The whole management system, in one workspace

Every part of the platform serves one operating cycle: Risk → Control → Owner → Evidence → Audit → Action → Review → Assurance. Here is what each stage does and where to read more.

The operating cycle

Stage 1

Risk

What could stop you delivering, protecting or complying — scored, owned and reviewed on a schedule.

Risks, controls and evidence
Stage 2

Control

What you do about it, mapped to every clause and Annex A control it satisfies across the four standards.

Integrated management system
Stage 3

Owner

A named person accountable for each control and action, with due dates and email reminders.

Policies and document governance
Stage 4

Evidence

Proof the control operated, dated so staleness is visible — collected manually or automatically from connected systems.

Evidence vault
Stage 5

Audit

Internal audit programmes that test whether controls actually worked, with findings recorded against the control.

Internal audit
Stage 6

Action

Nonconformities and corrective actions with root cause, owner, due date and evidence of closure.

Corrective actions
Stage 7

Review

Management review built from live register data rather than a slide pack assembled the night before.

Management review
Stage 8

Assurance

The same records answer buyer questionnaires, populate a Trust Centre and support third-party risk assessments.

Buyer assurance

What else comes with it

Who it is built for

UK technology companies, SaaS businesses, managed service providers and technology-enabled professional-services firms, typically 10–250 people — plus the ISO consultants and advisers who run several client workspaces at once.

Boundaries we keep to

iso-standard.app is not a certification body, a penetration-testing provider or a vulnerability scanner. Certification is awarded independently by an accredited certification body following its own audit. AI drafts and suggestions always require a human to review and approve before they become part of your management system.

See how your existing risks, controls and evidence could become one integrated management system

A short walkthrough with a practitioner, using your current material rather than a demo dataset.

Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.