ABOUT // COMPLIANCE SPRINTS

Practitioner-built. Audit-grade. No nonsense.

Compliance Sprints exists because most SMEs hit their first audit unprepared — not for lack of effort, but because the gap between "we have a policy" and "we have a working control" is invisible until an auditor finds it.

FOUNDER // CARL PITTS

CP

20 years on both sides of the audit room

Carl has led £250M+ in cybersecurity transformation across financial services, healthcare, and critical national infrastructure. He's been the auditor making findings, the auditee writing remediation plans, and the executive answering to the board when audits go sideways.

Compliance Sprints is the toolkit he wishes had existed when he first walked into a SOC 2 audit unprepared, in 2008.

CISMCISACISSPCEHAWS SecurityPRINCE2

PHILOSOPHY // THREE PRINCIPLES

01

Honesty over flattery

A 60% is a 60%. Inflated scores cost you audit findings later.

02

Documents are evidence

If you can't show approval, dates, and review history, the control doesn't exist.

03

Practitioner over theorist

Every recommendation comes from an audit room, not a textbook.