Policies that are owned, current and actually read

Every standard asks for documented information under control. In practice that means someone owns each policy, it has been approved, it is the current version, the people it applies to have acknowledged it, and it connects to the controls it governs.

The failure mode auditors see most often

A folder of well-written policies, approved two years ago, referencing a job title nobody holds, acknowledged by half the people it applies to, and disconnected from the controls it describes. The words are fine. The governance around them is not — and that is what gets written up as a nonconformity.

What the platform does

Guided drafting with AI assistance

Plain-English prompts explain what each section is asking for and why an auditor wants it, then draft wording you edit and approve.

Versioning and approval history

Every change is versioned with who approved it and when. Superseded versions stay available as evidence.

Owners and review intervals

A named owner and a review date on every document, with reminders before it lapses.

Acknowledgement campaigns

Issue a policy to the people it applies to, chase non-responders automatically, and keep the timestamped record.

Linked to controls and standards

Each policy points at the controls it governs and the clauses it satisfies, so audit scope is obvious.

Audit-readiness checks

Gaps, unapproved drafts, overdue reviews and unacknowledged policies are surfaced before an auditor finds them.

Where policies sit in the cycle

Policies describe intent; controls deliver it. Policy governance links back to risks, controls and evidence and forward to internal audit, which tests whether the policy is being followed rather than whether it exists.

Related: policy attestations · the policy management lifecycle guide

Answers buyers, procurement and auditors want

Is this just a document store?+

No. A document store holds files. Policy governance holds ownership, approval, version history, review dates, acknowledgement records and the link from each policy to the controls and standards it supports.

How does AI-assisted drafting work?+

Guided completion asks plain-English questions about how your organisation actually works, explains why an auditor asks for each answer, and drafts the wording. A human reviews and approves before anything is published.

How do we prove staff have read a policy?+

Policies are issued for acknowledgement to named people, chased automatically, and recorded with a timestamp — which is the evidence an auditor asks for.

Can we keep our own branding?+

Yes. Published policy documents and PDF exports carry your workspace branding.

What happens at review time?+

Each policy carries an owner and a review interval. When a review falls due the owner is reminded, the change is versioned, and the previous version stays in history.

See how your existing risks, controls and evidence could become one integrated management system

Bring your current policy set and see what is out of date, unowned or unacknowledged in a single pass.

Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.