Category: Simplification

  • UCM Global Case Study: ISO 27001 Implementation

    UCM Global Case Study: ISO 27001 Implementation

    When ISO 27001 Stops Being a Second Job

    For many organisations, ISO 27001 starts with good intentions and slowly turns into something else entirely: a growing pile of policies, audit panic every year, and a management system that feels disconnected from how the business actually operates.

    That was exactly what UCM Global wanted to avoid.

    Like many growing organisations, they needed an ISO 27001 implementation that would stand up commercially and operationally, not just during an audit. They had also experienced heavier approaches elsewhere: systems overloaded with generic documentation, excessive process layers, and AI-generated compliance material that looked impressive on paper but added friction in practice.

    Instead of building another “compliance machine”, the goal was to create something proportionate, usable, and embedded into the way the business already worked.

    That became the focus of the engagement with Collevo Consulting.

    The Challenge

    UCM Global needed to achieve ISO 27001 certification while navigating a number of operational and organisational realities:

    • Existing standards work elsewhere in the business felt unnecessarily heavy
    • Previous approaches had created bureaucracy rather than operational clarity
    • There was concern about introducing processes that staff would work around rather than use
    • The business had unique operational requirements that did not fit neatly into generic template-driven implementation
    • The organisation wanted an integrated management system approach that remained practical as additional standards evolved

    Like many SMEs and growing organisations, they did not need more paperwork. They needed better operational visibility, clearer ownership, and a system that could survive after the auditors left.

    That distinction matters.

    As explored in ISO 27001 Doesn’t Have to Be Painful, audit pain is often a symptom of systems that were never properly integrated into real operational behaviour in the first place.

    The Approach: Lean, Embedded, and Commercially Aware

    Rather than treating ISO 27001 as a standalone compliance exercise, the implementation focused on operational integration from the beginning.

    The work centred around a few key principles:

    Start with How the Business Actually Works

    Instead of beginning with control checklists or large template packs, the implementation started with operational reality:

    • What mattered to the business
    • Where dependencies existed
    • Where fragility sat
    • What genuinely needed protecting
    • Which controls were proportionate to actual risk

    This aligns closely with Collevo’s broader implementation doctrine: start with operational context and risk, not control recital.

    Keep the ISMS Lean

    The system was deliberately designed to avoid unnecessary complexity.

    That meant:

    • Tighter scoping
    • Proportionate documentation
    • Evidence tied to real operational processes
    • Avoiding duplicate workflows where existing systems already worked
    • Reducing “audit theatre” and manual evidence chasing

    The objective was not minimalism for its own sake. It was clarity.

    A lean ISMS is only effective if it still reflects operational reality and produces usable management information.

    Build Something People Would Actually Use

    One of the recurring problems in ISO implementations is the creation of policies and procedures that bear little resemblance to day-to-day work.

    The engagement focused heavily on practicality:

    • Making ownership clear
    • Designing controls around existing workflows where sensible
    • Ensuring evidence emerged naturally from operations
    • Keeping processes understandable for operational teams
    • Avoiding overengineering simply because a standard exists

    As explored in Beyond the Checklist, documentation alone does not create resilience; systems only work when they reflect how people genuinely operate.

    The Outcome

    UCM Global successfully achieved ISO 27001 certification with a system designed to remain workable long after certification day.

    More importantly, the organisation came away with:

    • A lighter and more maintainable management system
    • Clearer operational structure and ownership
    • Less dependence on performative documentation
    • An implementation aligned to the business rather than imposed onto it
    • Stronger confidence in how future standards could be integrated proportionately

    The engagement also helped challenge a common misconception in the standards world: that “more documentation” automatically means “better governance”.

    In practice, overengineered systems often increase friction, create workaround behaviour, and weaken engagement over time. Good governance improves visibility and resilience; it should not become a parallel administrative burden.

    Client Feedback

    Jennifer at Collevo Consulting was instrumental in helping us achieve our ISO 27001 accreditation. From the outset, her support, expertise, and willingness to really listen to our business needs stood out.

    What made the experience different was that Jennifer didn’t treat ISO accreditation as a simple tick-box exercise. She took the time to truly understand how we operate as a business, the unique challenges we faced, and how the framework could be implemented in a way that was both practical and valuable to us long-term.

    Her knowledge and guidance throughout the process were exceptional, helping us navigate some complex and unique requirements while ensuring the end result genuinely added value to our business and the way we work.

    I would highly recommend Jennifer and Collevo Consulting to any organisation looking for knowledgeable, supportive, and commercially aware ISO consultancy support.

    Final Thought

    There are broadly two ways to approach ISO 27001.

    One approach produces certificates.

    The other produces operational resilience.

    The difference usually comes down to whether the system was designed around audit performance or around how the organisation actually works.

    UCM Global chose the second approach.

    And that tends to make ISO 27001 significantly less painful to operate.

