Step-by-step, screenshot-first, written for humans.
Every guide maps a workflow in ISO-STANDARD.app to what corporate buyers and auditors actually ask for — so you close deals faster and pass audits cleaner.
Core workflows
Risk, controls, evidence, audits — the day-to-day of an ISMS.
Build a defensible risk register
Capture risks, score them consistently, treat them, and export a register your auditor and your biggest customer will both accept.
Manage controls and your Statement of Applicability
Turn ISO 27001 Annex A (and any framework) into a living SoA — with owners, evidence and audit history attached to every control.
Keep a live inventory of information assets
Track systems, data stores, devices and third-party services in one place — with owner, sensitivity and linked risks and controls.
Author, approve and distribute policies
Draft policies in the editor, run an approval workflow, distribute for read-and-acknowledge, and prove it — all inside the app.
Use the Evidence Vault as your single source of truth
Upload once, tag once, reuse across risks, controls, audits, Trust Center and buyer questionnaires. Never chase a screenshot again.
Plan and run an internal audit end-to-end
Schedule the audit, pick the scope, gather evidence against a checklist, capture findings, and raise corrective actions — all in one place.
Run corrective actions (CAPA) that actually close
Turn findings into owned, dated actions with root-cause analysis, evidence of closure and a management-review-ready report.
Run a management review that satisfies clause 9.3
Gather every ISO 9.3 input automatically, capture decisions and actions, and produce a signed minutes PDF in one session.
Buyer trust
Trust Center, questionnaires and evidence sharing — where deals are won.
Launch a Trust Center your buyers can self-serve
Publish live security posture — certifications, policies, subprocessors, evidence — so buyers can answer their own questions before yours pile up.
Answer SIG-Lite, CAIQ and custom questionnaires in hours
Use your evidence vault plus an AI-assisted answer library to knock out a 250-line questionnaire in an afternoon.
Share evidence packs with buyers without email chains
Bundle exactly what a specific buyer needs — with expiry, watermark and access log — instead of sending files over email.
Standards playbooks
ISO 27001, 9001, 42001, SOC 2 and GDPR — from zero to audit-ready.
ISO 27001 playbook: from zero to certification-ready
The 12-week path an experienced ISO 27001 lead implementer would follow inside ISO-STANDARD.app — plus the artifacts your certification auditor will ask for.
ISO 9001 playbook: quality that wins tenders
Use the same workspace as your ISMS. Quality objectives, process risks, corrective actions and management review — all mapped.
ISO 42001 playbook: govern AI without slowing it down
AI use-cases, model risks, human oversight, data disclosure controls and impact assessments — mapped to Annex A controls of ISO 42001.
SOC 2 playbook: readiness in one workspace
Reuse your ISO 27001 controls for SOC 2 CC via automatic crosswalk. Add the SOC 2 specifics (change management, monitoring) and you're audit-ready.
GDPR playbook: build the RoPA buyers will accept
Record of Processing Activities, subprocessor list, DSAR workflow, breach playbook — all inside the same workspace as your ISMS.
Admin & org
Workspaces, roles, MFA and branding.
Set up workspaces, seats and consultant multi-tenancy
Run one workspace per client (consultants) or per business (in-house) — with shared evidence libraries and clean segregation.
Roles, MFA and access control
Enforce MFA for every user, run role-based access and prove it to buyers with a live report.
Brand your workspace and control notifications
Put your logo on every export and policy, and dial notifications so the right people get the right emails.
Not sure where to start?
Most teams begin with the ISO 27001 playbook, then plug in Trust Center so buyers can self-serve.
