Delivery 04 · Decision Work Assurance

Compliance
as a permanent state.

The ongoing operation that keeps the client's information-security and data-protection program in an auditable state: ISO 27001 and LGPD alive, not certificates hung on the wall. XALQ doesn't sell a compliance platform and doesn't leave the knowledge in the head of a consultant who one day walks away. It takes on the cadence that keeps the client ready for the auditor, for the ANPD and for the board.

Schedule a conversation → ← Back to the site
Short answer

What is Decision Work Assurance?

It is the ongoing operation that keeps the client's information security and data protection program in an auditable state: ISO 27001 and LGPD alive, with a traceable evidence trail, risk and control management, ROPA in ANPD format and a whistleblower channel in operation. Compliance stops being an event and becomes a state.

What it is

The Decision Work line's offering for the domain of information security and data protection.

Decision Work Assurance is built in the same product format as the other lines: ongoing work, a senior Business Specialist, layered applied intelligence, and an operating posture over the client's governance environment, not over its technical infrastructure.

XALQ takes on the information-security and data-protection program as an operation that runs on cadence: maturity diagnosis, risk and control management, Statement of Applicability, ROPA in ANPD format, whistleblowing channel and a traceable evidence trail. It's not a consultancy that delivers the report and hands execution back.

The entry wedge is the Maturity Diagnosis: separable, low entry ticket, creditable if the client continues. It shows where the program stands today against ISO 27001 and LGPD and what's missing to reach the auditable state.

From it is born, if the client continues, the ongoing operation: Implementation builds the program on the client's reality and Sustainment keeps it alive on cadence, as the risk shifts, the standard evolves and the ANPD tightens. Continuing is an option, not an obligation.

What it proposes

To keep the compliance state alive and defensible at all times, not in the month of the audit.

So the client stops treating compliance as an event: the scramble before the certificate, the effort that evaporates the next day, the snapshot that ages in twelve months while the real risk keeps moving.

The operation delivers the compliance state ready for whoever asks (auditor, ANPD, board, counterparty in a client's or investor's due diligence), with the traceable evidence behind it and the read of what to decide next. Compliance as a permanent state, not a snapshot that ages in twelve months.

"Ready for the auditor" cannot be just a promise. That's why we are starting to record, every cycle, whether the program actually arrived ready when it was called upon (audit, ANPD, due diligence) or whether it needed a last-minute scramble.

What it delivers
  • A living ISMS aligned with ISO 27001
  • LGPD adequacy operated on cadence, not as a project
  • Statement of Applicability and ROPA in ANPD format, maintained
  • Ongoing management of risks, controls and traceable evidence
  • Whistleblowing channel and incident handling in operation
  • A compliance state ready for auditor, ANPD and board
What it doesn't deliver
  • An ISO certificate issued by XALQ (certification comes from an accredited body)
  • A GRC platform for the client to operate alone
  • Technical implementation of controls in the client's infrastructure
  • A legal opinion (legal responsibility remains the client's)
  • A promise of automatic approval in an audit or inspection
The central value is keeping the compliance state defensible and the risk decision substantiated, not issuing the certificate nor guaranteeing approval. Those depend on an accredited body and on the client itself.
Who it's for

Keeping compliance alive involves different profiles in your organization, and Decision Work Assurance serves each one, from the Diagnosis to the operation running.

Operational owner of the program
CISO · Security Officer · security lead

Whoever answers for information security day to day: CISO, Security Officer, IT lead who carries the ISMS on their back. For that person, Decision Work Assurance isn't a project that delivers the Statement of Applicability and disappears: it's the operation that keeps the program alive after the consultant has gone.

Risk is mapped, controls are managed on cadence and evidence stays traceable at all times. When the audit arrives, there's no scramble: the state is already ready. For whoever lives the program from the inside, it's the difference between rebuilding everything each cycle and keeping a state that doesn't age.

Accountable for personal data
DPO · Data Officer · Legal

Whoever is legally accountable for the processing of personal data and for LGPD compliance.

