Skip to main content

Cybersecurity · IT · OT · Quality · Compliance · AI

Audit, risk, compliance and critical-systems advisory

Assess objectively, identify gaps and demonstrate control. YMUNIT turns independent audits of your risks, systems and obligations into decisions, action plans and evidence that can be used immediately.

  • Independent audit
  • Prioritised findings
  • Defensible evidence

When should you commission an independent audit?

Before certification or inspection, when taking over a function, when control over a critical provider is uncertain, or when you need an objective view of risk: an external, methodical and documented assessment strengthens your decisions.

  • Preparation for certification, assessment or inspection
  • Doubt about the control of a critical supplier or third party
  • A new regulatory requirement to address (NIS2, DORA, HDS or the AI Act)
  • Due diligence before acquisition or integration

Four audit domains

Independent audits of your critical systems

Each domain combines a methodical assessment, prioritised findings and recommendations that can be acted on immediately.

Cybersecurity, IT and OT

Cybersecurity, IT and OT

Assess the security, compliance and resilience of information systems and industrial environments.

  • ISO 27001 · ISO 27005 · EBIOS RM
  • NIS2 · DORA · HDS
  • Industrial cybersecurity · IEC 62443 · OT
  • Organisational and technical audit
View all services
Cybersecurity governanceContinuityResilienceAsset managementAccess managementConfiguration managementOT environmentsSuppliers and third partiesRemediation plans

Engagements preserve appropriate separation between operational responsibilities, audited activities and independent assurance work; YMUNIT does not certify its own arrangements.

Quality and compliance

Quality and compliance

Structure, assess and strengthen quality systems and compliance obligations, excluding the specialist vigilance scope.

  • QMS · SOPs · document control
  • Deviations · CAPA · change control
  • Supplier qualification · quality agreements
  • Internal audit programmes and audits
View all services
Quality governanceProcess mappingQuality manualWork instructionsQuality-risk managementManagement reviewsProvider auditsInspection readinessData integritySystem validation as appropriate to the context

Vigilance services (GVP, medical-device vigilance and cosmetovigilance) and validation of safety databases are covered under Vigilance services.

Risk and supplier governance

Risk and supplier governance

Objectively assess risk, structure controls and secure the third-party dependency chain.

  • Risk mapping · audit universe
  • Internal control · governance · RACI
  • Due diligence · supplier audits
  • Third-party management · executive reporting
View all services
Control plansIndicatorsAction plansMaturity auditsAssessment of critical providersResilience of dependency chains
Artificial intelligence

AI audit and governance

Audit and govern AI systems. Leadership of an AI programme is covered under Leadership & programmes.

  • AI Act · ISO 42001 · AI governance
  • Risk analysis · AI-system audit
  • Security · robustness · resilience
  • Explainability · traceability · human oversight
View all services
Model managementData managementBiasTestingValidationAI suppliersAI in healthcareAI in regulated environments

Deliverables

Evidence that can be used immediately

Our audits produce documents that executives, auditors and regulatory authorities can use directly.

Audit report Prioritised findings and severity Gap assessment Risk mapping Remediation plan CAPA plan Traceability matrix Indicators and dashboards Executive reporting Evidence pack

Frequently asked questions

Audit & advisory

What types of audits do you perform?

YMUNIT performs cybersecurity, IT and OT audits (ISO 27001, ISO 27005, EBIOS RM, NIS2, DORA, HDS, IEC 62443), quality and compliance audits, governance and internal-control audits, supplier and third-party audits, and audits and assessments of artificial-intelligence systems (AI Act, ISO 42001).

How do you safeguard audit independence?

Engagements are organised with appropriate separation between operational responsibilities, audited activities and independent assurance work. YMUNIT never audits or certifies arrangements for which it holds operational responsibility and is not a certification body.

Do you work on quality and compliance?

Yes: QMS, quality governance, SOPs, document control, deviations, CAPA, change control, quality-risk management, supplier qualification, quality agreements, internal audit programmes and audits, inspection readiness and data integrity.

Do you audit suppliers and service providers?

Yes. YMUNIT assesses critical providers and suppliers through due diligence, supplier audits, third-party management, dependency-chain resilience and executive reporting, with prioritised findings and remediation plans.

Can you audit an artificial-intelligence system?

Yes, against the AI Act and ISO 42001: governance, risk analysis, security, robustness, explainability, traceability, human oversight, and model and data management. Leadership of an AI programme is covered under Leadership & programmes.

What deliverables are provided after an audit?

An audit report with prioritised findings and severity, a gap assessment, risk mapping, remediation and CAPA plans, indicators and executive reporting — ready for use in audits, inspections and governance committees.

Let us assess your risks and critical systems

Scope definition, selection of the appropriate framework and an audit proposal tailored to your priorities, following a confidential discussion and a reply within two business days.