Skip to content

CYBER SECURITY · 10 AUGUST 2026 · 2 MIN READ

ISO 27001 when you run on Google Workspace, not a cloud-native stack

Why the global GRC tools underdeliver on Workspace-first and mixed estates, and what a deliberate evidence model looks like instead.

The best-known compliance platforms were built for a particular kind of company: cloud-native, AWS or Azure, Okta, GitHub, a fleet of managed MacBooks. Their pitch is automation: agents and integrations that test controls continuously and collect evidence for you.

That model is real, and it works well on that stack. It works badly on the stack most Australian businesses actually have: Google Workspace or Microsoft 365 as the centre of gravity, a mix of managed and unmanaged devices, some on-premise systems, an MSP in the loop, line-of-business SaaS with no API. The integrations fire on a fraction of your controls and the price is set by your headcount, not by what the tool does for you.

The alternative is not "manual"

The choice is not automation versus spreadsheets. It is between pretending to auto-verify and deliberately evidencing.

A deliberate evidence model looks like this:

  • Every control has an owner and a cadence. Quarterly for access reviews, monthly for patch reports, on-change for policies.
  • Evidence is linked at the source, not copied. A Workspace admin export, a Drive document, an M365 compliance report: linked, dated, with staleness detected when the source changes or the review date passes.
  • One item, many requirements. The quarterly access review satisfies 27001 A.5.18, an Essential Eight ML2 requirement and SOC2 CC6.2, mapped once.
  • Status is arithmetic. Met, partial, not met, needs review: computed from what is linked and when. No model guesses.

This is how auditors have always worked. It is also how a Workspace-first business holds a 27001 certificate with evidence it can stand behind.

Where AI helps, and where it must not

There are places a language model genuinely saves time: turning a messy written answer into a proposed status for a person to confirm, drafting the first version of a policy, summarising a gap list in plain English, reviewing whether a document evidences the control it claims to. ISO Assist uses AI at exactly those boundaries, labelled, with every call logged and priced.

It must never set a compliance status. If a model's output fails validation or is uncertain, the item becomes needs review. It never defaults to compliant.

By ISO Assist. Tagged ISO-27001 · GOOGLE-WORKSPACE · EVIDENCE · GRC.

More in Cyber security

Reading about it is the slow way.

Book a demo and see the standard adopted in a workspace.