Compliance guides
Practical, plain-English guides to every standard ISO-STANDARD.app supports. Written by practitioners, free to read, no email gate.
Pillar guides
Thought leadershipISO 27001 certification cost (2026)
A transparent, line-by-line breakdown of what ISO 27001 really costs a UK/EU SME — registrar fees, internal effort, consultancy and tooling.
EU AI Act compliance guide for SMEs
Risk tiers, obligations, timelines and the documentation auditors will ask for — with Harvard-referenced sources throughout.
AI adoption: a risk-based approach
A practitioner's frame for adopting AI by inventory, classification, treatment and monitoring — not by accident.
The AI-assisted human
Michael McCarroll's sociotechnical model of person-plus-AI as the real unit of governance — drawing on Tavistock and actor-network theory.
AI adoption in resource-constrained organisations
The staged pattern that produced ROI in twelve weeks inside a UK housing association — governance and workforce first, tooling last.
The State of Risk Management in 2026
Why the spreadsheet era is finally ending — a four-stage maturity model, where most organisations actually sit, and what good looks like next.
Internal audit, CAPA and management review
How ISO clauses 9.2, 10.1/10.2 and 9.3 form a single loop — and how to run it without the spreadsheet stack that fails at surveillance.
Trust as competitive advantage
Why trust — evidenced, not asserted — is the fastest-compounding B2B moat, and how to operationalise it.
The long-term trust flywheel
Trust is not a campaign. Chained into a rhythm, artefacts become a flywheel that compounds into dominant advantage.
AI governance & risk — 11 new articles
EU AI Act compliance guide for SMEs
AI adoption: a risk-based approach
The AI-assisted human
Ongoing management of AI systems
Supplier management for AI
Decommissioning AI tools
Cross-border AI risk
Preventing inadvertent AI data disclosure
AI on the board agenda
Shadow AI: finding the tools your people already use
AI incident response
People, skills and change in AI adoption
Showing 132 of 132 guides.
ISO 27001 certification cost (2026)
A transparent, line-by-line breakdown of what ISO 27001 really costs a UK/EU SME — registrar fees, internal effort, consultancy and tooling.
EU AI Act compliance guide for SMEs
Risk tiers, obligations, timelines and the documentation auditors will ask for — with Harvard-referenced sources throughout.
NIS2 Directive compliance guide
How Directive (EU) 2022/2555 changes cyber obligations for essential and important entities — scope, controls, reporting and penalties.
DORA compliance guide for financial entities
ICT risk management, incident reporting, third-party oversight and resilience testing under the Digital Operational Resilience Act.
ISO 27001 vs SOC 2: which to pick
An evidence-based comparison — scope, audit model, cost, buyer expectations and how to run both without doubling the work.
AI adoption: a risk-based approach
A practitioner's frame for adopting AI by inventory, classification, treatment and monitoring — not by accident.
The AI-assisted human
Michael McCarroll's sociotechnical model of person-plus-AI as the real unit of governance — drawing on Tavistock and actor-network theory.
Ongoing management of AI systems
Drift, evaluation, change control and the weekly/monthly/quarterly rhythm that keeps AI in production safe.
Supplier management for AI
The four-layer AI supply chain, an AI-specific due diligence addendum and the contract clauses that matter.
Decommissioning AI tools
Retiring an AI tool safely — data, embeddings, downstream consumers, credentials and the records you'll need years later.
Cross-border AI risk
Why a single AI call can cross three jurisdictions in a second, and how to govern the resulting transfer risk.
Preventing inadvertent AI data disclosure
Paste-and-prompt is the dominant leak pattern. A layered control set — technical, contractual and cultural — that actually works.
AI on the board agenda
Five questions, three artefacts and the difference between meaningful oversight and oversight theatre.
Shadow AI: finding the tools your people already use
Discovery, classification and the provision-and-onboard response that beats the block-and-police one.
AI incident response
Hallucination, leakage, bias, prompt injection and supplier-side change — and the four-stage playbook that adapts what you already have.
People, skills and change in AI adoption
Why the human side determines AI risk, and the literacy programme the EU AI Act now requires.
