What we do

Specialist expertise across the compliance lifecycle

Organised around the ACT model — Auditing, Consulting and Training — each available as a permanent advisory retainer, temporary project support, or a freelance contract, whichever fits how your organisation resources compliance work.

Auditing

Evidence-based audits, scoped to what inspectors actually check

On-site or remote audits against GxP, pharmacovigilance and clinical-quality frameworks, delivered with findings your team can act on immediately.

Auditors and facility staff in a pharmaceutical manufacturing area
000°

GxP Quality Systems Audit & Compliance

A full assessment of your quality systems — current Good Manufacturing Practice (GMP/cGMP), Good Clinical Practice (GCP/cGCP), Good Distribution Practice (GDP/cGDP), Good Pharmacovigilance Practice (GVP/cGVP), Good Laboratory Practice (GLP/cGLP) and Good Documentation Practice (GDocP) — measured against what regulatory authorities expect to see, not just what the standard says on paper.

Engagements typically combine an on-paper gap analysis with structured interviews and, where useful, a mock inspection, so findings translate directly into a CAPA plan your team can execute.

  • Internal and supplier/CMO audits (AUD0001)
  • Gap analysis & CAPA planning (AUD0002)
  • Mock inspections and inspection readiness (AUD0003)

Typical timeline: 1–2 weeks planning & document review → 2–5 days on-site/remote audit → 1 week draft findings & CAPA plan.

Ask about GxP auditing →
240°

Clinical & Hospital Quality Auditing — ISO 7101:2023

ISO 7101:2023, the first international standard dedicated to quality management in healthcare organisations, is still largely unavailable through training and audit providers. We're closing that gap.

  • Available from Q4 2026 (Lead Auditor cohort, Oct. 2026) (ISO0001)
  • Gap assessment & readiness planning available now (ISO0002)

Typical timeline: 1 week readiness scoping → 2–3 weeks gap assessment → certification audit scheduled separately with the certification body.

Ask about ISO 7101:2023 →
Consulting

Building the systems that keep you compliant

Advisory work that goes beyond a findings report — helping your team design, document and operate the management systems a future audit will actually be checked against.

Advisory meeting with three consultants reviewing a tablet
060°

AI Governance & ISO/IEC 42001

For organisations deploying or procuring AI in a regulated context, we assess where current governance stands against ISO/IEC 42001 and build the management-system documentation and controls needed to close the gap.

Because ISO/IEC 42001, the EU AI Act and the NIST AI RMF overlap significantly in practice, this work also flags where a given AI system is likely to sit under the Act's risk tiers — useful input for legal and product teams working the same question from a different angle.

  • Gap assessment against ISO/IEC 42001 (AIG0001)
  • AIMS documentation & controls (AIG0002)
  • EU AI Act and NIST AI RMF risk-classification support (AIG0003)

Typical timeline: 1 week scoping → 2–3 weeks gap assessment → 1 week roadmap & report.

Ask about AI governance →
180°

Data Protection for Digital Health

Data protection work scoped specifically for health data: digital health platforms, clinical data flows, medical devices and AI-enabled tools that process patient information, where the stakes and the special-category rules are higher than in general-purpose data protection work.

The output is practical, not just a report: updated records of processing, a completed DPIA where one is required, and a clear view of which vendors or data transfers need closer attention.

  • Records of processing & legal-basis review (DPR0001)
  • DPIAs for health-data processing (DPR0002)
  • Vendor & data-transfer due diligence (DPR0003)

Typical timeline: 1 week data-flow mapping → 2 weeks DPIA & documentation → ongoing vendor review as needed.

Ask about data protection for health data →
220°

Pharmacovigilance & Regulatory QA

Quality assurance consulting of pharmacovigilance systems against GVP requirements — assessing whether your PV system would hold up under inspection, not running the day-to-day case processing itself.

This sits alongside broader regulatory-affairs support: submission planning, CMO oversight, and project management across multi-functional regulatory initiatives.

  • PV system consulting and risk assessment (QA/audit scope, not case processing) (PVR0001)
  • Regulatory submission & CMO-oversight support (PVR0002)
  • Multi-functional project management (PVR0003)

Typical timeline: 1 week scoping → 2–4 weeks PV system mock inspection & consulting → 1 week findings report.

Ask about PV & regulatory QA →
260°

GMP Systems Consulting

Quality assurance consulting of manufacturing systems against GMP requirements — assessing whether your GMP system would hold up under inspection, not running the day-to-day operations itself.

This sits alongside broader regulatory-affairs support: process controls planning, CMO oversight, and project management across multi-functional regulatory initiatives.

  • GMP & QMS system consulting and risk assessment (QA/audit scope, not case processing) (GMP0001)
  • Process controls & CMO-oversight support (GMP0002)

Typical timeline: 1 week scoping → 2–4 weeks GMP system mock inspection & consulting → 1 week findings report.

