Skip to content

ISO 27001 · Essential Eight · ISO 9001 · 45001 · 14001 · one platform

Certified in weeks. Compliant for good.

ISO Assist is the system of record for your whole management system: requirements, evidence, documents, registers and audit-grade reports. Built in Australia for Australian businesses and the partners who serve them.

14 DAYS FREE · NO CARD · ONE FLAT ANNUAL RATE · AUSTRALIAN DATA RESIDENCY

ISO 27001:2022 · Essential Eight

Live view of a workspace, first eight weeks

0%

readiness

CL 4.3Scope of the ISMS
CL 6.1.2Information security risk assessment
A.5.1Policies for information security
A.5.12Classification of information
A.5.15Access control
A.6.3Awareness, education and training
A.8.8Management of technical vulnerabilities
A.8.13Information backup
A.8.24Use of cryptography
CL 9.2Internal audit
CL 9.3Management review
E8 · ML2Patch applications within two weeks
ISO/IEC 27001:2022ACSC Essential EightISO 9001:2015ISO 45001:2018ISO 14001:2026SOC2

0 wks

to audit-ready, typical

Consultant-led programmes run 12+ months.

0

pricing tiers by revenue or headcount

One flat rate per plan, every standard included from Growth up.

0+

templates included on every plan

Policies, procedures, registers, JSAs. Adapt, approve, done.

0

standards on one spine

One evidence item can satisfy requirements in all of them.

Typical figures from ISO Assist programmes. Your timeline depends on scope and on how much evidence already exists. A certification body issues the certificate; we get you to the audit ready.

Why we rebuilt everything

It was never about templates.

For years ISO Assist sold document toolkits. They worked: thousands of organisations used them to get certified. But a folder of Word documents is where a management system starts, not where it lives.

Certification is a ledger: every requirement, who owns it, what proves it, when it was last checked. Keep that ledger in a spreadsheet and it rots between audits. Keep it in a US tool built for cloud-native start-ups and you pay for automation that never fires on your estate.

So we built the ledger. The templates are still here, more than 400 of them on every plan, and now they are one module in a system that runs the whole thing.

How it works

One requirement, start to finish.

Watch a single control move from adopted to audited. Every other requirement follows the same path.

  1. 01

    Adopt the standard

    Pick ISO 27001, the Essential Eight or all five. Every clause, control and requirement appears as a row with an owner and a status. Nothing to configure, nothing to type in.

  2. 02

    Link the evidence

    Upload it, link it from Google Workspace or Microsoft 365, or generate it from a template. Set a collection cadence. One item can satisfy requirements in several standards, mapped once.

  3. 03

    Run the system

    Actions, internal audits, management reviews, corrective actions, training and access reviews happen in the same workspace, so the records exist because the work happened.

  4. 04

    Hand the auditor the pack

    Statement of Applicability, gap report, dossier and evidence index, a frozen, hashed snapshot of your records. Time-boxed read-only access for the auditor.

The platform

Everything the standard asks for, as modules that talk to each other.

Grouped the way a management system is, not the way a feature list is.

Know where you stand

Frameworks & requirements

Every clause and control as a row with an owner and a status.

Assessments

Guided questionnaires per standard; maturity and readiness roll up from answers.

Dashboard

Per-standard posture, what is overdue, what is due next.

Reports

Statements of Applicability, gap reports, dossiers, frozen and hashed.

Prove it

Evidence

Upload, link or generate. Collection cadence, expiry, reuse across standards.

Documents

Policies and procedures with versions, approval, acknowledgement and review dates.

Registers

Assets, risks, legal obligations, interested parties, exceptions, as data, not tabs in a spreadsheet.

Trust centre

A public page that answers questionnaires once.

Run the system

Actions & CAPA

Nonconformities, corrective actions, root cause, verification.

Internal audits

Programme, checklists, findings, follow-up.

Management reviews

Agenda from the standard; minutes as records.

Incidents, hazards & inspections

Safety and security events captured from the field.

People & suppliers

People & training

Competency matrix, acknowledgements, onboarding.

Access reviews

Periodic review of who can reach what.

Vendors

Third-party register with risk and evidence.

AI

AI that drafts, reviews and explains. People decide.

Compliance state is arithmetic.

Met, partial, not met, needs review: computed from your records. No model ever sets a status.

AI drafts, you approve.

Policy drafting, plain-English gap summaries and document review, always labelled, always reviewed by a person before it becomes a record.

Uncertain means needs review.

If an AI output fails validation or is low-confidence, the item is flagged for a human. It never defaults to compliant.

Every call is logged and priced.

Model, tokens and cost per call, visible in your workspace. AI spend is a line you can see, not a surprise.

Built by practitioners

Designed by people who run certification programmes, audited by people who assess them.

ISO Assist has helped Australian organisations reach ISO 27001 and ISO 9001 since 2019. The platform carries that experience into software: every module exists because an auditor asked for the record it produces. If a report is not good enough for a real external auditor, it does not ship.

The story

Adopt your first standard today.

14 days free, no card. Or book a demo and we will walk it with you.