Help Centre module

Compliance Management

Operate an ISO 27001 management system, manage Annex A applicability and connect policies, risks and evidence to controls.

Start with the workflow

From requirements to demonstrable assurance

The compliance workspace combines the ISMS manual, Statement of Applicability, evidence, reviews, audits and registers.

1
Define

Build Clauses 4–10, scope and supporting registers.

2
Select

Set Annex A applicability and justification.

3
Implement

Track status and control ownership.

4
Evidence

Link policies, assessed risks and operating evidence.

5
Improve

Use score drivers, audits and nonconformities.

ISO 27001 workflows

Build and maintain the management system

Use focused guidance for the ISMS and Statement of Applicability.

Important operating rules

A compliance score is an operational signal

Use the underlying drivers to identify incomplete requirements and missing evidence. The platform score is not itself a certification decision.

  • Not Applicable controls require justification.
  • Approved policies can support control intent.
  • Completed risk assessments can support control context.
  • Evidence should be relevant, current and traceable.