February 28, 2024

Environmental Resource Management (ERM) Case Study

ERM is the largest global pure play sustainability consultancy, partnering with the world's leading organizations to create innovative solutions.

Share this post

“No other software vendor has invested this level of effort in our success, and we are most grateful”

– David Reilly, Environmental Resource Management Technical Lead

Environmental Resource Management (ERM) is the world’s largest advisory firm focused solely on sustainability, offering unparalleled expertise across business and finance. ERM supports clients across the business lifecycle and at all levels to assist in the transition towards a sustainable economy; creating sustainable products and supply chains; developing physical assets in a sustainable way; and integrating sustainability into daily operations.

With the help and support of Hicomply, ERM has also been able to seamlessly integrate ISO 27001 into daily operations, too.

The review

“The relationship we have with the Hicomply team is possibly the best we have with any of our vendors. It is that relationship that has enabled us to make use of the Hicomply system with such effectiveness, leading to our own ISO 27001 certification in a very short timeframe.”

Why does your organisation need 27001?

“ISO 27001 is an essential part of security management and the certification demonstrates to our customers and investors that we are properly managing the security and integrity of their data. It also helps to accelerate the acceptance of our products and services during the sales process.”

How did you manage 27001 previously?

“Before investing in an ISMS, our security configuration was difficult to manage with an inconsistent application of controls. Without an agreed approach it was not possible to measure our security performance.”

Why did you choose Hicomply?

“The functionality of Hicomply best suited our requirements, and the application appeared to be well maintained and under constant development.”

How have you found the customer service you have received?

“The entire team far exceed our expectations. We feel that we are an active part of the evolution of the Hicomply system. Many of our requests have been implemented and we have received detailed guidance to enable us to make best use of the available features.

“No other software vendor has invested this level of effort in our success, and we are most grateful to Laura and her team. Long may it continue!”

Risk Management
Compliance Reporting
Policy Management
Incident Management
Audits and Assessments

Ready to Take Control of Your Privacy Compliance?

See how Hicomply can accelerate your path to CAF compliance in a 15-minute demo.

Risk Management

Identify, assess, and mitigate security risks with an integrated risk register.Hicomply’s automated risk management software maps controls across ISO 27001, SOC 2, and NIST frameworks — helping teams track risk treatment plans, assign ownership, and monitor real-time compliance status.Build a resilient ISMS that reduces audit findings and demonstrates continuous improvement.

Compliance Reporting

Generate instant, audit-ready compliance reports across multiple frameworks — from ISO 27001 and SOC 2 to GDPR, DORA, and NHS DSPT.Automated evidence collection and built-in dashboards provide a single source of truth for your compliance posture, saving weeks of manual work during audits.

Policy Management

Centralise, version, and publish all your information security policies in one place.Hicomply automates approvals, reminders, and distribution, ensuring your ISMS documentation stays current and aligned with frameworks like ISO 42001 and NIST CSF.Say goodbye to outdated PDFs — manage policies dynamically and maintain full traceability.

Incident Management

Capture, investigate, and resolve security incidents with structured workflows and automated evidence trails.Hicomply integrates with ticketing tools like Jira, Zendesk, and Azure DevOps to streamline incident response and link findings to risk and control updates — a key step for SOC 2 Type II readiness.

Audits and Assessments

Simplify internal and external audit preparation with built-in audit templates and automated task assignments.
Hicomply’s audit management platform aligns with ISO 27001, ISO 9001, and ISO 14001, giving teams a clear overview of control effectiveness, audit evidence, and corrective actions — all from one dashboard.