Templates · written, not downloaded
33 free templates, each written by a page from your answers
A template is a document with the blanks left in; every page below asks for the answers and writes the document with the blanks filled, in the order the standard or the regulation lists, in six languages, with the facts in the link and the free text on the page and nothing sent anywhere.
ISO 27001
ISO 27001 scope statement template
Clause 4.3 from twelve answers: the certificate sentence, the boundaries, the exclusions.
ISO 27001 information security policy template
Clause 5.2 from ten answers, in your company's words, two pages.
ISO 27001 risk register and treatment plan template
From five answers: the starter risks for a software company, scored, with the treatment and the controls needed.
ISO 27001 Statement of Applicability template
Every Annex A control applicable or excluded, implemented or not, with the justification, in one document.
ISO 27001 internal audit programme template
Clause 9.2 from five answers, the year's schedule over every clause section and Annex A theme.
ISO 27001 management review minutes template
Clause 9.3 as an agenda: the seven inputs, the four trends with counts, the decisions, the actions.
ISO 27001 corrective action record template
Clause 10.2 for one nonconformity: correction, cause, elsewhere, action, effectiveness, change.
ISO 27001 incident response plan template
Roles, reporting, three severity levels, the response steps, the regulatory clocks, evidence and lessons.
ISO 27001 acceptable use policy template
Accounts, devices, remote work, data, services and AI tools, personal use, reporting, in twelve sections.
ISO 27001 access control policy template
Identities, authentication, roles, privileged access, third parties, reviews, leavers, logging, exceptions.
ISO 27001 supplier security policy template
Critical suppliers, due diligence, six contract clauses, cloud regions, the review, the exit.
ISO 27001 business continuity plan template
Recovery objectives, roles, five scenarios, security during disruption, backups, the exercise.
ISO 9001
ISO 9001 quality policy template
Clause 5.2 from ten answers: the commitments, the objectives, who is accountable.
ISO 9001 internal audit programme template
Clause 9.2 from five answers and your processes, the year's schedule over every section and process.
ISO 9001 management review minutes template
Clause 9.3 as an agenda: the six inputs, the seven trends with counts, the conclusion, the decisions.
ISO 9001 corrective action record template
Clause 10.2 for one nonconformity, the risks and opportunities updated among the sections.
ISO 42001
ISO 42001 AI policy template
Clause 5.2 in ten sections from eleven answers, the AI Act duties named.
ISO 42001 AI system impact assessment template
Clause 6.1.4 for one system: the consequences to individuals, groups and society, rated, the measures, the result.
ISO 42001 AI system inventory template
Every system with its purpose, role, dependencies, assessment date and AI Act reading, in one table.
GDPR
GDPR record of processing activities template
Article 30 field by field, for a controller and for a processor.
GDPR privacy notice template
Articles 13 and 14: every piece of information the notice must carry, from your answers.
GDPR data processing agreement template
The Article 28 terms as a checklist with a status each, beside the DORA clauses.
GDPR data protection impact assessment template
Whether one is due, then the assessment written to Article 35.
GDPR breach notification template
The clock from awareness, the deadline computed, the Article 33 notification written.
GDPR access request answer template
The clock from receipt, the deadline computed, the Article 15 answer written.
NIS2
DORA
DORA register of information template
The vendor data sheet from the implementing regulation's templates, field by field.
DORA Article 30 contract clauses template
Every clause a bank customer will ask a software vendor for, with a status each.
DORA vendor due diligence questionnaire template
The questions of the delegated regulation, generated for one vendor.
AI Act
AI Act fundamental rights impact assessment template
Article 27: whether one is owed, then the six elements written.
AI Act AI literacy record template
Article 4: the measures per group of people, written as the document to keep.
AI Act provider checklist template
Article 16: the provider's obligations with a status per point and the documents each needs.
AI Act EU database registration template
Article 49: which registration you owe and the Annex VIII fields prepared.
Free determinations and clocks
Not a document but an answer in writing: whether a regulation applies, which obligations, which deadline, at what cost.
ISO 27001 certification cost calculator
The auditor days by headcount, from the accreditation rules, times a day rate.
Which GDPR duties apply
The determination for a software company, in writing.
GDPR international transfers
The destination and the roles in, the transfer mechanism out.
NIS2 scope determination
Essential, important or out of scope, with the reason.
CRA scope determination
Whether the product is in scope, and default, important or critical.
CRA obligations by role
Every obligation of the manufacturer, importer, distributor or steward, with the article.
CRA reporting deadlines
The three clocks computed from the moment of awareness.
AI Act high-risk determination
A system read against the lists, with the reason.
CRA to ISO 27001 mapping
Which essential requirements an ISMS already evidences, and the gaps.
NIS2 to ISO 27001 mapping
Which sections of the implementing regulation a certified system satisfies, and the two it does not.
Packs bought at checkout
Three documents drafted from your answers and paid for once at checkout, not free.
In StandardOS the templates are the system
Every document above is a record in StandardOS, prefilled from what the system already holds, kept current by the automation, and read at the audit from the same place; the free pages write the first version, the product keeps it true.