Book FREE Consultation

‍

URM is pleased to provide a FREE 30 minute consultation on Transitioning to ISO 27001:2022 for any UK-based organisation. Once an enquiry form has been submitted, we will be in touch to understand the nature of your enquiry and to book a mutually convenient time for a 30-minute consultation slot with one of URM’s specialists.

GC RTS Gap Analysis

UK’s most experienced and proficient information security auditors has been conducting RTS audits for over a decade

RTS Gap Analysis

If your organisation is looking to operate a remote gambling product in the UK and needs to meet the security requirements of the RTS, URM is able to conduct a gap analysis of the security controls you have implemented against the control areas from the Standard.  These control areas taken from ISO 27001 cover such topics as information security policies, human resource security, access control, cryptography, physical and environmental security, supplier relationships etc.  

The focus of the gap analysis will be the controls that are protecting critical systems, e.g., electronic systems involved in processing payment card information or systems involved in the generation of random numbers or communication networks that transmit sensitive customer information.  Following the gap analysis, URM will produce a report which will not only detail those areas where your organisation needs to develop or improve your control implementation but also recommendations on how to address any gaps.

‍

Get in touch

Please note, we can only process business email addresses.

‍

Why URM?

Track record

URM is one of the UK’s most experienced and proficient information security auditors and has been conducting RTS audits for over a decade and has conducted hundreds of ISO 27001-related audits. URM has an unparalleled track record of assisting over 500 organisations to achieve and maintain certification to ISO 27001 and as such is perfectly placed to not only conduct audits but conduct gap analyses and help organisations remediate any gaps identified.

Assessor Competence

The Gambling Commission requires that the annual security audit is conducted by an independent and suitably qualified auditor. All of URM’s auditors hold one or more of the main recognised qualifications, e.g., ISO 27001 Lead Auditor, Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM) or Certified Information Systems Security Professional (CISSP). A number also hold the Payment Card Industry Qualified Security Assessor (PCI QSA) qualification. Furthermore, RTS audit reports are all peer reviewed before being submitted.

Achieving optimum balance

If used to remediate any gaps, URM’s goal is to achieve the optimum balance between meeting the RTS control requirements and ensuring the control (e.g., policy, process or other documentation) is tailored to your organisation’s size, culture and business objectives.

Information Security FAQISO 27001 FAQ

ISO 27001 Clause 4.2, Understanding the Needs and Expectations of Interested Parties

Published on
2/10/2026

URM's blog examines ISO 27001:2022 Clause 4.2, covering interested parties, their requirements and how these are addressed through the ISMS.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
21/9/2026
ISO 27001 Clause 4.1 - Understanding the Organisation and its Context

URM's blog explores ISO 27001 Clause 4.1 & how to identify organisational context, assess internal/external issues, and support effective ISMS decision-making.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
28/8/2026
Auditing ISO 42001: Its Unique Requirements and Key Differences From ISO 27001

URM's blog examines how the ISO 42001 management system requirements differ from ISO 27001, and the impact this has on what auditors will expect to see.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
13/8/2026
ISO 27001 Clause 9.1: Monitoring, Measurement, Analysis and Evaluation Explained

URM’s blog explores ISO 27001 Clause 9.1, what it requires and practical guidance on how to implement this Clause in full conformance with the Standard.

Read more
"
We've been using URM for our PCI DSS assessments for the last 5 years and we are pleased with their service. The assessment is always completed promptly, the price is competitive, and communication is great. We'll keep using them and are happy to recommend URM to anyone.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.