RSI Security, ISO 27001
Consultancy offering ISO 27001 readiness and ISO 42001 gap assessment and AI management system design, then referring clients to a separate auditor, and does not issue certificates.
RSI Security also offers compliance advisory. This page covers the ISO 27001 and ISO 42001 side of what they do, because that is what ISO27K is about.
RSI Security delivers from the United States. Canadian buyers should expect a cross-border engagement: quoting in US dollars, and no built-in familiarity with PIPEDA, Law 25 or the Canadian buyers asking you for a report. Where those matter, compare the quote against Canadian firms in this directory, which price in CAD and already work inside that market.
The listing
| Services | ISO 27001, ISO 42001, Compliance advisory |
|---|---|
| Frameworks | ISO 27001, ISO 42001 |
| Based in | United States |
| Website | rsisecurity.com |
What to check before you hire them
This is general advice about the kind of work RSI Security offers, not a judgement about the firm. Ask any firm the same questions and compare the answers.
- Certification body or consultant, never both for you
- Only an accredited certification body can issue an ISO 27001 certificate, and it cannot consult for the same client. A consultant builds the ISMS and walks you to the audit. Ask which one this is, and if they certify, ask who accredits them: in Canada that is the Standards Council of Canada, and internationally UKAS or ANAB.
- ISO 42001 is new, so ask what they have actually done
- The AI management system standard published recently and the pool of firms with real engagements behind them is small. Ask how many they have completed rather than how many they can talk about, and whether they are accredited to certify against it or only to advise.
Working with a firm in United States
Most of this work is done remotely and a cross-border firm can be the right answer, particularly if your buyers, your auditor or your users are in the United States too. Weigh the exchange rate against whatever they do better than the firms closer to you.
If a firm headquartered outside Canada also advertises a Canadian presence, treat that as a claim to check rather than a fact. Ask for the Canadian street address, the names of the people working from it, and a Canadian client who will take your call. A real office answers all three in one reply. A landing page put up to rank for Canadian searches answers none of them, and the engagement is still delivered from the United States.
This listing is not written by the firm
It was compiled from public information, so treat it as a starting point rather than a statement from RSI Security. If you work there, claim the listing and it becomes yours to correct. Claiming is free.
Get a quote from RSI Security
Tell us what you need and we will put it in front of RSI Security and the other firms in the directory that match it. There is no charge to you.
Get a quoteBrowse the rest of the list
RSI Security appears on these pages alongside comparable firms.
- Compliance advisory firms in Canada, 67 firms
- ISO 27001 firms in Canada, 68 firms
- ISO 42001 firms in Canada, 33 firms
Other firms doing this work
TrazTech Inc., Johanson Group LLP, MHM Professional Corporation, 13 Security, 360 Advanced, 7 River Systems
How do I know I can trust a firm like this?
Judge the website the way you would judge a report they wrote for you, because it is the only sample of their work you get for free. Four things to look for:
Past work, in specifics. Named clients, case studies, redacted sample reports, published research, CVEs, conference talks. A security or compliance firm that has done the work has something to show for it. A site that describes the service at length and never once shows the output of it is the single biggest red flag on this list.
An address in every country they claim. If a firm says it operates somewhere, it should show a street address there, and named people working from it. A country page with no address, no staff and no local clients is a marketing page, not an office, and the work will be delivered from wherever they actually are. That is fine if they say so, and a problem if they do not.
Writing that could only be about them. Generic copy that could have its name swapped for any competitor's, or the flat and tireless prose of an unedited language model, usually means nobody senior has looked at the page. Ask yourself whether any of it commits them to anything a client could hold them to.
People with names. Who leads the work, what they have done before, and are they findable outside the site. Testing and audit work is done by individuals, and a firm that will not name them is asking you to buy a logo.
None of these is proof on its own. Two or more together is a reason to ask direct questions before you sign anything, and to compare at least three firms. There is a longer version, with what to ask for in each case, on how to vet a firm.
Is this firm recommended by ISO27K?
No. A listing is not a recommendation. RSI Security carries an unclaimed listing, and nothing on this page is an endorsement of the firm or a statement that it is the right one for you. Compare at least three.
Does RSI Security pay to appear here?
No. This is a free listing. Firms can pay for the Verified tier, and this one has not.
How do I get a quote from them?
Use the form linked above. It goes to the firms whose services match what you describe, which includes this one. You are never charged for a quote.