ISO 27001 Audit Room
The ISO 27001 Audit Room is the complete implementation workspace. It already includes the 40+ item Stage 1 and Stage 2 readiness checklist, risk register, evidence tracker, owners and due dates, all 11 AI tools, the AI Assistant, and Excel and Word exports - everything an auditor will ask for, in one place.

What's included in Audit Room
Audit Room is the complete ISO 27001 implementation workspace. Everything below is already included - no add-ons, no separate tools to wire up.
Stage 1 + Stage 2 readiness checklist
40+ curated items mapped to ISO 27001 clauses and Annex A controls.
Risk register
Identify, score, and treat risks - linked to controls and owners.
Evidence tracker
Attach links, notes, and proof for every control an auditor checks.
Owners & accountability
Assign each item to a named owner so nothing falls through the cracks.
Due dates & status
Track open, in progress, complete, or N/A with target dates.
All 11 AI tools
SoA, Gap Analysis, Internal Audit, Roadmap, Scope, Asset, Annex A, Supplier, RTO/RPO and more.
AI Assistant
ISO 27001 guidance grounded in the standard, available on every item.
Excel & Word exports
Auditor-ready exports of your register, checklist, and evidence.
Quick readiness check
Answer 12 questions to see your ISO 27001 readiness score and your top missing items. No signup required.
Context of the organization
Internal and external issues, interested parties, and their requirements (Clause 4).
How to do this
Hold a 1-hour workshop with leadership. Capture: (1) internal issues (culture, resources, technology), (2) external issues (regulators, customers, threat landscape), (3) interested parties (clients, regulators, employees, suppliers) and their security requirements. Save as 'Context of the Organization' document, version-controlled, signed by the ISMS owner.
Leadership and roles defined
Roles, responsibilities, and authorities for the ISMS are assigned and communicated (Clause 5.3).
How to do this
Build a simple RACI matrix for: ISMS Owner, Risk Owner, Asset Owner, Internal Auditor, Incident Response Lead. Publish in the policy library and reference in job descriptions. Auditors will ask 'who is accountable for X' - the RACI is your answer.
ISMS Scope defined
Document the boundaries of the ISMS - locations, business units, services, and exclusions with justification.
Use our tool
We ship a tool that produces the evidence an auditor expects for this item.
Open the ISMS Scope BuilderInformation Security Policy approved
Top-management-approved ISMS Policy aligned with strategic direction (Clause 5.2).
How to do this
Draft a 2-3 page ISMS Policy that states the security objectives, commitment to legal/regulatory requirements, continual improvement, and roles. Get it signed by the CEO or top management, dated, and communicated to all staff. Re-approve at least annually. Store the signed PDF as evidence.
Risk assessment methodology
Documented method for identifying, analyzing, and evaluating information security risks (Clause 6.1.2).
Use our tool
We ship a tool that produces the evidence an auditor expects for this item.
Open Risk Copilot - Methodology SettingsRisk register populated
Initial risk register covering assets in scope with inherent and residual scores.
Use our tool
We ship a tool that produces the evidence an auditor expects for this item.
Open Risk Copilot - Risk RegisterRisk treatment plan
Risk treatment options chosen for each risk (mitigate, transfer, accept, avoid) with action plans.
Use our tool
We ship a tool that produces the evidence an auditor expects for this item.
Open Risk Copilot - Treatment PlanStatement of Applicability (SoA)
SoA listing every Annex A control with applicability, justification, and implementation status.
Use our tool
We ship a tool that produces the evidence an auditor expects for this item.
Open the SoA GeneratorMandatory policies and procedures
Acceptable Use, Access Control, Cryptography, BCM, Supplier Security, Incident Response, etc.
Use our tool
We ship a tool that produces the evidence an auditor expects for this item.
Open the Document Library (templates)Or do it yourself
You need at least: Acceptable Use, Access Control, Cryptography, Backup, Supplier Security, Incident Response, BCM, Change Management. Use our Document Pack templates as a starting point, tailor to your environment, get them approved by leadership, and publish to all staff.
Internal audit program
Schedule and procedure for internal ISMS audits (Clause 9.2).
Use our tool
We ship a tool that produces the evidence an auditor expects for this item.
Open the Internal Audit toolCorrective action process
Documented process for handling nonconformities and corrective actions (Clause 10.1).
How to do this
Maintain a simple Nonconformity and Corrective Action (NC/CA) log with: ID, date raised, source (audit, incident, complaint), description, root cause, corrective action, owner, due date, verification of effectiveness, closure date. Review the log at every management review.
Management review records
Process and inputs for periodic management review of the ISMS (Clause 9.3).
How to do this
Schedule at least one management review per year. Required inputs: status of previous actions, changes affecting the ISMS, performance feedback (incidents, audit results, KPIs, risk status), opportunities for improvement. Outputs: decisions on changes, resource needs, improvement actions. Keep meeting minutes signed by the chair as evidence.
ISO 27001 Audit Room - locked preview
Context of the organization
Stage 1: Documentation Review
Leadership and roles defined
Stage 1: Documentation Review
ISMS Scope defined
Stage 1: Documentation Review
Information Security Policy approved
Stage 1: Documentation Review
ISMS objectives and KPIs
Stage 1: Documentation Review
Risk assessment methodology
Stage 1: Documentation Review
Sign in to save your Audit Room across devices.
Sign in