Free consultation

ISO Consulting & Software Development

ISO certification
built on systems that actually work
not binders on a shelf

We set up information security, personal data protection and software development processes so your organisation is ready for audit — and we build the software that keeps those systems running long after the certificate arrives.

Registered company 0525568001095Nationwide · onsite & online
Company
Touch Consulthink Co., Ltd.
Tax ID
0525568001095
Office
Mueang Lampang, Lampang
Phone
086-654-0991

ISO Consulting

The standards your customers and partners are starting to ask for

We don’t hand every client the same document template. We look at how you actually work, then design policies, procedures and evidence that meet the requirements — at a size your team can maintain on its own.

ISO/IEC27001

Information Security Management System (ISMS)

Information security management

For: software companies, cloud and data-centre providers, businesses holding customer data, or anyone whose clients require it.

  • Risk assessment and Statement of Applicability
  • Policies and procedures for the Annex A controls
  • Security awareness training for staff
  • Internal audit and management review
ISO 27001 in detail →
ISO/IEC27701

Privacy Information Management System (PIMS)

Privacy information management

For: organisations processing large volumes of personal data that need to show systematic PDPA compliance.

  • Personal data mapping and Records of Processing (RoPA)
  • Defining Controller / Processor roles
  • Data subject request and breach response procedures
  • Run alongside ISO 27001 to avoid duplicate work
ISO 27701 in detail →
ISO/IEC29110

Systems & Software Engineering — Lifecycle Profiles for Very Small Entities (VSEs)

Software process for small organisations

For: software companies or development teams of up to 25 people who need to prove process quality to clients, government tenders or large enterprises.

  • Assessment against the Basic Profile and choice of profile level
  • Project Management (PM) and Software Implementation (SI) processes
  • Templates: project plan, requirements specification, test records
  • Fits the tools your team already uses, such as Git and Jira
ISO 29110 in detail →

ISO/IEC 27001:2022 · Annex A

93 controls in 4 themes

Our Process

From day one to the day the auditor walks in

Every project follows these five steps. Timing depends on your size and scope — you’ll get a firm timeline once the readiness assessment is done.

  1. Gap analysis

    Compare your current practice with the requirements and define the certification scope.

    ~2–4 weeks
  2. System design

    Write policies, procedures, forms and a risk register people will actually use.

    ~1–3 months
  3. Rollout & training

    Train your team and build up complete records and evidence.

    ~1–3 months
  4. Internal audit

    Audit internally, fix nonconformities and hold the management review.

    ~2–4 weeks
  5. Certification audit

    We stand beside you through the certification body’s or assessor’s audit until you’re certified.

    per auditor schedule

Consultants cannot issue certificates — certificates come from an independent Certification Body. We help you choose one and make sure everything is ready.

Software Development

Consultants who can code

Most ISO systems fall apart after certification because everything lives in spreadsheets nobody updates. We build tools that keep the system running, and take on general software projects using the same process we teach under ISO/IEC 29110.

01Compliance systems

Risk registers, document control, audit tracking and reminders for tasks coming due.

02PDPA tools

Consent management, data subject requests and RoPA records.

03Web apps & internal systems

Back-office systems, dashboards and custom workflows, secure by design.

04Integrations

APIs, alerts via LINE / Telegram / email, and migration from legacy systems.

Software development in detail →

ReactTypeScriptPostgreSQLSupabaseCloudflareREST API
# Example: weekly ISO task reminders
ISMS · Week 38

 A.5.15 Access rights review         done
 A.8.13 Backup restore test          done
! A.6.3  Train 3 new employees        due 26 Sep
! 9.2    Internal audit, round 2      due 15 Oct

# Summary sent to the owners on LINE

Our Product

Evidosa — our own platform, where audit evidence comes from the work your team already does

Touch Consulthink’s software development management platform, for software companies and IT teams that must pass standards audits without stopping development to write documents.

Evidence from real work

Requirements, risks, tests and acceptance live in one process, and the system shows which evidence each clause of the standard needs.

Reports in each standard’s format

Generate reports in the structure each standard expects at any time, as a printable document or a spreadsheet.

Keep the certificate next year

Every piece of evidence has its own review date, with a warning 60 days before it expires.

Quality assistants

Flag untestable requirements and generate test cases, rule-based or AI-assisted — AI can suggest, but never changes your work on its own.

Why Touch Consulthink

Talk to the people who do the work, start to finish

Our name comes from “Touch” — getting hands-on with the real work — and “Consult + Think” — thinking it through with you, not for you.

Right-sized systems

Designed for your size, with no more paperwork than needed, so a small team can keep it going.

ISO and IT in one team

When a technical control needs fixing, we can fix it — no second vendor — and we build our own tool, Evidosa.

Clear pricing

Quotes broken down by phase, so you know what each payment covers.

Nationwide

Based in Lampang, working onsite and online with clients across Thailand.

FAQ

Before starting, clients usually ask…

Can’t find your answer? Call us on +66 86 654 0991 or email touchconsulthink@gmail.com.

How long does ISO 27001 take?

Most small and mid-sized organisations take about 4–9 months from kickoff to audit-ready, depending on scope, existing documentation and how much time your team can give. You’ll get a firm timeline after the gap analysis.

Can Touch Consulthink issue the ISO certificate?

No — and no consultant should. Certificates must come from a Certification Body independent of the consultant, to keep it impartial. Our job is to get you ready and through the audit.

How is ISO/IEC 29110 different from ISO 9001?

ISO 9001 is a general quality system for any industry. ISO/IEC 29110 is built specifically for small software teams of up to 25 people and focuses directly on project management and software implementation — less documentation, faster to adopt.

Do we need ISO 27001 before ISO 27701?

The latest edition of ISO/IEC 27701 can be implemented on its own, but in practice most organisations pair it with ISO 27001 because they share much of the management structure and controls — saving time and audit fees.

Do you take software projects unrelated to ISO?

Yes. We build web apps, internal systems and integrations, with security designed in from the start following ISO 27001 practice.

Contact

Start with a free one-hour readiness assessment

Address
42/135 Chit Aree Ville 5, Lampang–Ngao Highway Rd., Chomphu, Mueang Lampang, Lampang 52100, Thailand

Call or email us and tell us where your organisation stands. We’ll tell you which standard to start with, roughly how long it will take, and what you need to prepare.

Tax ID
0525568001095