Digital tools

Focused workflows with useful outputs

Apply practical digital tools and implementation guidance to recurring audit, compliance and management-system work.

Focused workflows

From static files to practical digital tools

Static templates can be useful, but they may require significant manual adaptation before they fit a particular organisation, standard or audit approach.

AuditPrepared focuses on workflows with defined inputs, logic and useful outputs. Paid Self-Hosted Tools operate in the customer’s supported environment, with the shared catalogue showing each tool’s current status.

Current alternatives

Use a current tool or implementation guide

Start with the available readiness checker, then use the published guides for deeper planning and professional judgement.

Available free Free Website Tool

ISO 27001 Readiness Checker

Answer 25 structured questions across six readiness areas and receive an indicative score.

Output
Indicative score, six area results and a browser-generated downloadable report.
ISO/IEC 27001Readiness assessment · Gap analysis
Guide

ISO 27001 Gap Analysis: The Complete Step-by-Step Guide

Learn how to run an ISO 27001 gap analysis, score findings, build a remediation plan and use a practical gap analysis template.

Standard
ISO/IEC 27001
Workflow
Audit preparation

11 min read

Guide

How to Build an Information Security Risk Register

Build a practical information security risk register with clear ownership, consistent scoring and records that support risk treatment and review.

Standard
ISO/IEC 27001
Workflow
Risk assessment

2 min read

Coming Soon

Paid Self-Hosted Tools

Customer-controlled tools for repeatable audit, evidence and compliance workflows.

In development Paid Self-Hosted Tool

Audit Evidence Organiser

Organise evidence requests, ownership, review and audit-preparation records.

Output
Evidence request, ownership and review records.
Management systemsAudit preparation · Evidence management
In development Paid Self-Hosted Tool

ISO 27001 Control Gap Mapper

Relate controls, identified gaps and remediation work in one structured workflow.

Output
Control-gap and remediation records.
ISO/IEC 27001Gap analysis · Remediation planning
Coming soon Paid Self-Hosted Tool

Vendor Security Assessment Tool

Manage vendor assessment questions, findings, ownership and follow-up actions.

Output
Vendor questions, findings and follow-up records.
Information securityVendor assurance
In development Paid Self-Hosted Tool

Incident Response Decision Tree

Follow a structured incident-triage path and record escalation decisions.

Output
Decision path and documented escalation prompts.
Information securityIncident response

Implementation resources

Practical guidance for current work

Explore professional guidance for gap analysis, risk assessment and framework selection.

Guide

ISO 27001 Gap Analysis: The Complete Step-by-Step Guide

Learn how to run an ISO 27001 gap analysis, score findings, build a remediation plan and use a practical gap analysis template.

Standard
ISO/IEC 27001
Workflow
Audit preparation

11 min read

Guide

How to Build an Information Security Risk Register

Build a practical information security risk register with clear ownership, consistent scoring and records that support risk treatment and review.

Standard
ISO/IEC 27001
Workflow
Risk assessment

2 min read

Comparison

ISO 27001 vs SOC 2: What Is the Practical Difference?

Compare ISO 27001 and SOC 2 in practical terms: certification vs attestation, scope, evidence, control approach, customer expectations and when an organization may need one or both.

Standard
ISO/IEC 27001
Workflow
Framework selection

9 min read

Guide

ISO 27001 Annex A Controls: How to Select, Implement and Evidence Them

Learn how to move from Annex A control lookup to justified applicability, practical implementation, operating evidence and Statement of Applicability maintenance.

Standard
ISO/IEC 27001
Workflow
Control selection

3 min read

Guide

ISO 27001 Audit Evidence: Implementation vs Operating Evidence

Learn the practical difference between implementation evidence and operating evidence in ISO 27001 audits, with examples, audit questions and a simple evidence-preparation method.

Standard
ISO/IEC 27001
Workflow
Evidence management

6 min read

Reference

ISO 27001 Clauses 4–10 Explained: What Each Clause Does

Understand how ISO 27001 clauses 4–10 fit together, what evidence teams commonly prepare and how to avoid disconnected compliance paperwork.

Standard
ISO/IEC 27001
Workflow
ISO 27001 implementation

3 min read

Guide

How to Build an ISO 27001 Evidence Register That Actually Helps During an Audit

Build a practical ISO 27001 evidence register that tracks ownership, requirements, freshness, review status, audit use and evidence reuse without creating duplicate files.

Standard
ISO/IEC 27001
Workflow
Evidence management

6 min read

Checklist

ISO 27001 Readiness Assessment: A Practical Pre-Audit Checklist

Use this practical ISO 27001 readiness assessment to find gaps in scope, risk management, evidence, internal audit and management review before certification.

Standard
ISO/IEC 27001
Workflow
Audit preparation

4 min read

Guide

ISO 27001 Risk Matrix: How to Define Likelihood, Impact and Risk Levels

Build a repeatable ISO 27001 risk matrix with defined likelihood, impact and acceptance criteria, practical examples and calibration guidance.

Standard
ISO/IEC 27001
Workflow
Risk assessment

4 min read

Use a current tool or practical guide

Establish an indicative readiness baseline or browse the current resource library.