
A carve-out inherits obligations without inheriting the corporate machinery that used to meet them. After leaving Gartner, TalentNeuron owned its own security posture for the first time, with roughly 400 to 500 staff, enterprise customers, and standing privacy commitments to maintain. Then the company acquired a firm with its own ISMS, its own policies, and its own way of doing things. Running two security programs side by side would have doubled cost and confused every audit that followed. The integration had to produce one system, and the certification had to cover the merged organization, not the company as it looked before the deal.
BD Emerson built the ISMS for the combined entity. The scope was drawn to cover both organizations from the start, the acquired company's controls were mapped against the target control set, and the stronger control won wherever the two programs overlapped. Policies were consolidated rather than duplicated, risk registers merged, and Vanta implemented as the single compliance platform so evidence from both sides of the merger landed in one place. The integration work ran alongside certification preparation, so the Stage 1 and Stage 2 audits examined the company TalentNeuron had actually become.
TalentNeuron earned its first ISO 27001 certification with the acquired company inside the scope: one management system where there could have been two, and a compliance platform the whole organization shares. The merger is visible in the org chart and invisible in the control environment, which is the point of integration done early.