How to use ISO-STANDARD.app

Step-by-step, screenshot-first, written for humans.

Every guide maps a workflow in ISO-STANDARD.app to what corporate buyers and auditors actually ask for — so you close deals faster and pass audits cleaner.

Core workflows

Risk, controls, evidence, audits — the day-to-day of an ISMS.

8 min read

Build a defensible risk register

Capture risks, score them consistently, treat them, and export a register your auditor and your biggest customer will both accept.

Open guide
9 min read

Manage controls and your Statement of Applicability

Turn ISO 27001 Annex A (and any framework) into a living SoA — with owners, evidence and audit history attached to every control.

Open guide
6 min read

Keep a live inventory of information assets

Track systems, data stores, devices and third-party services in one place — with owner, sensitivity and linked risks and controls.

Open guide
7 min read

Author, approve and distribute policies

Draft policies in the editor, run an approval workflow, distribute for read-and-acknowledge, and prove it — all inside the app.

Open guide
6 min read

Use the Evidence Vault as your single source of truth

Upload once, tag once, reuse across risks, controls, audits, Trust Center and buyer questionnaires. Never chase a screenshot again.

Open guide
9 min read

Plan and run an internal audit end-to-end

Schedule the audit, pick the scope, gather evidence against a checklist, capture findings, and raise corrective actions — all in one place.

Open guide
6 min read

Run corrective actions (CAPA) that actually close

Turn findings into owned, dated actions with root-cause analysis, evidence of closure and a management-review-ready report.

Open guide
6 min read

Run a management review that satisfies clause 9.3

Gather every ISO 9.3 input automatically, capture decisions and actions, and produce a signed minutes PDF in one session.

Open guide

Buyer trust

Trust Center, questionnaires and evidence sharing — where deals are won.

Standards playbooks

ISO 27001, 9001, 42001, SOC 2 and GDPR — from zero to audit-ready.

Admin & org

Workspaces, roles, MFA and branding.

Not sure where to start?

Most teams begin with the ISO 27001 playbook, then plug in Trust Center so buyers can self-serve.