Running the external audit
A method for hosting the certification body: evidence architecture, the opening meeting, nonconformity handling, and findings tracked to verified closure.
Compliance5 Sept 202622 min read
Toolkit
Three shelves. Playbooks set out a method end to end. Templates carry it as a file you can open on Monday. The Lab ships it as software.
01 — Playbooks
Each one covers a responsibility end to end, with the failure mode it prevents, the steps, the deliverables and what the auditor will ask.
A method for hosting the certification body: evidence architecture, the opening meeting, nonconformity handling, and findings tracked to verified closure.
Compliance5 Sept 202622 min read
A repeatable method for turning a legal instrument into control objectives, controls, evidence and owners, worked end to end on NIS2 and on the CRA.
Compliance4 Sept 202622 min read
A method for standing up an ISO/IEC 27001 management system that produces evidence in daily operation instead of a binder assembled before the audit.
Governance3 Sept 202623 min read
Risk statements that name a source, an event and a consequence; scales that survive argument; and every row closed by a named approver on a dated decision.
Risk3 Sept 202622 min read
02 — Templates
The artefacts the playbooks produce, as downloadable files under an open licence.
A twenty-two column form that runs the AI Act decision test over one AI use case per row and closes each row with proceed, conditions or stop.
Compliance5 Sept 20263 min read
A sixteen-column register that carries every external audit finding from the auditor's wording to a verification date, with correction and cause kept apart.
Compliance5 Sept 20263 min read
A sixteen-column information security risk register with anchored 1-5 scales, a published combination rule and two mandatory decisions on every row.
Risk3 Sept 20265 min read
03 — Lab
Working products, not slideware — the same methods published here, shipped as software.
An offline reference handbook for information security managers.
An offline reference for information security managers. The whole knowledge base ships with the app: 478 topic cards across five parts, wired together by typed cross-links and a glossary built from the topics themselves.
A working BISO operating system, running privately. Early access on request.
A single-operator workspace that runs the business information security officer function end to end. Charter and service catalogue, risk register and control library, strategy, assurance, incidents and continuity. A governed AI agent proposes changes; a person reviews them before anything is applied.