AI adoption in resource-constrained organisations
The staged pattern that produced ROI in twelve weeks inside a UK housing association — governance and workforce first, tooling last.
Action research for AI programmes
Plan, act, observe, reflect — the disciplined method that turns AI change into evidence you can defend to a board or an auditor.
The economic Turing test
When hiring managers consistently prefer the machine — the workforce and governance implications for knowledge work.
From Copilot pilot to agentic AI
The five gates that separate a safe agent programme from a headline incident, and the staged pattern that has produced evidence in practice.
The State of Risk Management in 2026
Why the spreadsheet era is finally ending — a four-stage maturity model, where most organisations actually sit, and what good looks like next.
Internal audit, CAPA and management review
How ISO clauses 9.2, 10.1/10.2 and 9.3 form a single loop — and how to run it without the spreadsheet stack that fails at surveillance.
The ISO 42001 AI risk management playbook
An AI-specific threat taxonomy, how to score AI risks when likelihood is unknowable, and how AIMS fits with ISO 27001 and the EU AI Act.
Modern information security risk management
Beyond the annual spreadsheet refresh — continuous risk, KRIs and KCIs, and why control-centric compliance suites miss the risk layer.
ISO 27001 vs SOC 2
Scope, audit process, costs and how to choose between the two most common infosec assurance programmes.
ISO 42001 vs NIST AI RMF
Certifiable AI management system vs voluntary risk framework — what each covers, how they differ, and how to run them together.
Enterprise risk management software
What ERM software actually does and how to evaluate a platform without a six-week procurement cycle.
Risk management software & platforms
A practical buyer's guide to risk management software, methodology and the features that matter.
ISO 27001 risk assessment methodology
The 5×5 likelihood × impact model, scoring tables and treatment workflow.
ISO 27001 risk treatment plan
The four Ts — Treat, Transfer, Tolerate, Terminate — and mapping risks to Annex A.
ISO 27001 third-party risk assessment
How to evaluate vendor risk, manage supply-chain security and record supplier risks in the register.
ISO 31000 risk management framework
Principles, framework and process for enterprise risk — without GRC bloat.
Risk management frameworks comparison
Compare ISO 31000, NIST SP 800-30, COSO ERM and COBIT to choose the right framework for your organisation.
ISO 9001 quality management system
Risk-based thinking, the PDCA cycle and the documents auditors actually ask for.
ISO 42001 AI management system
The first international AI management standard, mapped to the EU AI Act.
ISO 42001 certification readiness for AI startups
The 12–16 week path AI startups take to certify — and how it accelerates enterprise deals.
ISO 20000-1 IT service management
How the SMS differs from ITIL and what an accredited audit actually tests.
SOC 2 compliance
Trust Services Criteria, Type I vs Type II and a 90-day path to readiness.
GDPR compliance checklist
Lawful bases, data subject rights, DPIAs, breach notification and ROPAs.
PCI DSS compliance
v4.0, the right SAQ, the 12 requirements and scope-reduction moves.
Cyber Essentials certification
The five technical controls and the two-week path to certification.
Cyber Essentials Plus
What the audit actually tests and how to pass first time.
Trust as competitive advantage
Why trust — evidenced, not asserted — is the fastest-compounding B2B moat, and how to operationalise it.
Building buyer trust in procurement
How modern procurement really evaluates trust and how to put your firm inside the shortlist before the RFP is issued.
Trust signals that actually work
A practitioner's ranking of the badges, testimonials, artefacts and behaviours that measurably shift decisions.
Radical transparency as a growth strategy
Why publishing incidents, prices and mistakes wins share from competitors who still hide them.
Rebuilding trust after a breach
The disclosure, evidence and remediation playbook that turns incidents into commercial recovery.
Building customer trust in the age of AI
The new buyer questions on data handling, model choice and human oversight — and how to publish credible answers.
From claims to evidence
Convert every trust claim into a downloadable artefact — the biggest win-rate lever most B2B firms haven't pulled.
Compliance as trust currency
How compliance done well unlocks enterprise deals, faster procurement, better pricing and higher renewals.
