What security teams actually run ISO 27001 on, according to one r/grc thread
A recent r/grc thread about ISMS tooling taught us more about this market than most vendor reports. Here is what it said and what we took from it.

A security professional with an ISO 27001 Lead Implementer certificate asked r/grc a plain question: they are implementing an ISMS at a roughly 1,000-person company that is not cloud-heavy, and they want to know whether Confluence plus Jira can carry it long-term, or whether they need a dedicated GRC platform.
ISMS Copilot is never mentioned in that thread. That is exactly why it is one of the most useful pieces of market research we have read in months. Several contributors disclosed vendor interests of their own, but nobody was speaking for us. Here is what the practitioners said, and what we took from it.
Atlassian and spreadsheets are normal, and they certify
The top-voted answer, from a practitioner running an ISMS for 2,000 people across SOC 2, ISO 27001, SOX and PCI, was blunt: most ISMS were built on Atlassian, spreadsheets, coffee and perseverance. A consultant with more than 100 implementations behind them pushed back that a well-fitted tool makes life meaningfully easier at scale. Both are right, and the thread is honest about where the line sits.
At around a thousand people, several practitioners reported the same strain in the Atlassian-and-sheets approach: the links. Risks, controls, assets, owners and evidence overwrite each other when they live in Jira issues. A folder of evidence does not tell you whether a record was accepted, rejected or is still current. The Statement of Applicability and its dated versions stay audit-ready only by hand. Others in the thread pushed back hard on spreadsheets at this scale and argued for a dedicated platform, so read this as a live argument, not a verdict.
That is a real problem, and the answer the GRC market sells is to move everything into a platform.
The GRC SaaS fatigue is real
Another theme showed up more than once: most GRC tools are described as task trackers with evidence bolted on. One commenter, currently running compliance for a 2,000-person organization, priced a Vanta seat against another junior hire and chose the junior. The tools the room respects either automate control testing or read a document against the requirement. Configuration-heavy platforms, in the words of one commenter, can leave the data worse than Excel.
Read that as a buyer speaking: the value is in the judgment layer, the part that says whether the policy covers the control, whether the SoA justification survives scrutiny, whether the register and the SoA agree. Tracking who owns the action item is a solved problem, in Jira or anywhere else.
The new entrant is AI, and the objection is accountability
The most interesting part of the thread is what people suggested instead of buying another platform: use Claude. One commenter disclosed their own product built on that idea, an agent that scaffolds the SoA and the risk register. Another described building their own GRC tooling with an LLM while keeping the register deterministic and outside the model.
The pushback was immediate and correct: it is all fun and games until the results are hallucinated and you are personally accountable. The same person answered that the way through is careful design, evidence gathering with citations and guardrails, and keeping the deterministic store out of the model.
That exchange is the whole thesis of our product in one comment thread, written by buyers without us in the room.
What we took from it
The thread splits compliance work into two layers. The register, the tickets, the evidence trail: those live in the tool the organization already trusts, whether that is Jira, Confluence, a sheet or a GRC platform. The judgment calls, whether a SoA justification satisfies clause 6.1.3 d), whether a policy covers A.5.15, where the SoA and the risk register disagree: those are framework questions, and they are exactly what a specialist should answer.
Here is how that works with ISMS Copilot, concretely. Your AI, the Claude, Cursor or ChatGPT you already work in, reads the page or the ticket if you already gave it those tools, and sends us a short excerpt. ISMS Copilot answers with the clause, the requirement, or the draft, and marks what it could not confirm so you can check the source. You sign every line, and the file stays in your wiki, your tracker, your sheet. We do not connect to Jira or Confluence, we do not store your register, and we do not write anything back.
That is why we are deliberately not the platform this thread was shopping for. The original poster needs a decision about where the register lives, and several contributors said they can keep it where it is. What they need next, and what every contributor describing AI said in their own way, is the judgment layer with citations, on demand, next to the files that already exist.
The honest limits
Two things the thread wants that we do not do, on purpose. We do not fix register integrity: if risks and controls overwrite each other in Jira, that is a Jira problem, and moving to a tracker that fits is a legitimate answer. And we do not automate control testing, because an unverified test result is exactly the hallucinated evidence the thread is afraid of.
An AI answer is a draft you are accountable for. The product's job is to make that draft traceable to the standard, mark every unconfirmed line, and let you sign with your eyes open. That is the same deal the careful builders in the thread described, without asking anyone to move their ISMS to do it.
Related Posts

Why we pay consultants 30% recurring when the rest of the market doesn't
A founder note on alignment, distribution, and how the compliance-AI market pays the people doing the recommending

The ISMS Copilot partner programme: earn 30% recurring
A compliance-focused affiliate programme for consultants, fractional CISOs, and creators who recommend ISMS Copilot

