How MetisJean Went From Startup to ISO 27001 and ISO 27701 Certified in Five Months

Certification

ISO 27001 | ISO 27701 | ISO 42001

Industry

Technology Startup

Location

Product

ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 42001

Industry

Technology startup

Engagement Length

Five months

Location

Outcome

ISO/IEC 27001 and ISO/IEC 27701 certifications and an ISO/IEC 42001 implementation in five months

Key Performance Metrics

ISO/IEC 27001

Certification in 3 months

ISO/IEC 27701

Certification in 3 months

ISO/IEC 42001

Implementation fast-tracked over the following 2 months

A governance framework built from scratch

Managed in Drata and designed to scale as MetisJean grows

At a Glance

  • Challenge: MetisJean, a technology startup, came to Axipro with no governance framework and a tight deadline. The roadmap covered three standards: ISO/IEC 27001, ISO/IEC 27701 and ISO/IEC 42001.
  • Solution: Axipro designed the governance framework with MetisJean and built it directly in Drata, then worked with Sensiba, the audit partner, to keep the audit schedule lined up with MetisJean’s deadlines.
  • Results: ISO/IEC 27001 and ISO/IEC 27701 certification within the first three months, and the ISO/IEC 42001 implementation fast-tracked over the next two.

The Company

MetisJean is a technology startup that came to Axipro with no governance framework and a tight deadline. Five months later it held ISO/IEC 27001 and ISO/IEC 27701 certifications and had implemented ISO/IEC 42001.

MetisJean wanted a management system it could run day to day and that would keep up as the company grew, rather than a set of documents written for the audit.

01- THE CHALLENGE

Building Governance While Scaling the Business

Governance and growth at the same time

MetisJean was building governance while still scaling the business.

Nothing in place, strict deadlines

It needed policies, processes, controls, risk management and audit evidence. None of these existed yet, and the certification deadlines were strict.

Three standards on one roadmap

The roadmap covered three standards: ISO/IEC 27001 for information security, ISO/IEC 27701 for privacy information management, and ISO/IEC 42001 for AI management. Everything had to be built from scratch, put into practice and taken through audit on the business’s timeline.

02- THE ENGAGEMENT

A Governance Framework Built Directly in Drata

 Designed together, built in Drata

Axipro designed the governance framework with MetisJean and built it directly in Drata. That gave the team one place to manage controls and evidence, and a setup they can keep running after the audit.

 From requirements to audit readiness

Axipro then guided the team through the rest of the build, from governance requirements, policies and risk management to controls, evidence collection and audit readiness.

 A responsive team

MetisJean’s team made this easier. They replied quickly and stayed involved throughout, so decisions and remediation moved fast.

 The timeline: three months, then two

MetisJean earned ISO/IEC 27001 and ISO/IEC 27701 certification within the first three months. The team then fast-tracked the ISO/IEC 42001 implementation over the next two months, which matched the timeline MetisJean wanted.

 Audit schedule aligned with Sensiba

Axipro worked with Sensiba, the audit partner, to keep the audit schedule lined up with MetisJean’s deadlines.

03- THE RESULTS

From No Governance Framework to Three Standards in Five Months

In five months, MetisJean went from no governance framework to one that covers information security, privacy and AI governance.

  • ISO/IEC 27001 certification in 3 months
  • ISO/IEC 27701 certification in 3 months
  • ISO/IEC 42001 implementation fast-tracked over the following 2 months
  • A governance framework built from scratch, managed in Drata, and designed to scale as MetisJean grows

Axipro + Drata + Sensiba

The engagement worked because each party covered a different piece.

  • Axipro brought the governance and implementation expertise,
  • Drata gave MetisJean one place to manage compliance and track evidence, and
  • Sensiba handled the independent certification audit.

The speed depended on MetisJean’s team. Because they were responsive and involved from start to finish, Axipro could deal with requirements quickly and keep momentum all the way to certification.

Axipro is proud to have helped MetisJean grow from a startup with no governance into a company that’s ready for certification audits and can show customers why to trust it.

04- CUSTOMER VOICE

What MetisJean Said

Throughout the engagement, Anna from the MetisJean team praised the Axipro team’s professionalism and guidance. She singled out Shumaila, who led the GRC work with her team.

“I am so grateful you’ve taken us through this journey. You are one of the best professionals I’ve worked with.”

Anna, MetisJean

“Thank you Axipro team for getting us through Stage 1 external audit. You are all very professional and great to work with. One last milestone left 💪”

Anna, MetisJean

Case Studies

Explore More Case Studies