Trust in remote-first teams
The operating patterns and rituals that hold distributed organisations together — and make trust visible to buyers.
Earning vendor trust through third-party risk transparency
Your customers inherit every risk from your suppliers — how to build a programme that reassures buyers as much as it protects you.
Brand trust and security
How marketing and security teams can compound each other into a durable commercial advantage.
How SMEs win enterprise trust
The plays small firms use to convert size from a disadvantage into a differentiator in enterprise procurement.
Measuring trust: metrics that matter to boards
The KPIs that turn trust into a boardroom conversation and connect security, sales and product.
Founder credibility and the trust premium
In evidence-driven markets, founder credibility is often the deciding trust asset. How to build and deploy it.
The long-term trust flywheel
Trust is not a campaign. Chained into a rhythm, artefacts become a flywheel that compounds into dominant advantage.
Writing an ISO 27001 Statement of Applicability that buyers respect
Learn how to transform your ISO 27001 Statement of Applicability from a compliance tick-box into a high-stakes sales tool that wins enterprise trust.
Building an ISO 27001 internal audit programme that finds real issues
Stop treating internal audits as a checkbox exercise. Learn how to build a rigorous ISO 27001 audit programme that surfaces risk and strengthens your security posture.
The ISO 27001 management review agenda that unlocks board sponsorship
Stop treating the ISO 27001 Management Review as a checkbox exercise. Learn how to structure your agenda to secure budget, visibility, and genuine board-level commitment.
Defining ISO 27001 scope: the decision that determines audit cost
Defining your ISO 27001 scope is the single most important decision in your certification journey. Learn how to map boundaries that satisfy auditors without inflating costs.
ISO 27001 continual improvement: turning findings into value
Stop treating ISO 27001 non-conformities as failures. Learn how to transform audit findings into a high-performance security engine that drives revenue and operational resilience.
ISO 9001 context of the organization: the clause most SMEs get wrong
Clause 4 isn't just paperwork; it's the foundation of your QMS. Stop treating 'Context' as a tick-box exercise and start using it to drive genuine business strategy.
The ISO 9001 process approach — beyond the flowchart
Stop treating ISO 9001 processes like static diagrams. Michael McCarroll explains how to build a dynamic, performance-led system that scales with your business.
Measuring customer satisfaction for ISO 9001 (that actually informs strategy)
Stop treating ISO 9001 customer satisfaction as a vanity metric. Learn how to transform Clause 9.1.2 into a strategic engine for retention and growth.
ISO 9001 nonconformity and corrective action done well
Ditch the administrative box-ticking. Learn how to transform ISO 9001 nonconformity management into a genuine competitive advantage that drives operational excellence.
An ISO 42001 AI policy that boards and buyers both approve
Ditch the generic AI ethics statements. Learn how to draft a pragmatic ISO 42001 policy that satisfies rigorous board oversight and complex enterprise procurement demands.
AI impact assessments under ISO 42001: a working template
Master the Artificial Intelligence Impact Assessment (AIIA) under ISO 42001 with a practical, evidence-based framework for senior GRC practitioners and founders.
ISO 42001 vs the EU AI Act: mapping controls to obligations
A practical guide for security leaders to align ISO 42001 certification and EU AI Act compliance, avoiding redundant effort and ensuring market access.
Model lifecycle governance under ISO 42001
Mastering the AI model lifecycle is the core of ISO 42001. Learn how to govern AI development from data sourcing to decommissioning without stifling innovation.
Building a service catalogue that satisfies ISO 20000-1 and customers
Master ISO 20000-1 service catalogues: move beyond simple lists to technical and business views that satisfy auditors and drive commercial value.
ISO 20000-1 change management without ticket sprawl
Modern change control in ISO 20000-1 doesn't require bureaucratic bloat; it requires smart automation and risk-based decision making to maintain service excellence.
ISO 22301 business continuity: a plain-English implementation guide
Stop treating business continuity as a paper exercise. Learn how to implement ISO 22301 using a practical, impact-first approach that protects your reputation and revenue.
ISO 22301 tabletop exercises that actually build resilience
Move beyond tick-box compliance with high-impact ISO 22301 tabletop exercises that stress-test your business continuity plans and prove resilience to stakeholders.
