ISO 27001 Audit Room

    ISO 27001 Audit Room

    The ISO 27001 Audit Room is the complete implementation workspace. It already includes the 40+ item Stage 1 and Stage 2 readiness checklist, risk register, evidence tracker, owners and due dates, all 11 AI tools, the AI Assistant, and Excel and Word exports - everything an auditor will ask for, in one place.

    Readiness score
    Evidence tracker
    Owners & due dates
    Stage 1 & 2 ready
    Friendly ISO 27001 audit mascot
    Complete workspace

    What's included in Audit Room

    Audit Room is the complete ISO 27001 implementation workspace. Everything below is already included - no add-ons, no separate tools to wire up.

    Stage 1 + Stage 2 readiness checklist

    40+ curated items mapped to ISO 27001 clauses and Annex A controls.

    Risk register

    Identify, score, and treat risks - linked to controls and owners.

    Evidence tracker

    Attach links, notes, and proof for every control an auditor checks.

    Owners & accountability

    Assign each item to a named owner so nothing falls through the cracks.

    Due dates & status

    Track open, in progress, complete, or N/A with target dates.

    All 11 AI tools

    SoA, Gap Analysis, Internal Audit, Roadmap, Scope, Asset, Annex A, Supplier, RTO/RPO and more.

    AI Assistant

    ISO 27001 guidance grounded in the standard, available on every item.

    Excel & Word exports

    Auditor-ready exports of your register, checklist, and evidence.

    Quick readiness check

    Answer 12 questions to see your ISO 27001 readiness score and your top missing items. No signup required.

    Context of the organization

    Internal and external issues, interested parties, and their requirements (Clause 4).

    How to do this

    Hold a 1-hour workshop with leadership. Capture: (1) internal issues (culture, resources, technology), (2) external issues (regulators, customers, threat landscape), (3) interested parties (clients, regulators, employees, suppliers) and their security requirements. Save as 'Context of the Organization' document, version-controlled, signed by the ISMS owner.

    Leadership and roles defined

    Roles, responsibilities, and authorities for the ISMS are assigned and communicated (Clause 5.3).

    How to do this

    Build a simple RACI matrix for: ISMS Owner, Risk Owner, Asset Owner, Internal Auditor, Incident Response Lead. Publish in the policy library and reference in job descriptions. Auditors will ask 'who is accountable for X' - the RACI is your answer.

    ISMS Scope defined

    Document the boundaries of the ISMS - locations, business units, services, and exclusions with justification.

    Use our tool

    We ship a tool that produces the evidence an auditor expects for this item.

    Open the ISMS Scope Builder

    Information Security Policy approved

    Top-management-approved ISMS Policy aligned with strategic direction (Clause 5.2).

    How to do this

    Draft a 2-3 page ISMS Policy that states the security objectives, commitment to legal/regulatory requirements, continual improvement, and roles. Get it signed by the CEO or top management, dated, and communicated to all staff. Re-approve at least annually. Store the signed PDF as evidence.

    Risk assessment methodology

    Documented method for identifying, analyzing, and evaluating information security risks (Clause 6.1.2).

    Use our tool

    We ship a tool that produces the evidence an auditor expects for this item.

    Open Risk Copilot - Methodology Settings

    Risk register populated

    Initial risk register covering assets in scope with inherent and residual scores.

    Use our tool

    We ship a tool that produces the evidence an auditor expects for this item.

    Open Risk Copilot - Risk Register

    Risk treatment plan

    Risk treatment options chosen for each risk (mitigate, transfer, accept, avoid) with action plans.

    Use our tool

    We ship a tool that produces the evidence an auditor expects for this item.

    Open Risk Copilot - Treatment Plan

    Statement of Applicability (SoA)

    SoA listing every Annex A control with applicability, justification, and implementation status.

    Use our tool

    We ship a tool that produces the evidence an auditor expects for this item.

    Open the SoA Generator

    Mandatory policies and procedures

    Acceptable Use, Access Control, Cryptography, BCM, Supplier Security, Incident Response, etc.

    Use our tool

    We ship a tool that produces the evidence an auditor expects for this item.

    Open the Document Library (templates)

    Or do it yourself

    You need at least: Acceptable Use, Access Control, Cryptography, Backup, Supplier Security, Incident Response, BCM, Change Management. Use our Document Pack templates as a starting point, tailor to your environment, get them approved by leadership, and publish to all staff.

    Internal audit program

    Schedule and procedure for internal ISMS audits (Clause 9.2).

    Use our tool

    We ship a tool that produces the evidence an auditor expects for this item.

    Open the Internal Audit tool

    Corrective action process

    Documented process for handling nonconformities and corrective actions (Clause 10.1).

    How to do this

    Maintain a simple Nonconformity and Corrective Action (NC/CA) log with: ID, date raised, source (audit, incident, complaint), description, root cause, corrective action, owner, due date, verification of effectiveness, closure date. Review the log at every management review.

    Management review records

    Process and inputs for periodic management review of the ISMS (Clause 9.3).

    How to do this

    Schedule at least one management review per year. Required inputs: status of previous actions, changes affecting the ISMS, performance feedback (incidents, audit results, KPIs, risk status), opportunities for improvement. Outputs: decisions on changes, resource needs, improvement actions. Keep meeting minutes signed by the chair as evidence.

    ISO 27001 Audit Room - locked preview

    Context of the organization

    Stage 1: Documentation Review

    Locked

    Leadership and roles defined

    Stage 1: Documentation Review

    Locked

    ISMS Scope defined

    Stage 1: Documentation Review

    Locked

    Information Security Policy approved

    Stage 1: Documentation Review

    Locked

    ISMS objectives and KPIs

    Stage 1: Documentation Review

    Locked

    Risk assessment methodology

    Stage 1: Documentation Review

    Locked

    Sign in to save your Audit Room across devices.

    Sign in