Built by a 25-year IT governance practitioner — for SMEs and consultants

The operating system
for integrated trust & risk.

Not another GRC platform. A workspace built around the outcomes SMEs and consultants actually need — certification, customer trust, faster procurement approvals, and less audit pain.

  • Certification-ready evidence, day one
  • Customer trust, self-served
  • Procurement approvals in days, not months
  • Audits without the fire drill
Live
Likelihood × Impact
5×5
5
10
15
20
25
4
8
12
16
20
3
6
9
12
15
2
4
6
8
10
1
2
3
4
5
LowCritical
Open risks
147
▾ 12% this quarter
Controls live
93
of 114 Annex A
Built around the standards auditors expectISO 27001ISO 31000ISO 9001ISO 42001ISO 20000-1SOC 2GDPRPCI-DSSCyber Essentials+
Certified
evidence and controls ready for your next audit
Trusted
live Trust Center your buyers can self-serve
Faster
procurement approvals — questionnaires in hours
Calmer
audits — no last-minute evidence scramble
AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the Lovable AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

Software + expertise

Software plus real-world implementation support.

iso-standard.app combines intelligent standards management software with consultancy and advisory support from an experienced governance, risk, compliance and service management leader.

Implement Standards

Support for ISO 27001, ISO 20000-1, ISO 9001 and ISO 42001 implementation, improvement and certification readiness.

Manage Risk

Practical support for information security, technology, supplier, operational and enterprise risk management.

Govern AI Responsibly

AI governance support informed by doctoral research into the AI-Assisted Human and practical experience in management systems and risk.

Why it matters

SMEs don't need more GRC. They need outcomes.

Enterprises buy GRC platforms to satisfy their board. SMEs and their consultants need something different: the certificate on the wall, the buyer who says yes, the procurement team that stops asking questions, and an audit that doesn't hijack the quarter. Everything here is built for those four outcomes.

Certification, not paperwork

Controls, evidence and policies pre-mapped to ISO 27001, 9001, 42001, SOC 2 and more — so you arrive at the audit already ready.

Get certified, faster

Customer trust, self-served

A branded Trust Center your prospects can visit at 11pm. Live control status, gated evidence, one link in every proposal.

Win the buyer before the call

Faster procurement approvals

Answer SIG, CAIQ and custom questionnaires in hours, not weeks — with a reusable answer library that gets sharper every deal.

Move from RFP to signed in days

Less audit pain

Continuous evidence, internal audits, CAPA and management review — the fire drill replaced with a rhythm your team can actually run.

Audit week becomes audit hour
Outcomes, not feature volume

The trust OS, measured in time you get back.

Every metric below is grounded in a source we can point you to — vendor benchmarks, analyst studies, or the workflow inside the product. No made-up percentages.

~80%
less time on buyer questionnaires

AI-assisted questionnaire answering with a reusable evidence library. Aligns with the 81% reduction IDC measured for AI-driven questionnaire automation across the trust-management category in 2025.

Source: IDC Business Value benchmark, 2025
2–4 wks
to audit-ready for ISO 27001 / SOC 2

Pre-mapped Annex A / TSC controls, policy templates and evidence slots collapse the standard 3–6 month readiness project into weeks — matching the fastest timelines reported by compliance-automation platforms.

Source: ComplianceRated readiness benchmarks, 2025
Days, not months
to clear procurement security review

A live, self-serve Trust Center means prospects find the SOC 2, ISO cert, DPA, subprocessors and pen-test summary without a sales cycle — cutting the 30–90 day review window most SMEs face.

Source: Enterprise buyer procurement studies, 2024–25
~70%
less effort on user access reviews

Structured quarterly access review workflow with evidence capture, replacing spreadsheet chases. Comparable to the reduction Vanta reports for automated access reviews.

Source: Vanta Access Reviews product benchmark
0
third-party AI training on your data

Prompts and evidence go through the Lovable AI gateway with contractual no-training terms. Your controls, policies and questionnaire answers never enter a model provider's training set.

Source: Platform architecture — verifiable in code
1 link
replaces the evidence email chain

Buyers get a permissioned Trust Center URL with real-time control status, gated documents and NDA support — replacing the ad-hoc DPA/SOC-2/questionnaire email loop.

Source: In-product Trust Center (see /trust)
9+
standards in one workspace

ISO 27001, 9001, 42001, 20000-1, 31000, 22301, SOC 2, GDPR, Cyber Essentials — controls crosswalked so one piece of evidence satisfies multiple frameworks.

