The ISO compliance workspace consultants run their whole client book from

Stop rebuilding the same spreadsheet stack for every engagement. One workspace per client, the same shared control catalogue and evidence model across all of them, white-label exports in your branding, and a clean handover when the client takes the ISMS in-house — across ISO 27001, ISO 42001, ISO 9001, ISO 20000-1 and SOC 2.

Where consultancies lose margin

Your methodology is good. Delivering it through bespoke spreadsheets is what kills utilisation.

  • Every client gets a slightly different register, SoA and policy pack — so nothing is reusable and quality depends on who staffed it.
  • Client evidence lives in their Drive, their email and your laptop; handover is a week of tidying you can't bill.
  • You can't see, across the book, which clients are drifting toward a failed surveillance audit until it's late.
  • Per-client licences of enterprise GRC destroy the economics of a fixed-fee engagement.
Product walkthrough

One methodology, every client

Spin up a client workspace from your template, run the engagement, and hand it over — the same screens, exports and cadence every time.

  1. 1
    Workspace switcher

    Every client is an isolated workspace with its own data, roles and audit trail. Switch without logging out.

  2. 2
    Shared control catalogue

    ISO 27001 Annex A, ISO 42001, ISO 9001, ISO 20000-1 and SOC 2 pre-loaded, so your methodology maps once and applies everywhere.

  3. 3
    Risk register & treatment

    The same 5×5 model and four-Ts treatment across the book, so a reviewer can read any client's register instantly.

  4. 4
    Evidence & crosswalk

    One evidence base per client, mapped across frameworks — collect an access review once, evidence it in three standards.

  5. 5
    White-label policy & report exports

    Branded PDFs with your logo, version, approver and effective date — deliverables clients recognise as yours.

  6. 6
    Roles, invites and handover

    Give the client member access during delivery, then transfer ownership. Nothing to migrate, nothing lost.

Spreadsheets vs ISO-STANDARD.app

The jobSpreadsheets & shared driveISO-STANDARD.app
Starting an engagementCopy last client's workbook, strip their data, hope nothing leaks.New workspace from your standard catalogue in minutes, clean by construction.
Consistency across consultantsEvery associate has their own template and scoring habits.One model, one catalogue, one export format across the whole book.
Portfolio visibilityAsk each consultant for a status update.Control health, overdue actions and audit dates visible per client.
Client confidentialityClient data mixed across drives and mailboxes.Hard tenant isolation, per-client roles, MFA and append-only audit log.
Handover / renewalA zip file and a call.Transfer the live workspace; the client keeps running your methodology — and keeps paying for it.
Free readiness assessment

Free assessment — score one live client, then decide

Take a real engagement, load its controls and evidence into a workspace, and see the gap score and deliverables you'd hand the client. If it doesn't beat your spreadsheet pack, you've lost an afternoon.

  • Framework coverage per client and per standard
  • Reusable evidence you're currently collecting twice
  • Deliverable pack: SoA, risk register, policies, management review
  • Effort saved per engagement, in hours

Instant download, no sales call. We reply within one business day.

What it costs

Multi-tenant plans are priced per practice, not per client licence, so a fixed-fee engagement stays profitable.

Multi-Tenant Team
£599/mo

Up to 5 client workspaces and 25 users, with AI ‘Fix this’, Microsoft and Jira integrations.

Multi-Tenant Business
£1,499/mo

Up to 25 client workspaces and 100 users, with higher automation limits.

Multi-Tenant Enterprise
£2,999/mo

Unlimited workspaces, SSO and the full integration set for larger practices.

Full feature-by-feature breakdown on the pricing page. No sales call required to start.

Working a single client? Single-organisation plans start at £79/mo.

MM
Built by Michael McCarroll
25+ years · IT governance · Information security · AI

I've been the consultant with twelve client spreadsheets and the practice lead trying to review them. This is the tool I wanted: one methodology, isolated client data, deliverables that look like yours, and a handover that takes an hour instead of a week.

Read the founder story

Where to go next

See the consultancy and advisory services, the full GRC workspace, or the online ISO consultant offer.

Answers buyers, procurement and auditors want

Is client data actually isolated?+

Yes. Each client is a separate workspace with row-level security, its own membership and roles, MFA enforcement and an append-only audit log. Consultants only see the workspaces they're a member of.

Can deliverables carry our branding?+

Yes — policy and report PDFs export with your logo and document control metadata (version, approver, effective date).

What happens when the client takes it in-house?+

Transfer ownership of the workspace to the client. They continue on their own subscription with all history intact; you keep the methodology.

Do you support more than ISO 27001?+

ISO 27001, ISO 42001, ISO 9001, ISO 20000-1, SOC 2, Cyber Essentials and GDPR share one register, one control catalogue and one evidence base — with crosswalk mapping between them.

Run your next engagement here

Set up a client workspace, import their register, and produce the deliverable pack in your branding — before you commit the practice.

Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.