Management Systems and Assurance
Hypergility Innovations Ltd holds ISO/IEC 27001, ISO 9001, ISO/IEC 42001, Cyber Essentials and Cyber Essentials Plus. We run the same disciplines for clients. Our fees are published, not quoted.
HG-FEE-3.0 · In force from 1 April 2026 · All fees exclusive of VAT
What we do
Build.
Gap analysis, documented information, risk methodology, Statement of Applicability. Taking an organisation from nothing to audit-ready.
Audit.
Full-cycle internal audit programmes against clauses 4–10 and applicable Annex A controls. Audit plan, fieldwork, written reports, findings log.
Close.
Root cause analysis and corrective action for nonconformities raised by any party — certification body, internal audit, or the client.
Run.
Retained monthly service where we hold the management representative role and report to the board.
Fee schedule
How to read the bars
Day rates
Minimum half day charged at 60%.
Principal Consultant
Lead Auditor / Lead Implementer. Certification body liaison, board reporting, major nonconformity root cause.
£1,150
per day
per day
Senior Consultant
Management system design, risk assessment, audit programme delivery.
£950
per day
per day
Consultant / Internal Auditor
Scheduled internal audit, control testing, corrective action tracking.
£750
per day
per day
Compliance Analyst
Documented information, evidence collation, register maintenance.
£550
per day
per day
ISO/IEC 27001:2022 — Information security management
Gap analysis and readiness assessment
Clauses 4–10 and all Annex A controls tested against current state. Written findings report with prioritised remediation plan.
£4,500
per engagement
per engagement
ISMS build — full documented information set
Scope statement, policy suite, SoA, risk methodology, and all mandatory records for a first certification.
£7,500
per engagement
per engagement
Policy suite review and refresh
Existing ISMS. Version control, clause traceability, and reissue of superseded documents.
£4,250
per engagement
per engagement
Internal audit programme — annual
Full-cycle programme covering clauses 4–10 and all applicable Annex A controls. Audit plan, fieldwork, reports, and findings log.
£5,750
per engagement
per engagement
Risk assessment and treatment plan
Build or rebuild. Asset and threat register, scoring methodology, treatment decisions, residual risk acceptance.
£3,250
per engagement
per engagement
Certification audit support
Stage 1 and Stage 2 attendance, certification body liaison, evidence marshalling.
£2,950
per engagement
per engagement
Management review facilitation
Per cycle. Agenda, input pack, facilitation, and minuted outputs meeting clause 9.3.
£990
per cycle
per cycle
ISO 9001:2015 — Quality management
QMS gap analysis
Process mapping against clauses 4–10 with written findings and remediation plan.
£2,950
per engagement
per engagement
QMS build — documented information set
Quality policy, objectives, process definitions, and mandatory records for a first certification.
£5,500
per engagement
per engagement
Documented information review and update
Existing QMS. Currency check, version control, and reissue.
£2,750
per engagement
per engagement
Internal audit programme — annual
Full-cycle programme across all QMS processes. Audit plan, fieldwork, reports, and findings log.
£3,950
per engagement
per engagement
Management review facilitation
Per cycle. Agenda, input pack, facilitation, and minuted outputs meeting clause 9.3.
£990
per cycle
per cycle
Integrated management system — ISO/IEC 27001 and ISO 9001 operated as one system
Integrated policy suite refresh
Single harmonised document set serving both standards. Removes duplication and conflicting clause references.
£6,250
per engagement
per engagement
Integrated internal audit programme — annual
One audit calendar covering both standards. Shared fieldwork where clauses align, separate reporting.
£8,750
per engagement
per engagement
Annex SL alignment and harmonisation
Clause-by-clause mapping across standards, common process architecture, shared evidence model.
£4,500
per engagement
per engagement
Nonconformity remediation — priced per finding, whoever raised it
Major nonconformity — closure
Per finding. Root cause analysis, corrective action design, implementation support, and closure evidence pack.
£2,250
per finding
per finding
Minor nonconformity — closure
Per finding. Corrective action, implementation, and closure evidence.
£850
per finding
per finding
Observation or opportunity for improvement
Per item. Disposition, rationale, and record.
£395
per item
per item
ISO/IEC 42001:2023 — AI management system
AIMS gap analysis
Clauses 4–10 and Annex A controls. AI system inventory and impact assessment baseline.
£4,950
per engagement
per engagement
AIMS build — documented information set
Policy suite, AI system register, impact assessment methodology, and mandatory records.
£9,500
per engagement
per engagement
Internal audit programme — annual
Full-cycle programme covering clauses 4–10 and applicable Annex A controls.
£5,950
per engagement
per engagement
Cyber Essentials — NCSC scheme, IASME-administered
Cyber Essentials readiness and submission
Pre-assessment gap check, evidence preparation, self-assessment questionnaire support.
£1,450
per engagement
per engagement
Cyber Essentials Plus readiness and audit support
Technical remediation planning, device sampling preparation, assessor liaison.
£2,950
per engagement
per engagement
Retained services
Rolling monthly, 30 days' notice either side.
Maintain — one and a half days per month
Register upkeep, evidence collection, surveillance audit readiness.
£1,650
per month
per month
Operate — three days per month
Everything in Maintain, plus scheduled internal audit delivery and corrective action management.
£2,950
per month
per month
Lead — four and a half days per month
Everything in Operate, plus named management representative, board reporting, and supplier assurance response.
£4,250
per month
per month
Market ranges reflect published UK consultancy pricing for equivalent work, reviewed August 2026. Full source list available on request.
Basis of pricing
One rate card, every client. These rates apply to all clients without exception, including group companies, related parties, and entities under common control or common directorship. We do not discount for connection and we do not uplift for it. Any engagement with a related party is contracted, scoped, delivered, evidenced, and invoiced on exactly these published terms.
VAT. All fees are exclusive of VAT. VAT is charged at the prevailing standard rate.
What a fixed fee includes. Scoping, delivery, the named deliverable, and one round of revision. Certification body fees, assessment fees, tooling, and licences are separate and paid by the client directly to the provider.
Nonconformity pricing. Charged per finding at the published rate regardless of who raised it — certification body, internal audit, or client. Findings are agreed and logged in writing before work starts.
Expenses. Work is delivered remotely by default. On-site attendance is charged at cost for travel and accommodation, agreed in advance. No mark-up is applied.
Out of hours. Work outside 08:00–18:00 on UK business days, where requested by the client, carries a 25 per cent uplift on the day rate.
Payment. Fixed-fee engagements are invoiced 50 per cent on signature and 50 per cent on delivery. Day rates and retainers are invoiced monthly in arrears. Terms are 30 days.
Evidence of delivery. Every engagement produces a dated deliverable and a delivery record. Both are retained and available to the client, their auditors, and their certification body on request.
Revision. This schedule is reviewed annually against published UK market data. Each version carries in-force dates. Superseded versions are retained and available at /services/management-systems/archive.







