14 mandatory clause documents + 14 auditor guides. Every document required for Stage 1 certification audit. Australian regulated-sector notes included.
Compliance documentation for
every framework that matters.
ISO 27001 · ISO 42001 · SOC 2 · NIST AI RMF · EU AI Act · APRA CPS 230 · Privacy Act · GenAI Governance · AI Procurement
19 templates + 19 auditor guides (38 files). All mandatory clauses and key Annex A controls. The most complete ISO 42001 documentation suite available for Australian organisations.
7 documents for organisations starting their AI Management System journey. Gap assessment, governance charter, project plan, risk appetite, stakeholder register, and executive brief.
10 pre-formatted evidence templates for ISO 42001 certification audits. Clause-mapped evidence registers, objective evidence logs, corrective action records, and management review minutes.
8 documents adapting ISO 42001 for Australian regulated industries. Sector risk overlays for financial services, healthcare, and government. APRA, APS, and TGA alignment notes.
9 editable Word documents for ISO 27001:2022 certification. Policy suite, risk register, Statement of Applicability covering all 93 Annex A controls, and management review pack.
Complete ISO 27001:2022 ISMS suite. Policy library, operational procedures, security awareness programme, supplier management, and business continuity integration. Coming Week 2.
7 documents covering the full EU AI Act compliance journey. Risk classification, prohibited practices, Article 9 risk management, conformity assessment, technical documentation, and post-market monitoring.
9 documents for governing generative AI deployment. Acceptable use policy, model risk assessment, vendor evaluation, output quality framework, and incident response. ISO 42001 and EU AI Act aligned.
9 documents implementing the NIST AI Risk Management Framework. GOVERN, MAP, MEASURE, and MANAGE functions. Risk profile, Trustworthy AI characteristics assessment, and implementation roadmap.
8 documents for AI vendor procurement and risk assessment. RFP template, 60-question due diligence questionnaire, risk scoring matrix, contract clause library, and ongoing monitoring plan.
10 documents for SOC 2 Type II readiness. Trust Service Criteria gap assessment, control mapping matrix, system description template, evidence collection tracker, and audit preparation checklist.
7 documents aligned to the OAIC PIA methodology and Australian Privacy Principles. Threshold assessment, full PIA template, data flow mapping, and Privacy Act reform checklist.
APRA CPS 230 supply chain and third-party risk documentation. Critical operations register, business impact analysis, business continuity plan, and APRA notification templates. Coming Week 2.
7 documents covering the full vendor lifecycle. Vendor tiering, due diligence questionnaire, weighted risk scoring, contract checklist, monitoring tracker, and exit playbook. CPS 230 and ISO 27001 aligned.
7 documents covering the full incident lifecycle. NDB scheme and GDPR Article 33 aligned. Triage checklist, investigation workbook, OAIC notification templates, response log, and post-breach review.
Extended Privacy Impact Assessment Toolkit with Privacy Act reform provisions, AI-specific data handling assessment, and enhanced OAIC reporting templates. Coming Week 2.
15 production-ready architecture decision records for AI/ML adoption. Framework selection, model hosting, inference, observability, RAG vs fine-tuning, privacy (APP 8), bias, incident response, and cost optimisation.
Complete ISMS documentation suite beyond the baseline. Operational procedures, security awareness programme, supplier security framework, and BCP integration.
APRA CPS 230 operational risk and resilience documentation with focus on supply chain risk and third-party oversight for APRA-regulated entities.
Extended PIA toolkit with Privacy Act reform provisions, AI-specific data handling assessment, and enhanced OAIC reporting templates.
Extended vendor risk management with enhanced fourth-party risk assessment, ESG supplier evaluation, and automation vendor governance.
ISO 42001 Implementation Bundle
Foundation Pack + Full Certification Pack + Implementation Roadmap. Everything to plan and certify your AI Management System. 59 documents.
Privacy & AI Governance Bundle
PIA Toolkit + ISO 42001 Foundation + GenAI Governance Pack. OAIC PIA methodology meets AI Management System certification.
APRA Operational Resilience Bundle
CPS 230 Supply Chain Pack + Vendor Risk Management Kit. The two APRA frameworks that directly feed each other.
International AI Compliance Bundle
EU AI Act Framework + ISO 42001 Foundation + NIST AI RMF Pack. For Australian organisations with international AI compliance obligations.
Privacy & Vendor Risk Stack
Data Breach Playbook + PIA Toolkit + Vendor Risk Management Kit. Prevent, assess, and respond to privacy and third-party risk.