ISMS Copilot
ISMS Copilot

Check a policy against an ISO 27001 control

Your AI reads the policy you already have. ISMS Copilot checks it against the control you name and lists what is missing. You sign. The file stays yours.

The check auditors run on every policy

An auditor reads a policy and asks two things: does it cover what the control requires, and does it describe what the organization actually does. Most ISMS owners find the first question hard because the requirement text and the policy text live in different places. The job is a comparison, and a comparison needs both texts in front of the reader. Your AI reads the policy from your wiki or repository and sends the relevant excerpt. ISMS Copilot brings the control requirement, compares the two, and returns a list: what the policy covers, what the control requires and the policy does not mention, and anything it cannot confirm from the excerpt. It does not invent requirements the control does not contain, and it marks every line it could not verify so you can check the source yourself.

Explore the ISO 27001 Copilot →

How the check works

Paste the policy excerpt, name the control (for example A.5.15), get the gap list

Works on procedures and registers too, not only top-level policies

Every unconfirmed statement is marked so you can verify it against the source

The answer cites the control requirement it is checking against

Only the excerpt travels: the policy stays in your wiki, repository or GRC platform

Why teams check before the audit

  • Catch the missing requirement before the auditor reads the policy
  • No copy-paste into a generic chatbot with no framework grounding
  • A named control on every finding, so remediation is a decision, not a rewrite
  • The same check works across the whole policy suite, one control at a time

Frequently Asked Questions

What if the policy does not exist yet?

Then the job is a draft, not a check. ISMS Copilot drafts the policy against the control from your scope and context, and you approve it before it enters your wiki.

Does it invent requirements the control does not contain?

No. The check cites the control requirement it is checking against, and anything it cannot confirm from your excerpt is marked as unconfirmed rather than presented as a finding.

Does it store our policies?

No. Your AI reads the file and sends a short excerpt. ISMS Copilot returns the check, and the policy stays where you keep it.

Check your policy against the control

Name the control, paste the policy, get the gap list before the audit.