The three records everything else depends on
A risk without a control is a worry. A control without an owner is a hope. A control without evidence is an assertion. This is where the three are held together — and where every audit, review and buyer questionnaire draws its answers from.
One register, not one per standard
Most organisations do not have a risk problem; they have a traceability problem. The risks are known. What is missing is the line from a risk, to the control that addresses it, to the person accountable, to dated proof that it actually operated. Break that line and every downstream activity — audit, corrective action, management review, customer assurance — becomes manual work.
How the record is built
Risks with treatment, not just scores
Controls mapped across standards
Named owners and due dates
Evidence with a freshness date
Linked assets, systems and suppliers
Health monitoring over time
The artefacts this register produces
Every artifact below is generated inside the workspace, versioned, timestamped and shareable via a signed link — no last-minute PDF assembly, no "wait, which version did I send them?"
Where it goes next
The register feeds the rest of the cycle: internal audits test it, corrective actions fix what fails, management review reads it, and buyer assurance answers customers from it.
Answers buyers, procurement and auditors want
What makes this different from a risk register in a spreadsheet?+
A spreadsheet holds the words. It cannot tell you whether a control operated last month, who owns it, which standards depend on it, or whether the evidence has gone stale. Those links are the point of the register here.
How is evidence kept current?+
Every piece of evidence carries a date and a review interval, so staleness is visible rather than discovered during an audit. Where a system is connected, configuration signals refresh automatically on a schedule.
Can one control satisfy several standards?+
Yes, and it should. A single access-review control can map to ISO/IEC 27001 Annex A, an ISO/IEC 20000-1 requirement and an ISO 9001 clause at once. You maintain it once and evidence it once.
How are risks scored?+
Likelihood and impact with a configurable scale, producing an inherent and residual position, a heatmap view and a treatment plan with owners and dates.
What happens when a control fails?+
The failure is explained in plain English, a prioritised remediation plan is produced, an owner and due date can be assigned, and the action can be pushed into your service desk if one is connected.
See how your existing risks, controls and evidence could become one integrated management system
Import what you have today and see the gaps, the duplicates and the unowned controls in one view.
Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.