Solution

Compliance does not fail for lack of documents, it fails on keeping them up to date.

Policies are easy to write once. The hard part is keeping them current, proving they have been followed and doing it all again every year.

The pain 1

We have no time to start from scratch, and there are years of old material.

An empty document template is the most common reason a security policy never gets written. Meanwhile documents have piled up on the file share and in email, and nobody knows which of them is in force.

How we solve it

You do not start from scratch. You answer a few questions in your own language, and the first version comes out of them. Existing material is imported as it is, and the version in force is brought to the front. Everything is edited straight in the browser, versioned from the first save.

Policies from questionsImport of existing materialEditing in the browser
ExampleA 120-person company imports 340 documents. They become 90 documents with version histories, and the rest are duplicates nobody has to guess about any more.
The pain 2

Documentation goes stale the moment it is finished.

Regulation keeps changing. Suppliers send updates. In many EU countries the same instruction has to exist in the national language. By hand this is impossible to keep current.

How we solve it

When a requirement changes, the system points out which documents the change affects and proposes the updates already written out. An update can even be started by forwarding an email with its attachments. Translations are versioned paragraph by paragraph, and an outdated language version is flagged immediately.

Regulatory change monitoringUpdates by emailMultilingual documents
ExampleThe third paragraph of the access control policy changes in Finnish. The Swedish and English versions are marked outdated in the same second, and what needs fixing is one paragraph, not 14 pages.
The pain 3

An audit does not fail on documents, it fails on evidence.

You pass a stage 1 audit with documentation. You pass stage 2 with evidence that the documentation has been followed. That is exactly what cannot be produced retroactively.

How we solve it

A requirement, a policy, a recurring task, its proof and people's sign-offs form one traceable chain that an auditor can verify without you. Staff training, with its check questions and sign-offs, accumulates as evidence automatically.

Evidence chainStaff training and sign-offVersioning and approval
ExampleThe auditor asks how the access review was done. The answer is one link: the policy, the task, the date, who did it, the result and the approval.
The pain 4

Who sees what, and what is the overall picture?

Not all documentation is meant for everyone. The overall picture is easily lost among individual documents.

How we solve it

Access is defined by role. Only management sees the risk register, an employee sees only the content for their own work. The dashboard gathers the whole picture into one view: what is current, what is about to expire and who has signed off.

Access rights and rolesDashboard views
ExampleThe management team opens the dashboard before the review and sees at once which policies expire this month and who has not signed off their training.
The pain 5

Will we be locked into this system?

The management system is the organisation's own property. Sooner or later it faces an audit, a supplier assessment or a due diligence.

How we solve it

Everything is stored in an open, readable format with a full version history. The entire body of material can be exported as a single package, self-service. The platform is also available installed in the organisation's own environment.

The material is yours, no vendor lock-in
ExampleThe buyer's adviser asks for the policies and their approval history. That is one export, not three weeks of digging.

Are you starting a certification process or choosing a tool for it?

Half an hour is enough to see what you already have in place and what is missing.

Book a 30 min demo[email protected]