Compliance Management guide

Configure and maintain the ISO 27001 ISMS

Build the Clauses 4–10 management system, maintain supporting registers and use the dashboard to prioritise improvement.

Compliance Manager, ISMS Manager or authorised contributor Ongoing programme activity Updated 27 July 2026

What the ISO 27001 workspace covers

PurpleWASP provides an end-to-end workspace for the ISO/IEC 27001 management system, including the ISMS manual for Clauses 4–10, scope records, the Statement of Applicability, management reviews, audit activity, nonconformities and supporting registers.

1. Build the ISMS manual

Open the ISO 27001 compliance workspace and work through Clauses 4–10. Complete the required organisational context, leadership, planning, support, operation, performance evaluation and improvement information.

The ISMS workspace structures the clauses and associated registers so the management system can be built and maintained in one place.

Where AI is enabled, it can draft supporting text using organisation details such as location and sector. Review and approve generated content before treating it as final.

2. Maintain scope and registers

Define what is in scope, what is out of scope and the relevant interfaces and dependencies. Maintain supporting registers such as assets, risks, objectives, incidents, legal obligations, suppliers, training and access reviews.

3. Record management and assurance activity

  • Document management reviews and their decisions.
  • Create audit programmes and retain audit reports.
  • Record nonconformities and corrective action.
  • Track ISMS objectives using measurable outcomes.
  • Keep evidence and related records connected to the applicable requirement.

4. Use the compliance dashboard

The dashboard presents current compliance status, control progress and drivers that explain what needs to improve.

The score is an operational indicator, not a certification decision. Use its underlying drivers to identify incomplete requirements, missing evidence and control work.

Common problems

AI-generated content is too generic

Provide accurate organisation profile information and rewrite the output to reflect real scope, stakeholders and operating practices.

The compliance score does not improve

Review the improvement drivers and confirm that completed records have been saved, evidence linked and status updated.