Docs

Management systems and compliance

Run ISO 27001, ISO 9001, UK GDPR and Cyber Essentials programmes for your customers and yourself, with one control library, controlled policies, risks, evidence, audits, auditor access and readiness.

  1. 1 Management systems overview What a programme is, how the control library, documents, risks, evidence and audits fit together, and how readiness is worked out.
  2. 2 Frameworks and the control library The shipped frameworks, the 321 common controls they map to, building your own framework with versions, and the template packs.
  3. 3 Policy documents under control Keep policies and procedures under document control, from a master library you adopt for customers, with customer approval, versions and staff acknowledgement.
  4. 4 Risk register and Statement of Applicability Score risks on the customer's matrix, treat them, get them accepted by their owner, and generate, approve and export the Statement of Applicability.
  5. 5 Evidence and compliance tasks Evidence that cannot be changed and proves itself, daily check snapshots, access reviews, and the recurring compliance tasks and calendar.
  6. 6 Audits, reviews and registers Plan internal audits over the cycle, raise and close nonconformities, hold management reviews with gathered inputs, track objectives, and keep the supplier, training, certificate and incident registers.
  7. 7 Auditors and the portal What the customer's people see and do in the portal's Compliance section, read-only access for an external auditor with an emailed code, and evidence packs.
  8. 8 Readiness, reports and selling compliance The MSP overview across every programme, management systems in the monthly report and business review, the readiness snapshot for prospects, and the project templates and catalogue items for selling compliance.