ISO 27701: adding a privacy layer to your ISMS
Ditch the confusion between GDPR and ISO 27001. ISO 27701 provides the missing structural link to turn privacy from a legal headache into a scalable operational asset.
ISO 27701 for controllers and processors: what changes
Stop treating privacy as a sidecar to security. ISO 27701 extends ISO 27001 by forcing specific accountabilities on controllers and processors to bridge the gap to GDPR.
A 90-day SOC 2 readiness plan that survives contact with the auditor
Stop treating SOC 2 as a tick-box exercise. This 90-day readiness plan focuses on operational reality, ensuring your controls actually work when the auditor arrives.
SOC 2 common criteria explained without the jargon
A practical guide for founders and security leads on decoding the SOC 2 Common Criteria to build a defensible, audit-ready security posture without the technical fluff.
SOC 2 evidence collection: from screenshots to continuous assurance
Stop the screenshot madness. Move from manual SOC 2 evidence gathering to a continuous assurance model that scales with your engineering team and builds real buyer trust.
GDPR data mapping and ROPA: the artefact that unblocks enterprise deals
Stop treating the Record of Processing Activities (ROPA) as a compliance chore. It is the single most important document for clearing enterprise vendor security assessments.
GDPR DPIAs in practice: a template you will actually use
Cut through the bureaucratic fog of GDPR Data Protection Impact Assessments with a pragmatic, risk-based approach designed for fast-moving product teams.
GDPR international data transfers after Schrems II
Navigating the complexities of international data transfers post-Schrems II requires more than just signing a contract; it demands rigorous impact assessments and monitoring.
Cyber Essentials: the five failure points that cost first-time applicants
Avoid the common pitfalls that lead to Cyber Essentials failure. Learm how to master the five key technical controls and secure your certification on the first attempt.
What to expect on Cyber Essentials Plus audit day
Forget the marketing jargon; here is the blunt reality of what happens when a Cyber Essentials Plus assessor audits your infrastructure and how to pass without breaking a sweat.
PCI DSS 4.0 transition: the changes that matter to SMEs
Forget the 360-page PDF; the transition to PCI DSS 4.0 is about shifting from 'point-in-time' compliance to continuous evidence. Here is how SMEs survive the March 2025 deadline.
PCI DSS scope reduction: proven moves to shrink the audit
Stop treating your entire network like a cash register. Learn how to aggressively descoped your PCI DSS environment to reduce audit costs and security risks.
The honest buyer's guide to GRC tools in 2026
An uncompromising guide to navigating the 2026 GRC software landscape, focusing on evidence over automation and trust over compliance badges.
The first 90 days of a GRC programme: what to build, defer and kill
Stop treating GRC as a paperwork exercise. Learn how to architect a risk-first programme in 90 days that actually protects the business and closes deals.
Policy management lifecycle: from draft to attested to retired
Stop treating policies as static PDF documents. Learn to manage the full GRC lifecycle to ensure your controls remain auditable, enforceable, and actually useful.
Control testing that doesn't waste anyone's time
Stop treats control testing as a box-ticking chore. Learn how to build a lean, evidence-first testing programme that satisfies ISO 27001 auditors without burning out your team.
Building a third-party risk management programme buyers trust
Stop wasting time on security questionnaires. Build a defensible Third-Party Risk Management (TPRM) programme that proves your maturity to enterprise buyers.
The security questionnaire response playbook that halves turnaround
Stop wasting engineering time on repeat security queries. Learn how a structured ISO 27001-aligned knowledge base cuts response times by 50% and accelerates your deal cycle.
Quantitative risk analysis for SMEs: FAIR without the PhD
Ditch the 'High-Medium-Low' guesswork. Learn how to apply formal quantitative risk analysis to your SME using a simplified FAIR framework that board members actually value.
Key risk indicators that boards actually use
Stop reporting 'missing patches' to the board. Learn how to build Key Risk Indicators (KRIs) that link security posture to commercial stability and board-level decision-making.
