What problem does it solve?
Preparing for an ISO 27001 internal, surveillance, or certification audit is high-stakes and easy to get wrong — stale risk registers, missing access review records, and incomplete management review inputs are the most-cited findings. This Skill pressure-tests your ISMS against six auditor-style forcing questions before the real audit happens.
Core Features & Use Cases
- Six-Question Audit Interrogation: Covers audit scope and 3-year coverage, risk register freshness, access review evidence, supplier management, incident response records, and Clause 9.3 management review inputs.
- Structured Readiness Verdict: Produces a markdown report with per-control pass/fail status, cross-framework impact (SOC 2, ISO 42001, GDPR), and a READY / CLOSE-CRITICALS-FIRST / NOT-READY verdict with top 3 actions.
- Cross-Framework Routing: Links to SOC 2, GDPR, ISO 42001, and compliance-readiness skills for reuse across overlapping control frameworks.
- Use Case: Before your annual Clause 9.2 internal audit, run the interrogation against your ISMS scope to surface gaps in access review records and risk register linkage, then assign corrective actions with owners and timelines.
Quick Start
Ask the AI to run an ISO 27001 audit readiness check on your ISMS scope using the six forcing questions and produce a readiness verdict report.