Example A

The quality manager updates the asset inventory.

New devices and systems are described in the chat exactly as they are. The platform updates the asset inventory, the related documents and their metadata: version, approver and review date.

Add to the asset inventory: 4 new MacBook Pros (2026), the Azure production environment and two network printers. Two old laptops are being retired.
I updated the asset inventory and the documents linked to it:
5.2 Asset inventory · 6 rows added, 2 marked as retired
3.6 Endpoint management · device types to review
2.5 Risk register · new environment added for assessment
version 2.4 → 2.5 · edited by: quality manager · 29 Jul 2026
approval pending: CISO · next review: 29 Jul 2027
Change recorded in the history with its sources
01

You describe the changes in the chat

No form and no separate spreadsheet: the list is enough as it is.

02

The platform recognises what the change affects

The asset inventory is updated, and the linked guidelines and risks are raised for review.

03

The metadata stays in order

Version, editor, approver and the next review are logged automatically.

Example B

An employee asks about the clear desk policy.

From question to answer and from answer to source: three clicks, no guesswork.

  1. 01

    A question in plain language, an answer with its sources

    The answer states the rule, your own implementation and the control in the standard. Every point links to the document it came from.

    ask your own materialyour material only
    Today
    What is the clear desk policy?
    02:38 PM

    In the documented implementation, a clear desk means in practice:
    • Confidential paper documents are not left out on the desk
    • If paper must be handled → stored in a lockable cabinet / appropriately, according to its classification
    • Printouts are destroyed after use (shredding)
    • Devices and peripherals too (e.g. USB sticks, external drives) are stored securely
    Sources:
    ComplianceCoded · 02:38 PM
  2. 02

    The source link opens your own guideline

    The guideline shows the version, status, owner and approver, the practical implementation, responsibilities, the evidence for the audit and the items still open.

    6. Implementation of controls (Annex A)A.7 Physical controlsA.7.7 Clear desk and clear screen

    A.7.7 Clear desk and clear screen

    Version: 0.3 · Status: Implementation documented · Owner: Matti Saarinen (CISO) · Approver: Harri Puolitaival (CEO)
    Review interval: annually · Last updated: 2026-05-20 · Relates to: 27001 A.7.7 · 27002 7.7
    Summary of the requirement

    Confidential information is not left visible on the desk or the screen when the user leaves. This prevents unauthorised viewing, disclosure or theft.

    Our implementation

    Clear screen: defined in 3.1 Acceptable use policy: “Lock your screen when you leave the device, at the home office too.”

    • Automatic screen lock after a short idle period
    • Password or biometrics required on wake

    Clear desk: paper documents are hardly used at all.

    • Confidential paper documents are not left out on the desk
    • If necessary, stored in a lockable cabinet according to classification
    • Printouts are destroyed after use (shredding)
    Responsibilities
    • CISO: ensures the automatic screen lock is enabled on all devices.
    • Employee: locks the screen when leaving and does not leave confidential information out.
    Audit evidence
    • 3.1 Acceptable use policy → “Lock your screen when you leave”
    • Automatic device lock timeout, confirmed from the configuration
    Open items
    • Quarterly check of the automatic screen lock per device
    • CEO signature for version 1.2
  3. 03

    From the guideline to the requirement in the standard

    The same chain continues to the control in the standard, so you can show the auditor directly which requirement your guideline answers.

    fi-iso-iec27001Annex A, Information security controls referenceA.7 Physical controlsA.7.7 Clear desk and clear screen

    A.7.7 Clear desk and clear screen

    Control

    Clear desk rules for papers and removable storage media and clear screen rules for information processing facilities shall be defined and appropriately enforced.

    ISO/IEC 27002 detailed guidance: 7.7 Clear desk and clear screen

    See ISO/IEC 27002:2022 for the full implementation guidance, purpose, and other information.

Example C

Training and the test in the same place as the documentation.

