Assurance for organisations that answer to regulators.
Farald Consultancy Services Limited helps regulated organisations prove that their information security and management systems actually work — not just that the paperwork exists. We build the evidence that stands up when a regulator, an auditor or a board committee asks for it.
What we do
Four practices, one standard of evidence.
Most organisations do not fail an audit because they lack a policy. They fail because nobody can show the control ran, who checked it, and what happened when it did not. Everything we do is built to close that gap.
Cybersecurity & Data Protection
Awareness programmes, social engineering simulation, NDPA compliance and ISO/IEC 27001 — the human and governance side of security.
- Phishing, smishing and quishing simulation
- NDPA and GAID compliance
- Breach readiness
- ISO/IEC 27001 and 42001
ISO Certification
Gap analysis through to certification audit across the six standards most often demanded in tender and supply-chain qualification.
- ISO/IEC 27001 and 42001
- ISO 9001 and 14001
- ISO 45001 and 22301
- Internal audit programmes
IT Equipment Supply
Specification, procurement and secure deployment of hardware — delivered hardened, asset-registered and ready to pass an audit.
- Needs assessment and specification
- Procurement and deployment
- Secure build and asset register
- Lifecycle and secure disposal
Product Management & Digitalisation
Taking an organisation from manual process to working digital service, and managing the product once it exists.
- Digitalisation roadmap
- Discovery and requirements
- Delivery management
- Change and benefits realisation
Experience
Sectors we have worked in.
Our Director's professional record, set out by sector rather than by client. The names are withheld. The work is not.
Rail & transport
United Kingdom
Safety-critical national infrastructure, where security sits alongside physical safety duties.
Energy & utilities
United Kingdom
Regulated supply operations, resilience and the controls that keep them running.
Telecommunications
United Kingdom
Multi-regulator environments carrying customer data at scale.
Financial services
United Kingdom · UAE
Payment security, PCI DSS and supervised compliance regimes.
Government, standards & trade
Nigeria · West Africa
Thirteen years inside the national standards body — ICT standards development, national quality policy, and trade facilitation work under the WTO TFA across Nigeria and its border countries.
Manufacturing & engineering
UK · Ireland
Third-party certification audit across six ISO management system standards.
Approach
How we work.
Evidence first
Every engagement is designed backwards from the question an auditor or regulator will ask. If a deliverable cannot be produced as evidence, it does not earn its place in the scope.
Built to hand over
Capability transfer is written into the scope from the outset. The aim is that your team can run, refresh and extend the work without us — not that you need us again next year.
Declared interests
We supply IT equipment, and we audit management systems. We never do both for the same organisation. The full policy is set out below.
Phased and reversible
Work is scoped in phases so you can authorise a contained first stage, see measured results, and decide on the rest on evidence rather than on a proposal document.
Two jurisdictions, properly
A Nigerian registered entity and a UK practice base. International good practice translated into the local operating reality, rather than imported wholesale.
Plain conclusions
Findings are reported as they are. A report that softens a material gap to keep a client comfortable is worth nothing to the board that relies on it.
Independence
Our conflict of interest policy.
We both supply IT equipment and audit management systems. Those two activities can pull against each other, so we publish the rule rather than leave you to ask.
- We do not supply equipment to organisations we audit or certify. Where a client engages us for assurance work, equipment supply is off the table for the duration of that engagement and for twelve months afterwards. Where a client engages us for supply, we will decline subsequent audit or certification work for the same period and refer it elsewhere.
- We hold no vendor commissions, rebates or referral fees. Equipment is supplied at cost plus a disclosed margin. If a cheaper specification meets your requirement, we will say so, and our fee does not change.
- Third-party certification audit is ring-fenced entirely. Audit delivered through an accredited certification body is governed by that body's own impartiality rules under ISO/IEC 17021. We do not sell anything to an organisation we audit in that capacity, ever.
- Interests are declared in writing before evaluation. Any personal, family or commercial relationship between our people and anyone involved in awarding work is disclosed in writing at the point of submission, not after an award.
Principal
Aderonke Agboola
Director
Ronke has written information security standards, implemented them in-house, and audited other organisations against them. That combination is what shapes how Farald scopes work.
She holds a senior in-house information security role in UK national infrastructure alongside independent audit and consultancy delivery, across Nigeria, the United Arab Emirates, the United Kingdom and Ireland.
Before that, thirteen years inside Nigeria’s national standards body — ICT standards development, the National Quality Policy, and trade facilitation as the organisation’s WTO desk officer and a member of Nigeria’s National Trade Facilitation Committee, alongside the Single Window programme and briefings delivered across Nigeria and its border countries.
Aderonke Agboola
Director
MSc · CISM · ISO Lead Auditor
aderonke.agboola@faraldconsultancy.com
UK +44 7424 450823 · NG +234 806 069 3098
Credentials
Contact
Start with a conversation.
Tell us what you are trying to demonstrate and to whom — a regulator, a certification body, a client's supply-chain questionnaire, or your own board. An introductory conversation costs nothing and carries no commitment.