One compliance workspace, every standard your buyers ask about.

ISO 27001, 9001, 42001, 20000-1, 31000 — each one is a growth lever. Together they're a trust engine. ISO-STANDARD.app is the SME- and consultant-priced platform that runs them all as one programme, so the next buyer questionnaire, tender or renewal is a link — not a scramble. Built by a founder with 25+ years across IT governance, information security and AI.

The problem with one-tool-per-standard

Most companies certified against more than one ISO standard end up running parallel universes. A risk register for 27001. A separate risk register for 9001 (or worse, nothing). A document library here, a controls log there. The same access control gets documented three times in three slightly different ways — and three different auditors find three different gaps.

This is not a tooling fashion problem. It is a real cost. Duplicated evidence, conflicting ownership, and management reviews that take a week to assemble because nothing aggregates. By the time the third surveillance audit lands, the team is doing compliance theatre instead of running an integrated management system.

An integrated ISO compliance platform

ISO-STANDARD.app is built on a single shared data model — risks, controls, processes, policies, suppliers, evidence — and overlays each standard as a view onto that model. A control like "logical access" is one record, mapped to Annex A 8.3 for 27001, to your ISO 9001 process owner, and to the relevant ISO 42001 AIMS control. Update it once, everywhere agrees.

The same approach runs through the policy library, the supplier register and the management review pack. The auditor sees one consistent ISMS / QMS / AIMS and your team stops re-typing the same evidence.

What's in the box

Multi-standard workspace

ISO 27001, 9001, 42001, 20000-1, 31000 — toggle the standards you need. Add more without re-implementing.

Shared controls catalogue

One control record, mapped to every standard that calls for it. Edit once.

Unified policy library

One acceptable use policy, one access control policy, one change policy — referenced by every standard that needs them.

Risk → control → evidence traceability

Every risk linked to the controls that treat it; every control linked to the evidence that proves it works. Across all standards.

Supplier & third-party register

Vendors assessed once, referenced by every framework. The procurement team stops being asked the same question by three different teams.

Management review dashboard

One pack covering every standard you certify — KPIs, audit results, NCs, risks, opportunities — ready for the board meeting.

Who it's for

Companies running ISO 27001 + ISO 9001

Pain: Two registers, two doc libraries, two auditors asking the same access-control question.

With ISO-STANDARD.app: One shared control catalogue and policy library — both auditors see the same evidence.

AI-first companies adding ISO 42001 to existing ISO 27001

Pain: The AIMS feels like a separate project bolted onto the ISMS.

With ISO-STANDARD.app: ISO 42001 Annex A controls re-use ISO 27001 evidence wherever they overlap. One workspace, two scopes.

Group functions standardising across business units

Pain: Each subsidiary runs compliance their own way; rolling it up takes weeks.

With ISO-STANDARD.app: Group-level dashboards across child workspaces — same KPIs, comparable data.

Why ISO-STANDARD.app

  • Integrated data model — risks, controls, policies and evidence are first-class objects shared across standards.
  • Add standards without re-implementation — toggle ISO 42001 onto an existing ISO 27001 workspace in minutes.
  • Audit-ready exports per standard — SoA, AIMS SoA, QMS document register, management review pack.
  • Transparent monthly pricing — no five-figure platform fee, no consultancy bundle.

Run every ISO standard from one workspace

Start free with ISO 27001 enabled; add ISO 9001, 42001 or 20000-1 with one click. The shared controls, policies and risks come with you.

Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the Lovable AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.