Check a policy against an ISO 27001 control
Your AI reads the policy you already have. ISMS Copilot checks it against the control you name and lists what is missing. You sign. The file stays yours.
The check auditors run on every policy
An auditor reads a policy and asks two things: does it cover what the control requires, and does it describe what the organization actually does. Most ISMS owners find the first question hard because the requirement text and the policy text live in different places. The job is a comparison, and a comparison needs both texts in front of the reader. Your AI reads the policy from your wiki or repository and sends the relevant excerpt. ISMS Copilot brings the control requirement, compares the two, and returns a list: what the policy covers, what the control requires and the policy does not mention, and anything it cannot confirm from the excerpt. It does not invent requirements the control does not contain, and it marks every line it could not verify so you can check the source yourself.
Explore the ISO 27001 Copilot →How the check works
Paste the policy excerpt, name the control (for example A.5.15), get the gap list
Works on procedures and registers too, not only top-level policies
Every unconfirmed statement is marked so you can verify it against the source
The answer cites the control requirement it is checking against
Only the excerpt travels: the policy stays in your wiki, repository or GRC platform
Why teams check before the audit
- Catch the missing requirement before the auditor reads the policy
- No copy-paste into a generic chatbot with no framework grounding
- A named control on every finding, so remediation is a decision, not a rewrite
- The same check works across the whole policy suite, one control at a time
Frequently Asked Questions
What if the policy does not exist yet?
Then the job is a draft, not a check. ISMS Copilot drafts the policy against the control from your scope and context, and you approve it before it enters your wiki.
Does it invent requirements the control does not contain?
No. The check cites the control requirement it is checking against, and anything it cannot confirm from your excerpt is marked as unconfirmed rather than presented as a finding.
Does it store our policies?
No. Your AI reads the file and sends a short excerpt. ISMS Copilot returns the check, and the policy stays where you keep it.
Check your policy against the control
Name the control, paste the policy, get the gap list before the audit.