A policy becomes an awareness and training module (7.3), the module a quick test, and the test a reading acknowledgement. Completions are logged per person, so awareness can be verified without a separate spreadsheet.

01

Training material straight from the source

The module is the same document that is versioned and approved. When the policy changes, the training changes with it.

Security training, basic module
Version 0.3
1. Read the training material first

Go through the basic module below carefully (about 12 min to read). Scroll to the end, then take the test and sign the acknowledgement below.

Version: 0.4
Status: Implementation documented (full version: quick test and acknowledgement in the system)
Owner: Security officer (CISO)
Approver: CEO
Review interval: annually and on significant changes (see 1.7 ISMS annual plan)
Last updated: 2026-05-27
Annex A: A.6.3
ISO/IEC 27002 implementation guidance: 27002 6.3
5.10 Security training, basic module (for staff)

About 18 min to read. After that, take the quick test (5 questions, pass mark 4/5) and sign the electronic acknowledgement in the system. The completion is visible to management and the CISO automatically.

If you meet an abbreviation you do not know, scroll to the section 16. Abbreviations and glossary.

02

The quick test measures understanding

Five questions about real work situations, pass mark 4/5. The test shows the guideline was read and understood.

2. Quick test (5 questions, pass mark 4/5)
1. You get an email from a “client” asking you to open an attachment named Invoice_2026_05.pdf.exe. What do you do?
a) I open it, because the client asked
b) I forward it to the CISO and ask, I do not open it
c) I open it, but only in a virtual machine
2. A client asks you to find out why an entry in their books is wrong. You want to use AI for the analysis. What do you do?
a) I paste the client's entire bookkeeping spreadsheet into the AI and ask for an analysis
b) I use our own controlled environment
c) I describe the problem generically without client data and ask
3. You notice your password leaked into an error log file you shared with colleagues. What do you do?
a) I delete the message and hope for the best
b) I change the password immediately and notify the CISO
c) I do nothing, the message was internal only
Submit answers
03

The electronic acknowledgement stays as evidence

The reading acknowledgement is logged against the person and the version as evidence of awareness. The acknowledgement rate shows in the status picture and can be shown to the auditor.

3. Reading acknowledgement

I have read the basic security training module (version 0.1) and commit to following the practices in it. I confirm this acknowledgement electronically with my own credentials.

I acknowledge having read this and commit to following it
SUBMIT AND ACKNOWLEDGE
Acknowledgement logged: version 0.4 · 27 May 2026 · acknowledgement rate 94 %
Why ComplianceCoded

Every auditor question has an answer and evidence.

Your data stays yours

Servers in the EU. No vendor lock-in: the data can always be exported out of the system.

AI that does not invent

A source link always, in every answer.

Change history is audit evidence

Changes, approvals and acknowledgements kept for the auditor.

Made for people, not engineers

Usable without training or technical support.

Change history

Traceability: documented information is under control.

Version control, approvals and acknowledgements form an unbroken record chain. Every version and approval is traceable and verifiable from a single view.

document metadatav1.0 · approved 21 May 2026
1. Leadership and scope1.2 Information security policy
1.2 Information security policy
Version: 1.0 · Status: Approved · Owner: Security officer (CISO) · Approver: CEO
Review interval: annually or on significant changes · Last updated: 2026-05-21 · Approved: 2026-05-21
ISO/IEC 27001: Clause 5.2
Annex A: A.5.1
ISO/IEC 27002 implementation guidance: 27002 5.1

Every document states who owns it, who approved it and which requirement it answers. The timeline shows what happened before this version.

v1.0 · draft · 4 Jan 2026v1.2 · reviewed · 18 Feb 2026branch: change proposal · 3 commentsv1.4 · approved · 12 Mar 2026acknowledged 94 %valid

Are you starting a certification process or choosing a tool for it?

Half an hour is enough to see what you already have in place and what is missing.

Book a 30 min demo[email protected]