The ongoing operation that keeps the client's information-security and data-protection program in an auditable state: ISO 27001 and LGPD alive, not certificates hung on the wall. XALQ doesn't sell a compliance platform and doesn't leave the knowledge in the head of a consultant who one day walks away. It takes on the cadence that keeps the client ready for the auditor, for the ANPD and for the board.
It is the ongoing operation that keeps the client's information security and data protection program in an auditable state: ISO 27001 and LGPD alive, with a traceable evidence trail, risk and control management, ROPA in ANPD format and a whistleblower channel in operation. Compliance stops being an event and becomes a state.
Decision Work Assurance is built in the same product format as the other lines: ongoing work, a senior Business Specialist, layered applied intelligence, and an operating posture over the client's governance environment, not over its technical infrastructure.
XALQ takes on the information-security and data-protection program as an operation that runs on cadence: maturity diagnosis, risk and control management, Statement of Applicability, ROPA in ANPD format, whistleblowing channel and a traceable evidence trail. It's not a consultancy that delivers the report and hands execution back.
The entry wedge is the Maturity Diagnosis: separable, low entry ticket, creditable if the client continues. It shows where the program stands today against ISO 27001 and LGPD and what's missing to reach the auditable state.
From it is born, if the client continues, the ongoing operation: Implementation builds the program on the client's reality and Sustainment keeps it alive on cadence, as the risk shifts, the standard evolves and the ANPD tightens. Continuing is an option, not an obligation.
So the client stops treating compliance as an event: the scramble before the certificate, the effort that evaporates the next day, the snapshot that ages in twelve months while the real risk keeps moving.
The operation delivers the compliance state ready for whoever asks (auditor, ANPD, board, counterparty in a client's or investor's due diligence), with the traceable evidence behind it and the read of what to decide next. Compliance as a permanent state, not a snapshot that ages in twelve months.
"Ready for the auditor" cannot be just a promise. That's why we are starting to record, every cycle, whether the program actually arrived ready when it was called upon (audit, ANPD, due diligence) or whether it needed a last-minute scramble.
Whoever answers for information security day to day: CISO, Security Officer, IT lead who carries the ISMS on their back. For that person, Decision Work Assurance isn't a project that delivers the Statement of Applicability and disappears: it's the operation that keeps the program alive after the consultant has gone.
Risk is mapped, controls are managed on cadence and evidence stays traceable at all times. When the audit arrives, there's no scramble: the state is already ready. For whoever lives the program from the inside, it's the difference between rebuilding everything each cycle and keeping a state that doesn't age.
Whoever is legally accountable for the processing of personal data and for LGPD compliance.
For the DPO, the Data Officer and Legal, the value isn't an opinion that goes stale, but an adequacy operation that stays running: ROPA maintained in ANPD format, legal basis revised when the processing changes, whistleblowing channel in operation, incidents handled with a trail, rather than rebuilt under inspection pressure.
It speaks the language that defends the company's position before the ANPD and the counterparty: evidence, traceability, documented rationale. Lowering the legal and reputational exposure of data is what the operation sustains while it runs, not a delivery that runs out at the certificate.
The board, the council and the partners who answer for risk before investors, clients and the regulator.
While the operation runs, compliance stops being a black box no one on the board can read and becomes a defensible, up-to-date state, ready for the investor's due diligence, for the large client's security questionnaire, for the hard question in the board meeting. It's what makes compliance hold up a business decision, not just pass an audit.
Separable, low entry ticket, creditable if the client continues. It shows where the program stands today against ISO 27001 and LGPD and what's missing for the auditable state. From it is born, if the client continues, the ongoing operation: Implementation builds the program on the client's reality and Sustainment keeps it alive on cadence. It's not a ladder of levels to climb; it's a program that runs and matures. Continuing is an option, not an obligation.
The diagnosis is done to hold up the risk decision within your organization: it speaks the language of the auditor, the ANPD and the board, with evidence and a defensible rationale, so that whoever answers for the risk has a clear basis to decide. And it doesn't lock you into anything: it opens the possible evolution without forcing any next step.
Before deciding, it's worth separating what is actually being compared. A GRC platform, traditional compliance consulting and Decision Work Assurance solve the same pain in structurally different ways.
You are not buying a one-off maturity report or a platform to feed on your own. You are buying the compliance state kept alive, cycle after cycle, and every cycle it's recorded whether the program arrived ready when it was called upon.
You are buying a report and a snapshot of the current state. The day after delivery, the knowledge leaves with the consultant, and the program starts aging with no one tending to it.
You are buying access to a risk and controls management system. Feeding it, keeping it updated and interpreting it remain entirely your own work.
A conversation of roughly forty minutes, in which XALQ's senior Business Specialist understands how your security and data-protection program is structured today and returns a preliminary read on where Decision Work Assurance fits, and where it doesn't.
No. Certification is issued by an accredited body. XALQ keeps the program in an auditable state so the client reaches the audit without a rush. There is also no legal opinion, since legal responsibility remains with the client, and no promise of automatic approval.
A living ISMS program aligned to ISO 27001, LGPD compliance run on cadence, Statement of Applicability and ROPA in ANPD format maintained, continuous risk and control management, whistleblower channel and incident handling.
The CISO or security lead, the DPO and Legal, and the board. The entry point is the Maturity Diagnosis, separable, low-ticket and creditable, which shows where the program stands against ISO 27001 and LGPD and what is missing to reach an auditable state.
No. XALQ does not sell a compliance platform for the client to operate alone nor implement technical controls on the client's infrastructure. The operation runs on the client's governance environment.
We are starting to record that at every Sustainment cycle: whether the program arrived at the audit, the ANPD, or due diligence without a last-minute scramble, and what needed to be rushed when it didn't. The track record becomes visible to you, not just the promise that it will arrive ready.