers and membership of the technical committees that grant certification.

National accreditation audits

Direct experience of Accredia witness and office audits for the initial granting and maintenance of ICT certification schemes.

Professional certifications

Independently verifiable

All badges on Credly ↗
AAISM2025

ISACA

Advanced in AI Security Management

Securing enterprise AI architectures, identifying machine-learning attack surfaces and applying AI models to security operations.

Verify on Credly
AAIA2025

ISACA

Advanced in AI Audit

Auditing and benchmarking AI systems, data pipelines, bias and explainability, and their alignment with regulation.

Verify on Credly
CCSK v42022

Cloud Security Alliance

Certificate of Cloud Security Knowledge

Cloud architecture security, identity and access management, cloud risk governance, encryption and incident response.

Verify on Credly
CISA2018

ISACA

Certified Information Systems Auditor

The benchmark credential for auditing IT governance, infrastructure, systems acquisition, continuity and information asset protection.

Verify on Credly
CISM2019

ISACA

Certified Information Security Manager

Information security governance, programme development, risk management and incident response at executive level.

Verify on Credly
CRISC2019

ISACA

Certified in Risk and Information Systems Control

Identification and evaluation of enterprise IT risk, mitigation strategy and the monitoring of IT controls.

Verify on Credly
PMP2020

Project Management Institute

Project Management Professional

Initiating, planning, executing, monitoring and closing complex technology and business programmes.

Verify on Credly

Experience

Full history on LinkedIn

  • 2024 — present Information Security & Cyber Security ConsultantGerico Security — Rome. Multi-scheme lead auditor, regulatory compliance and business continuity consulting, qualified cybersecurity inspector, technical reviewer for official lead auditor training.
  • 2021 — 2023 Product Manager & Product Developer, Digital ICTBureau Veritas Italia — Rome. Third-party lead auditor, development of new ICT certification services, technical presales, certification committee member.
  • 2016 — 2021 IT ManagerSABI Consulting — Rome. Corporate IT infrastructure, cybersecurity, disaster recovery and business continuity; R&D in cloud big-data processing and AI; IT GRC consulting.
  • 2008 — 2016 IT Manager · Software DeveloperCobaco — Rome. From software development and network administration to IT management, covering network security, systems and vendor governance.

Technical & governance background

Engineering foundation

Frameworks & regulation

NIS2DORAEU AI ActGDPRData ActNIST CSFCIS Controls v8OWASPCSA CCMENISA

AI governance & technology

ISO/IEC 42001ISO/IEC 42005NIST AI RMFLLM integrationModel Context ProtocolAgentic architecturesCompliance automation

Software & cloud

C# / .NETASP.NET MVCTypeScriptNode.jsPythonPowerShellMicrosoft AzureAzure DevOpsCI/CD

Data & business intelligence

SQL ServerPostgreSQLMariaDB / MySQLSQLiteSSISSSRSETL & data warehousing

Networks & security operations

Cisco routing & switchingCisco ASAActive DirectoryZero TrustWiresharkSplunkNetFlowSyslog

Open to audit, assurance and advisory engagements.

The most reliable way to reach me — and the complete professional history — is my LinkedIn profile.