Audit Readiness Group
Mid-market manufacturing & industrial

There are two audits: the one you schedule and the one you don’t. We get you ready for both.

One firm, two practices, one kind of client. Audit Readiness Group prepares your quality system for the audits your customers and your registrar run. Adversarial Risk Group tests your security the way an adversary would: on-site first, then continuously.

Quality
ISO 9001 readiness
Security
Adversarial testing
Sector
Manufacturing
Delivery
Founder direct
The problem with point-in-time

A certification audit and an adversary test the same thing: whether your system holds when someone from outside works through it.

How most plants get audited

Two weeks of scrambling.

Someone arrives, checks, writes a report, and leaves. The report starts aging the moment the door closes. People are hired, vendors change, processes drift. The next audit, or the next attacker, meets a different company than the one in the report.

How we get you ready

Audited before the auditor arrives.

We run your system the way the outsider will: clause by clause, evidence first, from the floor up. Findings come with a remediation plan you can actually work, and the gaps close before they cost you a certificate, a customer, or a wire transfer.

Quality
Audit Readiness Group · ISO 9001 audit preparation

Your registrar audits you once a year. Your customers audit you whenever they decide to.

We get you ready before they arrive. Three engagement types, sold separately or in sequence. Every one is a defined project with a defined deliverable.

01 Gap assessment

Audited the way a registrar audits.

An on-site review of your quality management system against ISO 9001, run the way a registrar runs it: clause by clause, evidence first. We interview the people who do the work and read the records they actually keep, not the ones in the binder.

on-site clause by clause evidence first
DeliverableFindings and a prioritized remediation plan. Flat project fee.
02 Remediation support

Close what the assessment found.

Fixed-scope projects against named gaps: documentation that matches the floor, process design, an internal audit program that runs without you chasing it, corrective action discipline that survives the next surveillance visit.

documentation process design internal audit corrective action
DeliverableNamed gaps closed, with the evidence a registrar will ask for.
03 Certification-audit support

A mock audit before the real one.

Preparation ahead of your Stage 1, Stage 2, surveillance, recertification, or customer audit. We run it under the conditions the auditor will, so your team has already answered the hard questions once.

stage 1 / 2 surveillance customer audit
DeliverableMock-audit findings, closed before the registrar sees them.
The work is led by a certified ISO 9001 lead auditor who runs internal audits and hosts registrar and customer audits inside a working manufacturer. We prepare you for certification. We never issue it. Your registrar’s independence is the point.
Security
Adversarial Risk Group · physical audits, continuous simulation

We travel to your facility. We find what gets through. Then we keep finding it, automatically, until we come back.

Breaches don’t happen to organizations. They happen to people. The same employee who clicks a malicious link is the one who holds the door for an unknown visitor. We test both, as one program.

01 · On-site audit

We walk the floor.

We observe operations, test physical access controls, and run initial adversarial simulation across every relevant vector: physical access, social engineering, phishing, vishing. You get a documented baseline: what’s exposed, why it matters, what fixing it requires.

02 · Continuous simulation

The testing keeps running.

After the audit, an AI-driven layer runs between engagements. Automated OSINT. Adaptive spear phishing. Vishing using current attack techniques. Tests iterate on what actually gets through, to which people, in which departments. The system never runs the same test twice.

03 · Annual review cycle

The cycle compounds.

Digital review years and on-site audit years alternate. Findings from the automated layer inform where we look next. The relationship is a managed service, not a project followed by silence.

The security practice has its own site Engagement model, techniques, cost model, and the founding client program for security.
Why one firm

The person who answers for the registrar audit is the person who should answer for the adversarial one.

01 / 04

Same facility. Same processes. Same people.

The owner who sweats the registrar audit is the owner who buys the security audit. One relationship, two things that have to hold when an outsider works through them.

02 / 04

One discipline.

ISO 9001 and ISO 27001 are built on the same management-system skeleton: context, leadership, planning, support, operation, performance evaluation, improvement. Audit preparation transfers across them. Quality audit readiness today, security management audit readiness next.

03 / 04

Nobody has to be convinced the problem exists.

Every certified manufacturer already has customer and registrar audits on the calendar. The only question is whether you show up prepared or scramble for two weeks. The adversary keeps a calendar too. You just don’t get to see it.

04 / 04

Each practice finds what the other fixes.

A quality review surfaces the process gaps an attacker walks through. A security engagement surfaces the controls a QMS should have formalized. Either door leads to the same building.

Who we work with

Mid-market manufacturing and industrial.

Companies with physical facilities, distributed workforces, real audit calendars, and environments where the human layer is the least protected surface. Fabricated metal, electrical and electronic equipment, machinery, aerospace and defense suppliers, and the shops that feed them.

If your audit prep consists of the two weeks before the registrar arrives, you already know how that feels. If your security program consists of annual training and a perimeter firewall, you are defended against attacks from several years ago.

Who we are

We sell to the environment we come from.

Three founders. All three came up on the floor of a working manufacturer: quality, compliance, IT, and the customer audits that decide whether the work keeps coming.

Co-founder · Quality practice
NB

Noah Brown

Certified ISO 9001 lead auditor

Runs the internal audit program and hosts the customer and third-party audits at a working manufacturer of utility-scale electrical equipment. Leads every Audit Readiness Group engagement.

Co-founder · Security practice
DA

David Ashby

Quality · compliance · automation

Quality, safety, and compliance background at the same manufacturer: physical audits, ISO 9001 mapped checklists, corrective action. Top 3 creator on n8n.io. Builds the continuous simulation layer directly.

Co-founder
JW

James Wall

Quality eng · IT · social eng

Quality Engineer. Background in IT infrastructure, hands-on networking implementation, and social engineering. Ex-Amazon, with supply chain experience. Operates across systems-of-systems.

Founding client program

Three spots per practice. Locked-in pricing. Direct line.

Each practice is onboarding three founding clients: one relationship, one warm referral, one direct. The quality trio is open now. The security trio is tracked on adversarialrisk.com.

Quality · Spot 01 Open Relationship · known quantity
Quality · Spot 02 Open Referral · warm intro preferred
Quality · Spot 03 Open Direct · move first

Founding clients receive

  • Rates locked for three years, below where standard pricing will land
  • Direct access to the founders throughout, not delegated
  • Input into how the service develops
  • Recognition as a founding client organization, at your discretion

We ask in return

  • Honest feedback throughout the engagement
  • Reference-ability once results are established
  • Case study rights, scope agreed in advance
Get in touch

Tell us which audit is on your calendar.

A founder reads every submission.