The terminology problem

In everyday conversation, "we did a cybersecurity audit" often actually describes a risk assessment or a vulnerability scan — advisory work, not a formal, regulated audit process. This isn't usually dishonest, just imprecise, but the imprecision matters when a bank, regulator or investor asks specifically what was done.

What "readiness" means versus "certified"

Compliance readiness advisory means identifying the gap between your current posture and what a given regulatory or framework expectation requires, then closing that gap — it prepares you for a formal process, it isn't the formal process itself. Being "certified" or "audited" against a specific standard requires an appropriately licensed, independent body conducting that specific process.

Who handles statutory audits

RETIS provides risk assessment, security gap assessment, and compliance readiness advisory — not statutory audits, certifications, or regulatory approval, unless the relevant licensing is explicitly in place. Where a formal audit or certification is genuinely required, that needs a separately licensed provider for that specific process.

A practical checklist

  • Do you know precisely which term describes what you actually need?
  • If a partner or regulator asks "what was done," can you answer precisely?
  • Have you distinguished advisory work from any formal audit requirement?
  • Is your compliance readiness work documented in a way that would support a later formal audit?

Frequently asked questions