Ask about GMP systems consulting →
280°

GCP Systems Consulting

Quality assurance consulting of clinical trial systems against GCP requirements (ICH E6(R3)) — assessing whether your GCP system would hold up under inspection, not running day-to-day trial operations itself.

This sits alongside broader regulatory-affairs support: protocol and Trial Master File (TMF) planning, CRO oversight, and project management across multi-functional regulatory initiatives.

  • GCP & clinical quality system consulting and risk assessment (QA/audit scope, not case processing) (GCP0001)
  • TMF and CRO-oversight support (GCP0002)

Typical timeline: 1 week scoping → 2–4 weeks GCP system mock inspection & consulting → 1 week findings report.

Ask about GCP systems consulting →
300°

GDP Systems Consulting

Quality assurance consulting of wholesale distribution systems against GDP requirements (EU GDP Guidelines 2013/C 343/01) — assessing whether your GDP system would hold up under inspection, not running day-to-day logistics itself.

This sits alongside broader regulatory-affairs support: cold-chain and wholesale-distribution planning, logistics-partner oversight, and project management across multi-functional regulatory initiatives.

  • GDP & distribution system consulting and risk assessment (QA/audit scope, not case processing) (GDP0001)
  • Logistics-partner oversight support (GDP0002)

Typical timeline: 1 week scoping → 2–4 weeks GDP system mock inspection & consulting → 1 week findings report.

Ask about GDP systems consulting →
320°

GDocP Systems Consulting

Quality assurance consulting of documentation and data-integrity systems against GDocP requirements (ALCOA+ principles) — assessing whether your GDocP system would hold up under inspection, not running day-to-day record-keeping itself.

This sits alongside broader regulatory-affairs support: data-integrity planning, electronic-system validation oversight, and project management across multi-functional regulatory initiatives.

  • GDocP & data-integrity system consulting and risk assessment (QA/audit scope, not case processing) (GDOC0001)
  • Data-integrity and e-system oversight support (GDOC0002)

Typical timeline: 1 week scoping → 2–4 weeks GDocP system mock inspection & consulting → 1 week findings report.

Ask about GDocP systems consulting →
340°

GLP Systems Consulting

Quality assurance consulting of non-clinical laboratory systems against GLP requirements (OECD GLP Principles) — assessing whether your GLP system would hold up under inspection, not running day-to-day study conduct itself.

This sits alongside broader regulatory-affairs support: study-protocol planning, test-facility oversight, and project management across multi-functional regulatory initiatives.

  • GLP & laboratory system consulting and risk assessment (QA/audit scope, not case processing) (GLP0001)
  • Test-facility oversight support (GLP0002)

Typical timeline: 1 week scoping → 2–4 weeks GLP system mock inspection & consulting → 1 week findings report.

Ask about GLP systems consulting →
Training

Practitioner-level courses your team can run with

The same expertise behind our audits and consulting work, built into structured courses — starting with a complete, ready-to-run internal auditor programme. All content is provided under ©PizarroMethod.

Practitioner reviewing training materials at a desk with colleagues
300°

Internal Auditor Training — Turnkey

Flagship programme — video walkthrough coming soon

A complete, ready-to-run programme that takes your staff from GxP fundamentals to conducting their first internal audit — training materials, templates and mentoring included, so there is nothing extra to build in-house.

Delivered as a structured curriculum rather than a one-off workshop, so your internal audit function is operational immediately, not just theoretically trained.

  • Full curriculum, audit templates & checklists included (TRN0001)
  • Mentored first audit with structured feedback (TRN0002)
  • Certificate of completion (TRN0003)

Typical timeline: 2 days fundamentals workshop → 2 weeks self-paced modules → 1 mentored audit (timing depends on your audit calendar).

Ask about Internal Auditor Training →
Coming soon

More courses joining the library

Site Activation and EU/non-EU Batch Release are next, with further topics shaped by the training needs we hear most often from quality and regulatory teams.

Site Activation (TRN0004) EU and non-EU Batch Release (TRN0005)
Ask to be notified →
Access tiers

Built for teams, not just individuals

Individual

Self-paced learning

Full course library access for a single learner.

Team & Site

Shared access for a department

Progress tracking across a quality or regulatory team at one site.

Enterprise

Multi-site licensing

Annual subscription for organisations training across multiple sites or business units.

Timelines above are indicative and vary by scope, organisation size and current documentation maturity — confirmed during the initial conversation.

Why organisations work with TrueNorth

No conflict of scale

With no larger portfolio of accounts to protect, findings aren't softened to preserve a bigger relationship elsewhere in the business.

One point of contact

You work directly with the person doing the audit and writing the findings — not a rotating account team.

Both sides of the table

Direct experience auditing multinational manufacturers translates into knowing what inspectors actually check for.

Not sure which service fits?

Tell us about your organisation and where you are in your compliance or AI-governance journey — we'll recommend the right starting point.

Request a consultation