Get ready for ISO 27001. With the right documentation and guidance.
We help your organisation prepare for ISO 27001 certification by establishing the necessary documentation, security policies and management processes — supported by Sovereign AI.
Independent Registrar Model: SpicterCloud provides preparation and documentation support. Certification is performed independently by an accredited certification body.
Information security starts with a structured approach.
ISO 27001 preparation involves more than implementing technical security measures. Organisations need documented responsibilities, risk management, security policies, operational procedures and verifiable evidence that their information security management system (ISMS) is properly implemented and maintained.
Structured Preparation
Understand what is required and establish a practical roadmap towards certification readiness without operational disruption.
Documentation Support
Develop the policies, procedures and records needed for your information security management system systematically.
Practical Implementation
Align documented security requirements with your actual business processes and institutional IT environment.
Sovereign AI Assistance
Accelerate the preparation and maintenance of security documentation using AI within a strictly controlled Swiss runtime.
From initial assessment to audit preparation.
Preparation support tailored to your organisation's baseline, scope and risk profile.
1. Initial Assessment
Review your existing security practices, organisational responsibilities and documentation to identify preparation needs and baseline maturity.
2. ISMS Framework
Support the definition of your information security management system, including scope, responsibilities, policies and management processes.
3. Risk Management
Support the identification, assessment and documentation of information security risks and the preparation of appropriate risk treatment plans.
4. Policies & Procedures
Provide structured document templates and help create organisation-specific information security policies, procedures and supporting records.
5. Implementation Support
Help translate documented security requirements into practical organisational and technical measures within enterprise workflows.
6. Audit Preparation
Review documentation, identify remaining gaps and support preparation for the independent certification audit stages.
SpicterCloud provides advisory, framework design and preparation support. Formal certification audits are conducted exclusively by independent accredited registrars.
You don't have to start with a blank page.
SpicterCloud provides structured documentation frameworks and templates to help you establish and maintain your Information Security Management System (ISMS). We support you in adapting these documents to your organisation, processes and security requirements.
ISMS Scope & Information Security Policy
Master governance blueprint setting management intent, organisational boundaries and core principles.
Roles & Responsibilities Matrix
Detailed RACI framework, Information Security Officer (CISO) remit, and clear escalation protocols.
Risk Assessment & Treatment Plan
Structured risk assessment methodology, risk register, criteria evaluation and mitigation blueprints.
Statement of Applicability (SoA)
Comprehensive mapping of all Annex A controls with systematic rationale for inclusion or exclusion.
Asset Inventory & Data Classification
Hardware/software asset register, handling guidelines and data tiering aligned with Swiss regulations.
Access Control & Incident Management
Least-privilege operational guidelines, RBAC configurations, and incident response playbook runbooks.
Business Continuity & Backup
RTO and RPO parameter specifications, testing cadence, and disaster recovery redundancy protocols.
Supplier Security Management
Vendor onboarding assessments, contractual SLA guidelines, and recurring third-party risk review schemas.
Internal Audit & Management Review
Standardised audit schedule, non-conformance logging matrices, and annual board-level reporting formats.
These are examples of documentation frameworks and templates we can provide. The exact documentation requirements depend on your organisation's scope, risks, existing controls and operating environment. Templates must be adapted, implemented and maintained to support ISO 27001 conformity.
Less time writing documents. More time improving security.
Our Sovereign AI supports the creation, review and maintenance of ISO 27001 documentation. Using structured templates and your organisation's specific information, AI helps prepare tailored policies, procedures and supporting records within a controlled environment.
Document Drafting
Generate initial drafts of policies and procedures using structured templates and organisation-specific information.
Document Review
Identify missing information, inconsistent terminology and areas requiring further clarification prior to internal sign-off.
Document Adaptation
Adapt framework documents to the organisation's actual processes, responsibilities and specific technical infrastructure.
Document Maintenance
Support updates when business processes, security requirements or the institutional operating environment changes.
Internal interviews, infrastructure schematics
ISO 27001 baseline structures & controls
AI-assisted document drafting in a controlled environment
Security officer sign-off & RACI validation
Audit-ready documentation repository
AI assists with documentation preparation. Your organisation remains responsible for reviewing and approving the content, implementing security measures and maintaining its ISMS.
A practical path towards certification readiness.
Three sequential phases aligning documentation depth with operational reality.
THINK
Understand your organisation, define the ISMS scope, assess existing practices and establish a pragmatic preparation roadmap tailored to your timeline.
- Scope boundary definition
- Baseline gap analysis
- Target state milestones
BUILD
Develop the documentation framework, adapt policies and procedures, support risk management and help implement the required organisational and technical measures.
- Drafting & template adoption
- Risk treatment drafting
- Control operationalisation
OPERATE
Support the maintenance of documentation, preparation of internal reviews, management review activities and continuous improvement of the ISMS.
- Internal audit facilitation
- Management review protocols
- Certification audit preparation
Engage SpicterCloud for individual documentation assignments or for a comprehensive ISO 27001 preparation journey.
We prepare. An independent body certifies.
SpicterCloud supports your organisation in preparing for ISO 27001 certification. The formal certification audit and certification decision remain the responsibility of an independent, accredited certification body.
SpicterCloud – Preparation Support
- checkInitial assessment and preparation roadmap
- checkISMS documentation frameworks and tailored policies
- checkAI-assisted document drafting and review
- checkRisk management and implementation guidance
- checkPreparation for the independent certification audit
Accredited Certification Body – Independent Certification
- gavelConducts the formal certification audit
- gavelEvaluates conformity with ISO 27001 requirements
- gavelMakes the independent certification decision
- gavelIssues the certificate following a successful certification process
Extend your security and compliance services.
IT resellers and managed service providers can offer ISO 27001 preparation and documentation support to their customers using SpicterCloud's documentation frameworks, specialist expertise and Sovereign AI capabilities. You retain your customer relationship while we provide the agreed preparation and implementation support.
Connect information security with your wider IT environment.
Complete sovereign infrastructure solutions designed according to Swiss data governance mandates.
Secure Workplace
Managed workplace applications, identity and device management, and security operations within your chosen sovereign environment.
Managed Cloud
Professionally managed cloud infrastructure and operational services with European and Swiss hosting options.
Sovereign AI
AI capabilities for organisations that require greater control over their sensitive information, processing environments and AI infrastructure.
Preparing for ISO 27001?
Tell us where your organisation stands today. We'll help you identify the documentation, processes and preparation activities needed for your next steps.
Zurich Head Office • Swiss Advisory • Non-Disclosure Guaranteed