Compliance software backed by real-world GRC leadership

Consultancy & Advisory Services

Practical governance, risk, compliance and service management support from a practitioner who has implemented, operated and audited management systems in real-world organisations.

iso-standard.app combines intelligent compliance software with hands-on consultancy and advisory support. Whether you are preparing for certification, improving an existing management system, building a risk framework or embedding governance into day-to-day operations, we provide practical support designed around your organisation's maturity, risk profile and commercial objectives.

Core services

Standards, risk and governance — implemented properly.

Every engagement is delivered by a practitioner with real implementation, audit and leadership experience — not a template pack.

ISO 27001 Implementation Support

Design, implement and improve practical Information Security Management Systems aligned to ISO 27001.

  • ISO 27001 gap assessments
  • ISMS design and implementation
  • Information security risk assessment
  • Statement of Applicability development
  • Policy and procedure development
  • Control implementation
  • Internal audit support
  • Certification readiness
  • Continual improvement planning

Practical implementation — not documentation for documentation's sake.

ISO 20000-1 Implementation Support

Build service management systems that improve consistency, control, customer confidence and operational performance.

  • IT service management framework design
  • ITIL-aligned process development
  • Incident management
  • Change enablement
  • Problem management
  • Service catalogue design
  • Supplier management
  • Service reporting
  • Management review
  • Certification readiness

ISO 9001 Quality Management Support

Create quality management systems that improve process ownership, accountability, customer satisfaction and continual improvement.

  • Process mapping
  • Quality policy and objectives
  • Process ownership
  • Internal audit programmes
  • Non-conformance management
  • Corrective action tracking
  • Continual improvement
  • Management review
  • Certification readiness

ISO 42001 AI Management System Support

Support organisations developing responsible, governed and risk-aware approaches to artificial intelligence.

  • AI governance framework design
  • AI risk assessment
  • AI policy development
  • Human oversight controls
  • Responsible AI principles
  • AI system lifecycle governance
  • AI compliance monitoring
  • ISO 42001 readiness support

Informed by the founder's doctoral research into the AI-Assisted Human.

Risk Management Services

Practical risk management support that helps organisations identify, assess, treat and monitor risks in a way that supports better decisions.

  • Enterprise risk management
  • Information security risk management
  • Technology risk
  • Operational risk
  • Supplier and third-party risk
  • Risk register development
  • Risk appetite and scoring models
  • Risk treatment planning
  • Board and leadership reporting
  • Ongoing risk review support

Compliance & Governance Advisory

Support for organisations that need to strengthen governance, assurance and control across technology, service delivery and business operations.

  • Governance framework design
  • Compliance obligations mapping
  • Audit preparation
  • Internal audit programmes
  • Policy framework development
  • Management review facilitation
  • Continual improvement programmes
  • Regulatory and contractual assurance support
Fractional leadership

Senior GRC leadership — without the full-time cost.

Senior governance, risk, compliance and service management expertise without the cost of a full-time executive hire. Ideal for organisations that need experienced leadership to mature governance, risk, information security, quality or service management practices, but do not yet require or cannot justify a full-time senior appointment.

Fractional Head of Governance
Virtual Information Security Manager
Virtual Compliance Manager
Fractional Risk Manager
Governance Advisor
Service Management Advisor
Founder expertise

Michael McCarroll MA, BSc (Hons)

Governance, Risk, Compliance and Service Management Leader

Michael McCarroll is a governance, risk, compliance and service management professional with more than two decades of experience helping organisations improve operational performance, information security, service management and organisational governance.

His experience spans local government, managed service providers, insurance services, enterprise IT organisations and regulated sectors. Throughout his career he has designed, implemented and matured management systems, governance frameworks, risk management processes and operational capabilities that deliver measurable business outcomes.

Michael has led ISO 27001, ISO 20000-1 and ISO 9001 initiatives, managed PCI-DSS compliance programmes, established information security governance frameworks and successfully prepared organisations for external certification and assurance audits.

His approach combines practical implementation experience, academic study and doctoral research into human–AI collaboration, enabling organisations to adopt governance and compliance practices that are effective, sustainable and future-facing.

Experience highlights

Real-world implementation — across sectors and standards.

Head of Governance

Managed Service Provider

Michael has held responsibility for integrated governance across quality, information security, IT service management, environmental management implementation and HSCN compliance. His work has focused on embedding governance into daily operations, improving processes, strengthening audit readiness and using governance as a driver for cultural and operational change.

  • ISO 9001 quality standards accountability
  • ISO 27001 information security accountability
  • ISO 20000-1 IT service management accountability
  • ISO 14001 implementation activity
  • HSCN compliance
  • Governance transformation and continual improvement
  • External BSI audit with zero non-conformances
  • Governance as an enabler of cultural change

Head of Support

Managed Service Provider

Michael led the transformation of support services within a rapidly growing managed service provider. He designed and implemented an ITIL 4 aligned operating model focused on sustainability, consistency and measurable service improvement.

  • End-to-end support service leadership
  • ITIL 4 operating model design
  • Incident, change, problem and patch management
  • Major and security incident management
  • Service performance improvement
  • Customer satisfaction improvement
  • Operational maturity uplift

IT Service Delivery Manager

Insurance and Finance

Michael introduced an ISO 27001-aligned Information Security Management System, managed a successful PCI-DSS certification programme and founded the IT Security Board responsible for information security governance across people, process, policy and technology.