  • ISO 27001 Doesn’t Have to Be Painful

    ISO 27001 Doesn’t Have to Be Painful

    Why This Matters

    Most teams don’t struggle with ISO 27001 because it’s inherently complex (although it certainly feels that way).

    They struggle because it’s turned it into a document factory. And it’s not surprising, that’s how much of the market has evolved, to get the badge quick and templates are the quickest way to achieve that.

    So:

    Policies multiply.
    Spreadsheets sprawl.
    Evidence gets chased in the weeks before the audit.
    And suddenly “being compliant” feels like a second full-time job.

    That’s not a standards problem, it’s not a problem of the people in the company doing their best, it’s an operating model problem.

    The pattern is consistent, templates are bought off the shelf, or consultants are brought in who promise ‘ISO in 90 days’:

    • They start with templates instead of risk
    • They treat Annex A like a checklist
    • They write documents before they have working processes
    • They collect evidence manually, in bursts, under pressure

    The result?

    • Documentation that looks complete but doesn’t reflect reality
    • Controls that exist on paper but get bypassed in practice
    • Audit readiness that depends on heroics
    • A system that quietly decays between audits

    This is where ISO 27001 gets its reputation for being bureaucratic and painful.

    But that pain is largely self-inflicted.

    The standard itself is risk-based, flexible, and designed to fit the organisation. It’s not the other way around.

    The problem is that many implementations optimise for looking compliant, not being operationally sound.

    And those two paths diverge faster than most teams expect.

    What It Actually Is

    ISO 27001 is not a documentation standard.

    It’s a management system for making deliberate decisions about information risk.

    At its core, it’s asking:

    • Do you understand what matters in your organisation?
    • Do you know what could go wrong?
    • Have you chosen proportionate controls?
    • Can you show that those controls actually work?
    • Are you paying attention and improving over time?

    That’s it.

    Documentation exists to support that, not replace it.

    What It Includes (In Practice)

    A working ISMS typically involves:

    • A clear scope tied to real business services
    • A risk assessment that reflects actual exposure
    • A Statement of Applicability based on those risks
    • Controls embedded into real processes (not bolted on)
    • Evidence generated by normal operations
    • A review and improvement rhythm

    What It Does Not Mean

    It does not mean:

    • Writing 40+ generic policies upfront
    • Implementing every Annex A control “just in case”
    • Maintaining parallel compliance workflows disconnected from real work
    • Collecting screenshots as proof of existence

    Those are coping mechanisms, not requirements.

    The Real Distinction

    Shallow implementation:

    • Documents first, reality later
    • Controls selected generically
    • Evidence collected manually
    • Audit = panic cycle

    Mature implementation:

    • Risk first, controls second
    • Documentation reflects how things actually work
    • Evidence is produced as a byproduct of operations
    • Audit = checkpoint, not crisis

    That difference is what determines whether ISO 27001 feels heavy or almost invisible.

    How to Approach It in Practice

    Fixing this isn’t about “doing less ISO”.

    It’s about running it differently.

    A more effective approach usually looks like this:

    Start With Real Scope and Context

    Not “the whole business by default”, and not an artificially tiny slice that breaks credibility.

    Define:

    • What services matter
    • What data matters
    • What dependencies matter

    This is where most clarity (or confusion) begins.

    Run a Risk-Led Design, Not a Control-Led One

    Instead of asking:

    “Which controls do we need?”

    Ask:

    “What could realistically hurt us here?”

    Then:

    • Identify risks
    • Decide what’s acceptable
    • Select controls deliberately

    This is how you avoid both overengineering and blind spots.

    Design Evidence Into Operations

    This is where most teams either win or suffer.

    Rather than:

    • chasing screenshots
    • exporting logs manually
    • building audit folders at the last minute

    You design:

    • tickets, logs, approvals, and system outputs as ongoing evidence streams

    That turns:

    • audit prep → routine review
    • compliance → byproduct of doing the work

    Keep Documentation Tight and Purposeful

    You don’t need more documents.

    You need:

    • the right documents
    • that actually reflect reality
    • and are usable by the people doing the work

    Anything else becomes maintenance overhead.

    Build a Lightweight Operating Rhythm

    Instead of:

    • annual panic
    • audit-driven activity

    You create:

    • small, regular review cycles
    • ownership of controls and risks
    • visible improvement actions

    That’s what keeps the ISMS alive after certification.

    Close

    ISO 27001 doesn’t become painful because it’s demanding, that’s not to say it doesn’t require discipline.

    It becomes painful when it’s disconnected from how the organisation actually runs.

    If you treat it like a documentation project, you’ll get paperwork, friction, and audit stress.

    If you treat it like an operating model, you get:

    • clearer decisions
    • better visibility of risk
    • less audit drama
    • and a system that actually holds up under pressure

    That’s the difference.