Achieved Compliance

Back to Blog

FROM CONVERSATION DATA TO CERTIFICATION: How Future Ready AS used our Cyrigo platform to achieve ISO 27001 and 27701 certification

Customer story – Cyrigo AS

At a glance

Customer: Future Ready AS – a Norwegian provider of an agentic CX platform (Conversation Intelligence, AI Coaching, AI Outbound Caller) built specifically for Nordic speech (https://futureready.ai/)
Industry: SaaS / AI for the contact centre sector
Challenge: Building an audit-ready management system for information security and privacy, in a business that processes sensitive audio recordings and conversation data for European customers
Solution: Every module in Cyrigo – GRC platform, Cyber Risk, Privacy, task management, access control and reporting
Result: Certified to ISO/IEC 27001:2022 and ISO/IEC 27701, with a single system covering the entire path from gap analysis to audit

Background: A company built on trust in data

Future Ready is building what they describe as "the agentic CX platform we wished existed" – a tool that understands Norwegian and Swedish conversations in their own language, without translating them into English or sending them outside Europe first. The platform scores every single customer conversation, builds targeted speech coaching from the weaknesses it uncovers, and does all of it while every audio recording stays within the EU throughout.

That makes information security and privacy far more than a checkbox for Future Ready. The company handles audio recordings of real customer conversations – often containing names, phone numbers and other personal information – which are transcribed, anonymised and analysed. For a small, execution-focussed founding team, that meant a robust, documented management system had to be in place quickly, without costing the company the pace it is built to keep.

"Privacy and data residency are the foundation the platform is built on, not features added afterwards." — Future Ready, on its own security philosophy

The challenge: From principle to documented compliance

Saying you are built for security is one thing. Proving it to security and procurement teams at European customers – with a certificate, a Statement of Applicability (SoA) and an audit trail – is something else entirely. Future Ready faced three parallel needs:

  1. A certification-ready information security management system (ISO/IEC 27001:2022) capable of withstanding an independent audit

  2. A privacy extension (ISO/IEC 27701) formalising how personal data in conversation data and transcriptions is processed, anonymised and deleted

  3. One place to manage all of it – instead of spreadsheets, email threads and scattered documents, which quickly become a bottleneck in a small company with no dedicated compliance function

"We're a small team, and we couldn't afford to put the product on hold for six months to get certified. Having the gap analysis, the risk register and the SoA in one place meant the work could run alongside everything else, instead of taking over." - Lars Andreas Kolflaath, CEO, Future Ready AS

The solution: Every Cyrigo module working together

Rather than splitting the work across several tools and spreadsheets, Future Ready chose to adopt the full Cyrigo platform. Here is how the modules were used throughout the certification process:

The GRC platform gave Future Ready the overview they started from: A consolidated view of IT systems, vendors and information assets, and the connections between them – essential for identifying which systems actually handle conversation data, and where the critical dependencies lay.

The Cyber Risk module provided a customisable, interactive risk picture across the entire organisation. With a small team, being able to see every risk in one aggregated view – rather than digging through separate assessments – was decisive.

The Privacy module simplified the registration of processing activities and provided a structured basis for personal data processing tied directly to conversation data – from transcription to anonymisation to storage – which later became the backbone of the ISO 27701 work.

The ISO/IEC 27001 and 27701 framework support gave Future Ready a ready-made setup for gap analysis, risk register, Statement of Applicability (SoA), control implementation guidance and an internal audit checklist – in practice, the map from current state to certification-ready documentation.

The same approach is now being applied to the EU AI Act: Cyrigo's AI Act framework lets Future Ready reuse the risk assessments, asset overview and controls already in place, rather than starting a third compliance process from scratch.

Task management let the team delegate concrete measures and track status as work progressed, with tasks linked directly to framework requirements or assets – so that nothing uncovered in the gap analysis disappeared into a forgotten email.

Access control, hierarchy and SSO mirrored Future Ready's own organisational structure and role-based access principles (RBAC) directly in the tool, with fast sign-in via Microsoft SSO – consistent with the principle of least privilege already underpinning their technical architecture.

Archive and reporting brought earlier risk assessments and other relevant documentation together in one place, and made it possible to produce finished risk assessment reports directly from the platform – documentation that fed straight into the audit evidence.

“Before, we managed compliance across spreadsheets, which made it difficult to maintain a shared overview. Now our risks, processing activities and open tasks are all in one system, so everyone on the team can see where we stand and what needs to happen next.” - Lars Andreas Kolflaath, CEO, Future Ready AS

The result

With the entire management system consolidated in one platform, Future Ready achieved:

  • ISO/IEC 27001:2022 certification, with an independently audited management system and a continuously maintained SoA

  • ISO/IEC 27701 certification, formalising the privacy work around conversation data and giving customers a concrete answer on how personal data is handled across the full processing chain and a continuously maintained PIMS

  • One consolidated system for risk, privacy and task follow-up – instead of documentation scattered across spreadsheets and folders

  • Faster security conversations with customers: the certificate and SoA can now be shared directly when European customers' security and procurement teams request documentation, with no manual gathering from multiple sources

For a small, execution-focussed team, this meant the certification work could be done alongside product development – not instead of it.

Back to Blog