How an engagement runs

Six steps, in order. You should know what happens next at every point, and what it costs before it starts.

The sequence

This genuinely is a sequence — each step depends on the one before it. The most common failure in compliance projects is starting remediation before scope is settled, which produces work that gets thrown away.

1

Scoping call

Thirty minutes. Your framework, your deadline, what triggered this, and what has already been tried. No charge, and no obligation. If the work is not a fit you get a straight answer and, where possible, a referral.

2

Written proposal

Within a few business days: defined scope, named deliverables, timeline and fee. Fixed scope wherever the work can be defined in advance. Anything genuinely open-ended is called out as such rather than buried in an hourly estimate.

3

Assessment

The current-state pass. Documentation review, control walkthroughs, system and evidence sampling, and interviews with the people who actually operate the controls rather than the people who own them on paper.

4

Findings and remediation plan

Every gap written down with a severity, an owner, a target date and an assessor-impact rating. Sequenced so the items that block the audit are done first and the items that merely improve the program wait their turn.

5

Execution support

Remediation is where most engagements quietly stall. This step is drafting the policy, designing the control, building the evidence process and reviewing the work as it lands — not handing over a spreadsheet and leaving.

6

Audit or handoff

Running the evidence process through fieldwork, managing the assessor's request list and responding to findings. Or, where you are taking it in-house, a documented handoff your team can operate without further help.

How the work is actually delivered

You work with one person. The person on the scoping call is the person doing the assessment. Nothing is handed to a junior consultant after the contract signs.

Findings are written to be argued with. Every gap includes the reasoning and the requirement it maps to, so your team can push back where the finding is wrong. A finding you cannot challenge is a finding you cannot trust.

Working documents stay in your systems. Deliverables are produced in whatever format your team already uses, and remain yours.

Independence is preserved. Highpoint RMC does not issue SOC reports, PCI Attestations of Compliance or ISO 27001 certificates. Advisory and attestation stay in separate hands, which is what your external auditor will expect.

Step one costs nothing

Bring the deadline and the trigger. Thirty minutes is usually enough to tell you whether this is a four-week problem or a six-month one.

Start an inquiry