Xeviora QuarterlyIssue No. 14
ISO 27001 Audit PrepFeatured Tool

ISO 27001 Audit Prep AI — ISMS Scope, Risk Register & Annex A Mapping

Stand up an ISMS without staring at a blank page.

Editor's note

Give the tool your organization profile, key assets, and existing controls. It drafts an ISMS scope statement, builds a risk register with treatments, and produces an ISO/IEC 27001:2022 Annex A control mapping plus a remediation plan — the backbone of your certification project.

Tagged

ISO 27001 audit prep·ISO 27001 readiness·ISO 27001 risk register·Annex A controls

§ Section I

How to use ISO 27001 Audit Prep

Three movements
01

Describe your organization and what's in scope

Tell the tool what you build, the stack you run on, the data you hold, and which teams, products, and systems belong inside your ISMS. The scope statement an auditor reads first is only as good as this input, so be concrete about inclusions and exclusions.

02

List your assets and the controls you already have

Paste a quick inventory of key systems and data stores, then describe what you already do for security — SSO, MFA, backups, access reviews, on-call. Honesty here matters: the assessment is more useful when it knows what's informal or missing.

03

Get a structured readiness package

In under a minute you receive a drafted ISMS scope, a risk register mapped to Annex A, an applicability assessment across all four control themes, a readiness score, and a prioritized remediation plan you can hand straight to your team.

§ Section II

Who it's for

Readership · 4 cohorts
No. 01

SaaS founders & security leads

You've been asked for ISO 27001 by an enterprise prospect and need to know the real distance to certification before you commit budget. The readiness score and gap list turn a vague 'we should get certified' into a concrete plan.

No. 02

ISMS managers

You own the management system day to day and need to keep the risk register, SoA, and remediation backlog current. Re-run the assessment after each scope change to catch drift before the surveillance audit does.

No. 03

CTOs & engineering leaders

You want to understand the engineering cost of certification — which Technological controls (A.8) are already covered by your stack and which need new work — without sitting through a week of consultant discovery calls.

No. 04

vCISOs & compliance consultants

You run readiness across multiple clients and want a fast, consistent first pass that maps free-text context onto Annex A. Use it to draft the initial gap analysis, then spend your billable hours on judgment and remediation instead of data entry.

§ Section III

Frequently asked

6 entries
Q.01Which version of ISO 27001 does this tool use?
A.01

ISO/IEC 27001:2022, the current revision. Its Annex A reorganizes controls into 93 controls across four themes — Organizational (A.5), People (A.6), Physical (A.7), and Technological (A.8). The tool maps your risks to these 2022 references, not the retired 2013 numbering.

Q.02Does this replace a certification audit or a consultant?
A.02

No. It's a fast readiness assessment that shows you where you stand and what to fix first. Certification still requires an accredited certification body to run a Stage 1 and Stage 2 audit. Many teams use this output to brief a consultant or auditor more efficiently — and to avoid paying for hours of basic gap analysis.

Q.03What is the Statement of Applicability and does the tool produce one?
A.03

The Statement of Applicability (SoA, clause 6.1.3 d) records which Annex A controls apply, their status, and the justification for including or excluding each one. The tool generates the applicability assessment that feeds your SoA — you review it, adjust the judgments, and formalize the document.

Q.04How much does it cost to run?
A.04

Each assessment costs 10 credits. New accounts start with 10 free credits, so your first run is on us. There's no per-seat license and no commitment — run it again whenever your scope or controls change.

Q.05Is ISO 27001 just a control checklist?
A.05

No, and that's where many teams underestimate it. ISO 27001 is a management system. Beyond Annex A controls, you need a defined scope, a risk assessment and treatment plan, an SoA, internal audits, and management reviews (clauses 4–10). The tool flags these management-system gaps, which are the most common reasons a Stage 2 audit stalls.

Q.06Can I use the output for client security questionnaires?
A.06

Partly. The readiness summary and control status give you a clear, organized view you can draw on when answering vendor security reviews. For a customer-facing assurance artifact, though, an actual certificate or a SOC 2 report carries more weight — this tool gets you to that point faster.

— Fin —Set in Fraunces & Plex