  • ISO 27001-aligned ISMS implementation
  • PCI-DSS certification leadership
  • SIEM procurement and implementation
  • Founded Information Security Board
  • Client information security audits
  • Tender assurance responses
  • ITSM tooling implementation
  • Supplier and service level management

ICT Service Support Manager

Metropolitan Local Authority

Michael supported successful ISO 27001 certification and introduced improvements across asset management, procurement, event management, patch management, knowledge management and operational performance.

  • ISO 27001 certification achieved
  • Asset management improvement
  • Procurement rationalisation
  • Windows migration project
  • Event and patch management
  • Knowledge management
  • Problem board leadership

Director

SR1 IT Solutions — Managed Service Provider

As Director of SR1 IT Solutions, Michael managed customer relationships, developed new business and supported technical delivery within a managed service provider environment. He developed processes and technical services designed to protect the confidentiality, integrity and availability of client data.

  • Customer relationship management
  • New client acquisition
  • Technical delivery leadership
  • VoIP platform design
  • Information security for client data
  • Support for special category data handling

HP Enterprise Services & EDS

Enterprise IT

Michael's earlier career with HP Enterprise Services and EDS provided a strong foundation in enterprise IT operations, team leadership, service support and ITIL problem management.

  • ITIL Problem Manager
  • Team leadership
  • Enterprise service operations
  • Large-scale IT support

Governance, Service & Information Security Management and Risk Experience

Housing Association Sector

Michael also brings experience from the Housing Association sector, further strengthening his background across governance, service management, risk, operational improvement and organisational assurance. This section will be expanded with role-specific responsibilities, achievements and outcomes.

  • Governance and assurance
  • Service management
  • Risk management
  • Operational improvement
Academic & professional credentials

Credibility, documented.

Executive MA in Management — Merit

Durham University Business School
  • Strategy
  • Economics
  • Accounting
  • Strategic Marketing
  • Organisational Behaviour
  • Leadership
  • Operations Management
  • Supply Chain Management
  • Human Resource Management

BSc (Hons) Network Computing

University of Sunderland
  • Cisco networking
  • Voice over IP
  • SIP
  • Project management
  • Software engineering
  • Ethical hacking
  • Network management
  • C#
  • PHP
  • MySQL
Professional qualifications
CISM — Certified Information Security ManagerISO 27001:2022 Certified ISMS Internal AuditorISO 27001:2022 Certified ISMS FoundationMicrosoft Certified: Azure FundamentalsITIL 4 Direct, Plan and ImproveITIL 4 FoundationCOBIT 5
Doctoral research

The Development of the AI-Assisted Human.

Exploring how artificial intelligence can augment human capability, improve decision-making and support responsible governance.

Michael is currently undertaking doctoral research exploring how artificial intelligence can augment human capability within governance, risk, compliance and decision-making environments.

The research investigates how organisations can create effective partnerships between humans and artificial intelligence, combining machine intelligence with human judgement, accountability, ethics and contextual understanding.

Rather than viewing AI as a replacement for human expertise, the research focuses on the concept of the AI-Assisted Human: a future operating model where individuals are empowered by intelligent systems that enhance decision-making, productivity, learning and organisational performance.

Human–AI Collaboration

Exploring how AI can act as a trusted advisor, coach and analytical partner that enhances professional capability while preserving human accountability.

  • Decision support
  • Productivity enhancement
  • Reduced cognitive overload
  • Accelerated learning
  • Better access to organisational knowledge

AI Governance and Oversight

Investigating how organisations can govern AI responsibly while maintaining transparency, explainability and human control.

  • Transparency
  • Explainability
  • Ethical AI usage
  • Risk management
  • Human oversight
  • Accountability for decisions

AI in Risk and Compliance

Examining how AI can support governance, risk and compliance professionals without replacing professional judgement.

  • Risk identification
  • Control selection
  • Compliance monitoring
  • Evidence gathering
  • Internal audit support
  • Continual improvement

Organisational Transformation

Researching how organisations must adapt leadership, culture, governance structures and operating models to successfully integrate AI-enabled ways of working.

  • Workforce adaptation
  • Digital maturity
  • Change management
  • Trust in AI systems
  • Human-centred design
  • AI adoption governance
How this research shapes iso-standard.app

Research-informed. Practitioner-built.

The long-term vision for iso-standard.app is directly informed by Michael's doctoral research into the AI-Assisted Human.

The platform is being developed as an AI-assisted governance and compliance solution that helps organisations build, operate and improve management systems while preserving human accountability.

The aim is not to replace governance, risk or compliance professionals. The aim is to support them with intelligent tools that reduce administrative burden, improve evidence quality, strengthen risk visibility and enable better decision-making.

Build management systems faster
Maintain compliance more efficiently
Reduce administrative overhead
Improve risk visibility
Strengthen decision quality
Support internal audit activity
Preserve human accountability
Embed continual improvement into daily operations

“Artificial intelligence should enhance professional judgement, not replace it.”

AI-assisted governance, human-led accountability

Intelligent systems. Human accountability.

iso-standard.app is designed around a human-led model of governance. AI helps analyse information, suggest improvements, identify gaps, organise evidence and support decision-making — but accountability remains with people.

Intelligent Assistance

Use AI to reduce repetitive administration, organise evidence, identify gaps and support management system development.

Human Judgement

Keep experienced professionals in control of decisions, risk treatment, governance priorities and organisational change.

Sustainable Compliance

Move beyond one-off certification activity towards embedded, continually improving management systems.

Enquiry

Discuss your consultancy requirements.

Tell us a little about your organisation and challenge. Michael responds personally, usually within one business day.

Standards of interest
Type of support required
© 2026 ISO-STANDARD.app · Intelligent compliance software. Practical governance support. Human-led accountability.