Solution

ComplianceCoded makes building certification documentation easier and faster, maintaining it and embedding it in everyday processes.

  1. 01

    Bring in your material, compose in the browser

    Drag your current documents in as background material. The AI compiles company-specific documentation from them, interviews you with clarifying questions and helps shape the text to match how you actually work. You finish it in the browser, and every change is recorded: who, when, what.

  2. 02

    ComplianceCoded keeps the record

    Statuses, approvals and acknowledgements are logged automatically. Progress and blind spots are visible at a glance.

  3. 03

    Ask, and get the source

    The AI answers only from your own material and attaches a clickable source to every answer.

content structureISO 27001 · 6 sections · 142 documents
Search...
+ ADD CONTENT
1. Leadership and scope(7)
1.1 ISMS scope
1.2 Information security policy
1.3 Roles and responsibilities
1.4 Context analysis
1.5 ISMS objectives and metrics
1.7 ISMS annual plan
2. Risk management(5)
2.1 Risk assessment method
2.2 Risk treatment method
2.3 Statement of Applicability (SoA)
2.4 Risk treatment plan
2.5 Risk register
3. Operating policies(15)
4. Procedures (processes)(8)
5. Evidence and records(14)
6. Implementation of controls (Annex A)(4)
2. Risk management

2. Risk management

2. Risk management

This section covers identifying, assessing and treating risks, plus the Statement of Applicability (SoA), the single most important document in ISO/IEC 27001 certification.

Maps to ISO/IEC 27001:2022 clauses 6.1, 8.2 and 8.3.

Contents
2.1 Risk assessment method
2.2 Risk treatment method
2.3 Statement of Applicability (SoA)
2.4 Risk treatment plan
2.5 Risk register
The structure is ready: each section states which clauses of the standard it answers. Work starts from writing, not from an empty folder tree.
status pictureISO 27001 · implementation 64 %
Dashboard
0%
Health
ISO/IEC 27001, status picture
142 documents · index calculated from implementation
Implemented 91In progress 38Open 13
1. Leadership and scope5/7 implemented · 78%
2. Risk management3/5 implemented · 72%
3. Operating policies (operational)9/15 implemented · 66%
4. Procedures (processes)5/8 implemented · 69%
5. Evidence and records8/14 implemented · 61%
6. Implementation of controls (Annex A)46/93 implemented · 54%
Open findings and actions
13
13 open · 38 in progress · 91 documented
A.5.6 Contact with special interest groups
A.5.7 Threat intelligence
A.8.10 Information deletion
Next actions
15.09.2026Internal audit and management review
30.09.2026Stage 1 (documentation audit)
15.11.2026Stage 2 (implementation audit)
Source: ISMS annual plan (1.7)
Timeline, process maintained
Choosing an accredited certification body and the contract
15.07.2026
Security training for all staff
30.06.2026
Deadline for certification quotes
16.06.2026
Progress and blind spots as numbers: what is done, what is in progress and what is still open. The same view serves the management review and audit preparation.
Core capability

You adapt the system to your own needs by describing them.

The platform is not a fixed set of forms. You say in your own words what your management system is missing, and the section takes shape in conversation: fields, approval chain and acknowledgements follow your process.

No specification document and no waiting in a development queue. The finished section behaves like the rest of the material: versioned, approved and cited as a source in the AI's answers.

Describe the need
“We want a section for supplier assessment: an assessment form, an annual review and an acknowledgement from the owner.”
Section built and added to the structure
Three documents, an assessment form and an annual review reminder. Review and approve for use.
7. Supplier assessment
7.1 Supplier assessment form
7.2 Annual review procedure
7.3 Acknowledgements and responsibilities
01

You describe the need

No specification document and no technical description. It is enough to say what the section should do.

02

The section is created and reviewed

You see a draft immediately, refine it in conversation and approve it for use.

03

It behaves like the rest of the material

The same versioning, the same approvals and acknowledgements, the same source reference in AI answers.

Examples of sections built by describing them

Supplier assessment and annual review
Handling nonconformities and incidents
Role-specific onboarding checklist
Change management approval chain
Site-specific work instructions
Tracking customer requirements per contract
Control is retained

Versioning and change history for every section.

Responsibilities

Owner, approver and review interval as in every other guideline.

Access rights

Visibility and edit rights by role.

Audit

Acknowledgements and approvals in the same form as all other evidence.

Are you starting a certification process or choosing a tool for it?

Half an hour is enough to see what you already have in place and what is missing.

Book a 30 min demo[email protected]