For the DPO, the Data Officer and Legal, the value isn't an opinion that goes stale, but an adequacy operation that stays running: ROPA maintained in ANPD format, legal basis revised when the processing changes, whistleblowing channel in operation, incidents handled with a trail, rather than rebuilt under inspection pressure.

It speaks the language that defends the company's position before the ANPD and the counterparty: evidence, traceability, documented rationale. Lowering the legal and reputational exposure of data is what the operation sustains while it runs, not a delivery that runs out at the certificate.

Answers for risk to the board
Board · directors · partners

The board, the council and the partners who answer for risk before investors, clients and the regulator.

While the operation runs, compliance stops being a black box no one on the board can read and becomes a defensible, up-to-date state, ready for the investor's due diligence, for the large client's security questionnaire, for the hard question in the board meeting. It's what makes compliance hold up a business decision, not just pass an audit.

The commercial wedge
Maturity Diagnosis

Separable, low entry ticket, creditable if the client continues. It shows where the program stands today against ISO 27001 and LGPD and what's missing for the auditable state. From it is born, if the client continues, the ongoing operation: Implementation builds the program on the client's reality and Sustainment keeps it alive on cadence. It's not a ladder of levels to climb; it's a program that runs and matures. Continuing is an option, not an obligation.

The diagnosis is done to hold up the risk decision within your organization: it speaks the language of the auditor, the ANPD and the board, with evidence and a defensible rationale, so that whoever answers for the risk has a clear basis to decide. And it doesn't lock you into anything: it opens the possible evolution without forcing any next step.

How to compare

Three ways to keep compliance, and who carries the risk in each.

Before deciding, it's worth separating what is actually being compared. A GRC platform, traditional compliance consulting and Decision Work Assurance solve the same pain in structurally different ways.

Ongoing operation
Decision Work Assurance

You are not buying a one-off maturity report or a platform to feed on your own. You are buying the compliance state kept alive, cycle after cycle, and every cycle it's recorded whether the program arrived ready when it was called upon.

When it fails: it shows up in the next cycle, on the record
Project
Traditional compliance consulting

You are buying a report and a snapshot of the current state. The day after delivery, the knowledge leaves with the consultant, and the program starts aging with no one tending to it.

When it fails: the consultant is already gone
Tool
GRC platform

You are buying access to a risk and controls management system. Feeding it, keeping it updated and interpreting it remain entirely your own work.

When it fails: no one signs off on it
Next step

If compliance in your company is still an event, and not a state, it's worth a conversation.

A conversation of roughly forty minutes, in which XALQ's senior Business Specialist understands how your security and data-protection program is structured today and returns a preliminary read on where Decision Work Assurance fits, and where it doesn't.

Schedule a conversation → ← Back to the main site
FAQ

Frequently asked questions

Does XALQ issue the ISO 27001 certificate?

No. Certification is issued by an accredited body. XALQ keeps the program in an auditable state so the client reaches the audit without a rush. There is also no legal opinion, since legal responsibility remains with the client, and no promise of automatic approval.

What does the operation deliver in practice?

A living ISMS program aligned to ISO 27001, LGPD compliance run on cadence, Statement of Applicability and ROPA in ANPD format maintained, continuous risk and control management, whistleblower channel and incident handling.

Who benefits and how does it start?

The CISO or security lead, the DPO and Legal, and the board. The entry point is the Maturity Diagnosis, separable, low-ticket and creditable, which shows where the program stands against ISO 27001 and LGPD and what is missing to reach an auditable state.

Does XALQ sell a GRC platform?

No. XALQ does not sell a compliance platform for the client to operate alone nor implement technical controls on the client's infrastructure. The operation runs on the client's governance environment.

Do you show whether the program actually arrived ready for the audit?

We are starting to record that at every Sustainment cycle: whether the program arrived at the audit, the ANPD, or due diligence without a last-minute scramble, and what needed to be rushed when it didn't. The track record becomes visible to you, not just the promise that it will arrive ready.