Risk appetite statements that survive the next crisis
Stop treating risk appetite as a compliance tick-box. Learn how to craft quantitative, resilient statements that drive growth while keeping your ISO 27001 posture intact.
Operational resilience beyond business continuity plans
Ditch the dust-gathering BCP. Learn why true operational resilience requires a shift from 'recovery' to 'continuity' through evidence-based risk management and ISO 22301 principles.
Scenario planning for trust-eroding events
Stop waiting for the breach. Learn how to use proactive scenario planning to defend your brand’s reputation and satisfy ISO 27001:2022 risk requirements.
Designing a trust centre that closes deals
Learn how to transform your security posture from a cost centre into a sales engine by building a high-performance Trust Centre that accelerates procurement.
Public status pages: turning outages into trust deposits
Stop hiding your outages. A well-managed public status page is a sophisticated GRC tool that converts system downtime into measurable market credibility and customer retention.
Proof-driven marketing: replacing adjectives with artefacts
Stop telling customers you are secure. Start proving it. Learn how to transform your GRC artefacts into your most powerful sales assets.
Customer onboarding as a trust-building programme
Transform your onboarding process from a legal hurdle into a strategic engine for customer trust and accelerated revenue.
The executive trust narrative every founder should be able to deliver
Master the executive trust narrative to bridge the gap between technical security and board-level commercial assurance.
Trust for SaaS startups selling upmarket
Winning enterprise deals requires more than a good product; it requires a 'Trust Stack' that satisfies cynical procurement teams and risk-averse CISOs.
Trust in fintech: passing bank due diligence at Series A speed
Master the brutal world of Tier-1 bank due diligence by shifting from reactive compliance to a proactive trust posture that accelerates your Series A growth.
Trust in healthtech: DTAC, DCB0129 and buyer confidence
Master the NHS trust landscape by aligning DTAC, DCB0129, and ISO 27001 to secure contracts and demonstrate clinical safety.
Trust in legaltech: confidentiality as commercial edge
Discover why robust information security is the most effective sales tool for modern legaltech firms and how to leverage ISO 27001 to close larger enterprise deals faster.
Trust for public sector suppliers: winning framework work
A practitioner's guide to navigating public sector procurement by leveraging ISO standards to bypass hurdles and win framework spots.
ISO 27001 for cyber security firms: certifying the shoemaker
Cyber consultancies, MSSPs and pentest firms are the group most likely to get away with 'trust us, we're the security people' — and the group where a buyer's compliance question lands hardest. This...
ISO 42001 for cyber security firms: governing the AI you sell and use
Cyber firms sit in an awkward spot with AI: you sell AI-augmented services, you use AI in the SOC, and your clients now ask about both in the same questionnaire. ISO 42001 is the cleanest way to an...
SOC 2 for cyber security firms: when to add it to ISO 27001
If half your pipeline is US-headquartered, ISO 27001 alone will start losing deals. A pragmatic view on when a cyber firm should add SOC 2, and how to run both without duplicating effort.
Risk management for cyber security firms: eating your own dog food
Cyber firms give risk advice all day and often run their internal risk register in a spreadsheet nobody has opened in six months. Here is what a credible risk programme actually looks like inside a...
ISO 9001 for cyber security firms: quality as competitive advantage
Cyber engagements are famously variable in quality. ISO 9001 is the underrated standard that formalises how a cyber firm scopes, delivers and improves — and it is often the differentiator in enterp...
ISO 20000-1 for cyber security firms delivering managed detection
MDR, managed SIEM and managed EDR are services. ISO 20000-1 formalises how you run them — the standard behind the phrase 'we operate a mature service management system' on enterprise RFPs.
ISO 27001 for managed service providers: the ISMS your clients inherit
When an MSP gets breached, every client is in scope. ISO 27001 is now table stakes for winning mid-market and enterprise MSP work — here's how a 20–200 person MSP certifies without a full-time comp...
ISO 20000-1 for MSPs: the service management standard buyers now ask for
ITIL is a body of knowledge. ISO 20000-1 is the certifiable proof you actually run services the way you claim to. For MSPs bidding beyond SME accounts, it is fast becoming the deciding standard.
