Policy Register
For the compliance or ISMS manager who is asked for the policies first

The document set the audit will ask for, with what is missing named, from the policy list you already keep.

Paste your policy list. Get, per policy, which clauses of the standards you answer to require it and what they expect it to contain, who should own it and how often it is reviewed, the controls it must govern, and the list of policies those standards expect that you do not have, each with the template to start from. Eight documents free, no account.

Build a registerClassification and every count run in your browser against a published dictionary of policy types and the clauses that require them. Nothing leaves it until you choose to save.
A compliance manager at a desk with a set of policy documents open for review
Walk into the review with the auditor's first question, show me your policies, already answered on one page: what you hold, who owes each document a review, and what the standards still expect from you. It works from the clause text of seven regimes, read by hand, against nothing more than the titles you already keep: no account, no platform to populate first.
Specimen: 24 documents, a 300-person software company8 of 24 shown
DocumentRequiresOwnerState
Information Security PolicyISO 27001 5.1; ISO 27701 5.2CISOcurrent
Access Control Policy
duplicate
ISO 27001 5.15, 5.18Head of IToverdue
Password StandardISO 27001 5.17, 8.5Head of ITcurrent
Business Continuity PlanISO 27001 5.29not namedoverdue
Data Breach Notification ProcedureGDPR Art. 33, 34; ISO 27701 A.3.12DPOcurrent
Logical Access Standard
duplicate
ISO 27001 5.15, 5.18not namedundated
Quillfeather Attestation Charter
unrecognised
nonenot namedundated
AI use policy
expected, not listed
ISO 42001 A.2.2, A.9.2templategap
24 listed, 23 classified56 clauses25 expected, not listed
Eight of the 24 lines as the register reads them; the specimen runs whole, your own list runs to eight lines free. The full register adds the expected owner and the cadence on every line, the clause text each requires, the 25 documents four regimes expect and the list does not carry, and eight findings.
One document per line: Title, or Title | Owner | Last reviewed. Tabs, commas or pipes; a header row is optional and its column names are recognised in any order; a numbered list or a document register export works; ids and version tags such as POL-007 ... v3.2 (2025-11) are read and set aside. A first line iso 27001: yes | gdpr: yes | as at: 2026-09-21 ticks the regimes and pins the date.
Tick the regimes you answer to; with none ticked, ISO/IEC 27001 is applied. Nothing is sent anywhere until you choose to save.
01

Paste the list you already have

The document register export, the intranet index or the list the last auditor was sent: one document per line, with the owner and the last review date if you have them, in any order the header names. Every title is matched against a published dictionary of policy types in ten families; a title that matches nothing is marked unrecognised and never guessed.

02

Read what each document answers, and what is missing

Per document: the clauses of the ticked regimes that require it, each with what it expects the document to contain, the owner role the clauses imply against the one on your line, the review cadence and the due date. Per register: the documents those regimes expect that your list does not carry, each with the clause that expects it, its family and the template to start from.

03

Take the gap list to the next review

Export the register and the gap list, the owner and cadence sheet and the requiring-clause matrix, or print the one-page auditor summary. The register reads your titles; it never reads the documents and never rules on them.

Why a register and not a GRC platform

The platforms are built for the team with a licence budget and a year to populate them. The compliance manager at a 300-person firm has a folder of policies, a spreadsheet that lists them and an auditor who opens with "show me your policies". Before the platform conversation, somebody has to say which documents the standards expect, which of them exist, who owns each and when it was last read. That is the register this builds, in your browser, from the list you already hold.

The dictionary and the requiring-clause table are ours and published in full: every policy type it recognises, in ten families, and what each regime expects of a document set. The requirement text behind every clause is quoted from the standards themselves, read clause by clause against the copy we hold.