The document set the audit will ask for, with what is missing named, from the policy list you already keep.
Paste your policy list. Get, per policy, which clauses of the standards you answer to require it and what they expect it to contain, who should own it and how often it is reviewed, the controls it must govern, and the list of policies those standards expect that you do not have, each with the template to start from. Eight documents free, no account.

| Document | Requires | Owner | State |
|---|---|---|---|
| Information Security Policy | ISO 27001 5.1; ISO 27701 5.2 | CISO | current |
| Access Control Policy duplicate | ISO 27001 5.15, 5.18 | Head of IT | overdue |
| Password Standard | ISO 27001 5.17, 8.5 | Head of IT | current |
| Business Continuity Plan | ISO 27001 5.29 | not named | overdue |
| Data Breach Notification Procedure | GDPR Art. 33, 34; ISO 27701 A.3.12 | DPO | current |
| Logical Access Standard duplicate | ISO 27001 5.15, 5.18 | not named | undated |
| Quillfeather Attestation Charter unrecognised | none | not named | undated |
| AI use policy expected, not listed | ISO 42001 A.2.2, A.9.2 | template | gap |
| 24 listed, 23 classified | 56 clauses | 25 expected, not listed | |
Paste the list you already have
The document register export, the intranet index or the list the last auditor was sent: one document per line, with the owner and the last review date if you have them, in any order the header names. Every title is matched against a published dictionary of policy types in ten families; a title that matches nothing is marked unrecognised and never guessed.
Read what each document answers, and what is missing
Per document: the clauses of the ticked regimes that require it, each with what it expects the document to contain, the owner role the clauses imply against the one on your line, the review cadence and the due date. Per register: the documents those regimes expect that your list does not carry, each with the clause that expects it, its family and the template to start from.
Take the gap list to the next review
Export the register and the gap list, the owner and cadence sheet and the requiring-clause matrix, or print the one-page auditor summary. The register reads your titles; it never reads the documents and never rules on them.
Why a register and not a GRC platform
The platforms are built for the team with a licence budget and a year to populate them. The compliance manager at a 300-person firm has a folder of policies, a spreadsheet that lists them and an auditor who opens with "show me your policies". Before the platform conversation, somebody has to say which documents the standards expect, which of them exist, who owns each and when it was last read. That is the register this builds, in your browser, from the list you already hold.