Source: In-product control catalogue
£0
six-figure GRC contract

Subscription pricing designed for SMEs and consultants. No mandatory implementation project, no per-framework surcharge in the £5k range that Vanta and Drata charge for additional standards.

Source: Public pricing pages, verified July 2026
See it in 24 seconds

How ISO-STANDARD.app actually works

From a fresh risk register to an audit-ready treatment plan — the whole workflow, end to end.

The platform

Everything an ISO program needs — in one workspace.

Risk register

Score, treat and track every risk — with the audit trail built in.

Likelihood × impact, ownership, status, treatments and evidence — one source of truth per workspace.

Heatmap5 × 5
5
10
15
20
25
4
8
12
16
20
3
6
9
12
15
2
4
6
8
10
1
2
3
4
5

Assets & threats

Inventory your assets and tie risks to the things they actually threaten.

Controls & treatments

Map Annex A controls, plan treatments, assign owners with due dates.

Audit-ready dashboards

KPIs, heatmaps and exportable reports leadership and auditors can both read.

Secure by Design Platform

Enforced security, per-workspace and row-level security with role-based access out of the box. Hosted in the EU, provided by UK company.

Close the ISO governance loop

Internal audits, corrective actions and management reviews — built in.

Clauses 9.2, 10.1 and 9.3 are where most ISO certifications get lost in spreadsheets. Not here.

Clause 9.2

Internal audit programme

Plan, schedule, evidence and close internal audits with a full trail auditors love.

Clause 10.1

Corrective action register

Log nonconformities, assign owners, verify effectiveness, and prove closure.

Clause 9.3

Management reviews

Structured inputs and outputs, attendees, minutes and a finalise workflow that locks the record for the audit trail.

Standards

Built for the standards auditors expect.

Switch frameworks per organisation. ISO-STANDARD.app ships defaults for ISO 27001 Annex A, the ISO 31000 risk process, ISO 9001, SOC 2, GDPR, PCI-DSS, Cyber Essentials and Cyber Essentials Plus.

ISO 27001
Information security
ISO 31000
Enterprise risk
ISO 9001
Quality
ISO 42001
AI management
ISO 20000-1
IT service mgmt
SOC 2
Trust services
GDPR
Data protection
PCI-DSS
Payment cards
CE+
Cyber Essentials+
Why SMEs and consultants switch to ISO-STANDARD.app

Silicon Valley GRC bloatware, meet real-world buyers.

Vanta, Drata, Sprinto, Secureframe and Thoropass are powerful — but priced for Series B upwards and optimised for SOC 2. ISO-STANDARD.app is purpose-built for SMEs and consultants running ISO programs — by someone who's spent 25 years earning the trust of the buyers on the other side of the table.

vs. Vanta, Sprinto

True multi-tenant by design

Manage your own organisation and every client workspace from one login. Vanta, Sprinto and Hyperproof bill per-entity.

vs. Vanta, Drata

ISO-first control libraries

Ships with ISO 27001 Annex A, 31000, 9001, 42001, 20000-1, SOC 2, GDPR, PCI-DSS and CE+ catalogues ready to adopt.

vs. Diligent, Resolver

Transparent, fair pricing

Flat workspace pricing — no per-control, per-auditor or per-framework surcharges.

vs. Hyperproof, Resolver

Live in minutes, not quarters

Create a workspace, pick a standard, start logging risks. No mandatory implementation engagement.

vs. Vanta, Sprinto

Risk-led, not checklist-led

A real 5×5 likelihood × impact heatmap, treatments and control mapping at the core.

vs. Onspring, Diligent

Audit-ready exports out of the box

Risk register, control status and treatment plans export cleanly for surveillance audits.

Capability
ISO-STANDARD.app
Enterprise GRC
Diligent · Resolver · Onspring
Compliance suites
Vanta · Sprinto · Hyperproof
Multi-client workspaces in one login
ISO 27001 · 31000 · 9001 · 42001 · 20000-1 · SOC 2 · GDPR · PCI-DSS · CE+ ready
5×5 risk heatmap as a first-class view
Flat, predictable workspace pricing
Self-serve setup — no mandatory implementation fee
Exportable audit-ready reports included

Stop paying enterprise GRC pricing for an ISO program. Start your workspace free — bring your first standard live today.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.