Risk assessments buyers trust — not spreadsheets that sink deals.

Enterprise procurement wants to see how you rank, treat and monitor risk. A version-controlled spreadsheet won't cut it. ISO-STANDARD.app is the SME- and consultant-friendly risk assessment platform with a 5×5 register, ISO 27001 Annex A control mapping, treatment workflow and audit-ready exports pre-wired — built by a founder with 25+ years of IT governance and information security.

Why most risk assessment tools disappoint

Teams searching for risk assessment software usually land in one of two places. Spreadsheets — fast to start, impossible to audit once you cross a dozen risks and two reviewers. Or enterprise GRC suites — six-figure contracts, a four-month implementation, and a tool where the risk register is a tab inside a tab.

Neither matches what ISO 27001, ISO 27005 or ISO 31000 actually expect: identify the risk, score it, pick a treatment, map it to a control, document the decision, review it on a cadence. That is a workflow, not a content-management system.

What ISO-STANDARD.app gives you

5×5 risk register

Inherent and residual scoring, owner, treatment decision (the four Ts), target residual and review date — in one editable view that exports cleanly.

Annex A:2022 control mapping

Every risk links to the controls that treat it. Statement of Applicability assembles automatically from your decisions.

Treatment workflow

Treatment actions, owners, due dates and status tracked alongside the risk — not in a separate Trello board nobody opens.

Live heatmap & reports

5×5 heatmap, treatment status, by-category and by-owner views. Configurable report views you can save and share.

Risk → control → policy traceability

Auditors stop asking "where is the evidence?" — every risk is one click from its control and its policy.

Audit-ready exports

Management-review pack (ISO 27001 clause 9.3), risk register CSV, full SoA — branded PDFs ready for the auditor.

Full audit trail

Every change to every risk is logged with who, when and what. Required for Growth-tier plans and above.

Multi-framework

Ships with ISO 27001 Annex A, ISO 42001, ISO 20000-1, ISO 31000 and ISO 9001 control catalogues — adopt one or several.

Who it's for

SaaS teams chasing ISO 27001 certification

Pain: Procurement is gating an enterprise deal on a certificate and the CTO is the de facto ISMS manager.

With ISO-STANDARD.app: A 60–90 day path to a Stage 2 audit with the register, SoA, treatment plan and policies the auditor expects already in place.

Operations leaders moving off spreadsheets

Pain: Three risk spreadsheets, two control logs, none of them reconcile and nobody owns the master copy.

With ISO-STANDARD.app: One canonical workspace where risks, controls, treatments and evidence are linked — drift becomes visible instead of hidden.

Consultancies running multiple client ISMSs

Pain: Every client gets a bespoke spreadsheet stack; handovers are painful and audits look different every time.

With ISO-STANDARD.app: A repeatable workspace per client with the same exports, the same catalogue and the same review cadence.

See the competitive landscape

We track the risk assessment software category openly. See who currently ranks for "risk assessment software", our side-by-side comparison vs Vanta, SafetyCulture, Hyperproof and Drata, and the most-asked buyer questions.

Start your risk register today

Spin up a free workspace with the 5×5 register, Annex A controls and the SoA already wired together. Bring an auditor when you're ready.

Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the Lovable AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.