Software versus spreadsheets

Spreadsheets are not the enemy. They are an excellent place to think and a poor place to keep a management system operating for three years. This page sets out where the line usually falls, without pretending the answer is always software.

Where spreadsheets hold up

For a first risk assessment, a gap analysis or a control list on one standard, a spreadsheet is faster than any tool. It is flexible, everyone can use it, and it costs nothing. Plenty of organisations reach their first certificate this way and are right to.

Where it starts to cost more than it saves

The difficulty is not the first version; it is the second year. A spreadsheet stores values, not relationships. It cannot tell you that a control has no owner, that its evidence is fourteen months old, that the same control appears in three tabs with different wording, or that an audit finding was never closed. Each of those is discovered by a person looking, and people stop looking when the work is busy.

ConsiderationSpreadsheets and documentsA linked management system
Setup speedImmediate — open a file and startImport existing records, then map to standards
TraceabilityManual cross-references between filesRisk, control, owner and evidence linked as records
OwnershipA name typed in a cellNamed owner with reminders until the work closes
Evidence freshnessVisible only if someone checks the dateReview interval per item; staleness surfaces itself
Multiple standardsA separate workbook per standard, re-keyedOne control mapped to every standard it satisfies
Audit preparationCollate and re-check before each auditExport the current position at any time
Buyer questionnairesRewritten from memory each timeAnswered from the same controls and evidence
CostNo licence; time cost rises with scopePublished subscription; time cost flatter as scope grows
Best suited toOne standard, small scope, one ownerSeveral standards, several owners, recurring assurance

A reasonable test

Ask three questions of your current spreadsheet. Who owns control A.5.15 and when did they last evidence it? Which other standards depend on that same control? What is still open from the last internal audit? If answering takes longer than a minute, the cost has moved from the tool to the searching. If it does not, keep the spreadsheet.

If you do want the linked version, the risk, controls and evidence page describes the record structure, and the risk register template is free either way.

Deciding how to run it

Answers buyers, procurement and auditors want

Can you certify to ISO 27001 using spreadsheets?+

Yes. The standards require records, not software. Organisations certify with documents and spreadsheets every year. The question is what maintaining them costs once the system has to keep running between audits.

When are spreadsheets genuinely fine?+

A single standard, a small scope, one person doing the work, and an audit date in the near future. The overhead of any tool is hard to justify against that.

What breaks first?+

Usually ownership and freshness. Nothing in a spreadsheet chases the person responsible, and nothing marks evidence as out of date, so gaps appear quietly and are found during the audit.

See how your existing risks, controls and evidence could become one integrated management system

Bring what you already have — a part-finished risk register, a folder of policies, last year's audit findings — and see it mapped across the standards you need.

Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.