ISO 9001 for MSPs: managing quality across a multi-tenant estate
Every MSP swears their service is consistent. Every client eventually experiences that it isn't. ISO 9001 is the standard that closes the gap between the story and the reality across a multi-tenant...
ISO 42001 for MSPs: governing AI copilots inside client environments
AIOps, ticket triage copilots and AI-assisted patching are now everywhere in the MSP stack — often without a governing standard on top. ISO 42001 gives MSPs an answer to the 'what AI are you runnin...
Risk management for MSPs: your risk is every client's risk
One credential compromise, one misconfigured backup, one supplier failure — inside an MSP each of those cascades across every tenant. A grown-up risk programme is the difference between a bad week...
Multi-tenant compliance for MSPs: one ISMS, many clients
MSPs live at the intersection of one internal ISMS and dozens of client environments each with their own regulatory obligations. Here is the operating model that keeps one certifiable ISMS while ge...
ISO 27001 for B2B SaaS: the standard your enterprise pipeline needs
Beyond about £5m ARR, B2B SaaS deals stop closing without an infosec assurance certificate. ISO 27001 is the most portable answer — here is the pragmatic path for a 20–200 person SaaS without a ded...
ISO 42001 for B2B SaaS shipping AI features
If your product includes an LLM feature, buyer questionnaires now include an AI section. ISO 42001 is the standard that lets you answer it credibly, and — crucially — differentiates you from every...
ISO 9001 for B2B SaaS: the underrated quality standard for scale-ups
Every SaaS founder talks about quality. ISO 9001 is the standard that turns 'we care about quality' into a system that survives founder handover, VP transitions and cross-region expansion.
ISO 20000-1 for B2B SaaS: when service management becomes the standard buyers ask for
For SaaS firms selling into regulated industries, financial services and public sector, ISO 20000-1 is the standard that formalises what your ops team already half-does. It's simpler than SREs fear...
Risk management for B2B SaaS: from spreadsheet to boardroom
SaaS risk is unusual: dependencies you don't own, customers who inherit your posture, and a founder who is often the ultimate risk owner. Here is a risk model that scales from Series A through Seri...
Answering SaaS security questionnaires without a full-time compliance manager
The single biggest hidden cost in mid-market B2B SaaS is the founder or CTO spending days on questionnaires. A repeatable answer bank, evidence library and trust centre eliminate almost all of it.
The SaaS trust centre that measurably shortens sales cycles
A trust centre isn't a marketing page — it's a procurement tool. The right structure turns week-long security reviews into a self-serve pass and moves deals into legal review faster.
ISO 27001 for manufacturing: OT, IT and the standard buyers now demand
UK and EU manufacturers now face infosec assurance questions from every tier-one customer. ISO 27001 is the answer that scopes across corporate IT and shop-floor OT without becoming a two-year prog...
ISO 9001 for modern manufacturers: beyond the audit binder
Most UK manufacturers have held ISO 9001 for decades and lost the plot along the way. Here is what a modern, useful ISO 9001 system looks like in a 20–200 person manufacturer — one that survives di...
ISO 42001 for manufacturing: governing AI on the shop floor
Predictive maintenance, visual inspection and demand forecasting are now AI-powered in most modern manufacturers. ISO 42001 is the standard that governs them the way ISO 9001 governs quality.
ISO 20000-1 for manufacturing IT: services underneath a physical business
Manufacturing IT teams run ERPs, MES, OT bridges and site services that the shop floor cannot run without. ISO 20000-1 formalises how that IT is delivered — a natural companion to a mature ISO 9001...
Risk management for manufacturers: from HSE clipboard to enterprise register
Most UK manufacturers manage safety risk brilliantly and enterprise risk badly. Here is the operating model that unifies HSE, quality, supply chain and cyber risk into one live register a board can...
Cyber risk for connected manufacturing: IIoT, OT and the ransomware target on your back
Connected manufacturing has quietly become one of the most targeted sectors for ransomware in the UK and EU. Here is the cyber risk view that maps genuine OT/IT exposure and the ISO 27001-anchored...
Have a question we haven't covered?
Email hello@iso-standard.app — a practitioner will reply within one business day. No sales script.