Advisory work exists to close the gap between a requirement written in general terms and a decision that has to be made about a specific system. Regulations and standards are drafted to apply across every sector, which means they rarely answer the question actually being asked: whether this processing needs an impact assessment, whether this deployment makes us a provider, whether this control is proportionate for this risk. Turning the general into the specific is the work.
Most engagements span more than one framework because the obligations do. A single system can carry GDPR duties on the personal data, NIS 2 duties on the infrastructure, AI Act duties on the model, and ISO 27001 or SOC 2 evidence duties on the controls protecting all three. Mapped once, the shared evidence serves every regime; mapped separately, it acquires four descriptions and four owners who each assume someone else is handling it.
The boundary matters as much as the advice. Consultants analyse requirements, test assumptions, set out options with their consequences, and recommend a course of action. Accepting risk, committing budget, and approving a control set are management decisions and stay with named internal owners. An engagement that blurs that line produces a plan nobody inside the organisation actually owns, which fails at the first internal audit.
There is also a hard constraint on who can do what afterwards. Under clause 5.2.7 of ISO/IEC 17021-1, a certification body may not certify a management system it has consulted on for at least two years. Advisory support and certification therefore have to come from different organisations, and the sequencing is worth settling at the start rather than discovering it when the certification body asks who wrote the Statement of Applicability.